Security
Probing Blocklist
Public feed of IPs blocked on im.forsale after probing sensitive paths or abuse review — for operators who want to block the same scanners.
Active entries
81,668
Last published
Sep 6, 2026 09:33 UTC
Download files regenerate once per day and are served as static files.
What gets listed
-
Honeypot blocks — permanent on first hit to paths like
.env,wp-admin,phpMyAdmin,.git. - Manual blocks — IPs blocked by administrators for abuse.
This is an IP list, not a User-Agent bot list.
Download formats
Plain text is one IP per line for firewalls, fail2ban, nginx deny, and WAF import. JSON includes source and trigger metadata. Files are regenerated once per day.
curl -s https://im.forsale/blocklist.txt
curl -s https://im.forsale/blocklist.json | jq '.count, .entries[0]'
How others publish blocklists
Most community blocklists ship a plain-text file with one IP per line for firewalls, fail2ban,
nginx deny, or WAF rules.
JSON feeds add metadata. Feeds are typically cached with a Last-Modified header.
Provided as-is for community use. No warranty; verify before blocking in production.
Request removal
If your IP hit the honeypot by mistake, request removal from a different network than the blocked IP.