Security

Probing Blocklist

Public feed of IPs blocked on im.forsale after probing sensitive paths or abuse review — for operators who want to block the same scanners.

Active entries

81,668

Last published

Sep 6, 2026 09:33 UTC

Download files regenerate once per day and are served as static files.

What gets listed

  • Honeypot blocks — permanent on first hit to paths like .env, wp-admin, phpMyAdmin, .git.
  • Manual blocks — IPs blocked by administrators for abuse.

This is an IP list, not a User-Agent bot list.

Download formats

Plain text is one IP per line for firewalls, fail2ban, nginx deny, and WAF import. JSON includes source and trigger metadata. Files are regenerated once per day.

# Plain text
curl -s https://im.forsale/blocklist.txt
# JSON
curl -s https://im.forsale/blocklist.json | jq '.count, .entries[0]'

How others publish blocklists

Most community blocklists ship a plain-text file with one IP per line for firewalls, fail2ban, nginx deny, or WAF rules. JSON feeds add metadata. Feeds are typically cached with a Last-Modified header.

Provided as-is for community use. No warranty; verify before blocking in production.

Request removal

If your IP hit the honeypot by mistake, request removal from a different network than the blocked IP.

Please confirm you are not a robot:

Re-probing sensitive paths after unblock will block the IP again.