• Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login
Netgate Discussion Forum
  • Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login

stretchoid.com IP list for use in blocking their port scans

Scheduled Pinned Locked Moved Firewalling
13 Posts 7 Posters 14.8k Views
Loading More Posts
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • S
    SprockTech
    last edited by SprockTech Aug 22, 2022, 12:34 PM Aug 22, 2022, 12:34 PM

    @Sissy Thanks for this. Also, looks like they have an opt-out form on their website, FWIW. https://stretchoid.com/

    F 1 Reply Last reply Aug 22, 2022, 12:51 PM Reply Quote 0
    • F
      fireodo @SprockTech
      last edited by fireodo Aug 22, 2022, 1:07 PM Aug 22, 2022, 12:51 PM

      @sprocktech said in stretchoid.com IP list for use in blocking their port scans:

      Also, looks like they have an opt-out form on their website

      In my opinion its strange to opt-out from something I never opt-in ... and btw - I dont like self proclaimed Internet Policemens ... 😀
      AS14061 is in my pfblocker and until now I never saw from there any legit connection ... 😉

      Kettop Mi4300YL CPU: i5-4300Y @ 1.60GHz RAM: 8GB Ethernet Ports: 4
      SSD: SanDisk pSSD-S2 16GB (ZFS) WiFi: WLE200NX
      pfsense 2.8.0 CE
      Packages: Apcupsd, Cron, Iftop, Iperf, LCDproc, Nmap, pfBlockerNG, RRD_Summary, Shellcmd, Snort, Speedtest, System_Patches.

      J 1 Reply Last reply Aug 22, 2022, 1:29 PM Reply Quote 1
      • F
        fireodo @johnpoz
        last edited by fireodo Aug 22, 2022, 1:22 PM Aug 22, 2022, 1:21 PM

        @johnpoz said in stretchoid.com IP list for use in blocking their port scans:

        For that matter block all of digitalocean inbound

        Also works with the IP-feed Cinsscore
        in pfblockerNG-devel for all the strechoids ... 🤓

        Kettop Mi4300YL CPU: i5-4300Y @ 1.60GHz RAM: 8GB Ethernet Ports: 4
        SSD: SanDisk pSSD-S2 16GB (ZFS) WiFi: WLE200NX
        pfsense 2.8.0 CE
        Packages: Apcupsd, Cron, Iftop, Iperf, LCDproc, Nmap, pfBlockerNG, RRD_Summary, Shellcmd, Snort, Speedtest, System_Patches.

        1 Reply Last reply Reply Quote 1
        • J
          johnpoz LAYER 8 Global Moderator @fireodo
          last edited by Aug 22, 2022, 1:29 PM

          @fireodo yeah a home user would have zero need for anything coming from DO at all.. But as mentioned you might if your hosting email services, etc.

          I found this parsed listed of the stretchoid IPs
          https://github.com/SilvrrGIT/IP-Lists/blob/master/stretchoid

          Looks like last updated 21 days..

          As the OP stated that opt-out thing could just be way to get more info - who knows.. I see their IPs hitting my wan... To me its just one of the many other bots, scripts, whatever - who cares.. If they find my open ports... Can't lock down the ports from every single IP - have them locked down to country already..

          What does it get you blocking them - still traffic hitting your wan.. So what if they find out your running smtp server.. You are running a smtp server open to the planet anyway ;)

          If anything I could see just blocking and not logging the traffic maybe if its filling up your logs with stuff you don't care to see.

          An intelligent man is sometimes forced to be drunk to spend time with his fools
          If you get confused: Listen to the Music Play
          Please don't Chat/PM me for help, unless mod related
          SG-4860 24.11 | Lab VMs 2.8, 24.11

          S 1 Reply Last reply Aug 22, 2022, 1:37 PM Reply Quote 1
          • S
            SprockTech @johnpoz
            last edited by Aug 22, 2022, 1:37 PM

            @johnpoz Doh, I skipped over the part in the OP about the opt-out. Oh well, I at least wanted to say thanks for the contribution. Everyone has a different way of doing things.

            N 1 Reply Last reply Aug 22, 2022, 2:49 PM Reply Quote 1
            • N
              NogBadTheBad @SprockTech
              last edited by Aug 22, 2022, 2:49 PM

              @sprocktech

              https://isc.sans.edu/api/threatlist/shodan/?xml

              https://isc.sans.edu/api/threatlist/shadowserver/?xml

              Handy for pfBlocker:-

              Screenshot 2022-08-22 at 15.47.25.png

              Andy

              1 x Netgate SG-4860 - 3 x Linksys LGS308P - 1 x Aruba InstantOn AP22

              W 1 Reply Last reply Jul 30, 2023, 9:10 PM Reply Quote 1
              • W
                williamdes @NogBadTheBad
                last edited by Jul 30, 2023, 9:10 PM

                Hi all,

                This is an old subject but has good SEO.
                There is lists of stretchoid IPs: https://github.com/SilvrrGIT/IP-Lists/issues/85

                I built a much more complete one, you can find it here: https://github.com/SilvrrGIT/IP-Lists/issues/85#issuecomment-1657267386

                I currently use this with my pfSense/OPNsense setup as a firewall alias.

                B 1 Reply Last reply Aug 6, 2023, 5:58 PM Reply Quote 1
                • B
                  Bob.Dig LAYER 8 @williamdes
                  last edited by Aug 6, 2023, 5:58 PM

                  @williamdes said in stretchoid.com IP list for use in blocking their port scans:

                  I built a much more complete one, you can find it here: https://github.com/SilvrrGIT/IP-Lists/issues/85#issuecomment-1657267386

                  I currently use this with my pfSense/OPNsense setup as a firewall alias.

                  Thanks, today I encountered some stretchoid hits from your list, which were not in the PRI group feeds.

                  J 1 Reply Last reply Aug 6, 2023, 8:56 PM Reply Quote 1
                  • J
                    johnpoz LAYER 8 Global Moderator @Bob.Dig
                    last edited by Aug 6, 2023, 8:56 PM

                    @Bob-Dig what were the ips?

                    An intelligent man is sometimes forced to be drunk to spend time with his fools
                    If you get confused: Listen to the Music Play
                    Please don't Chat/PM me for help, unless mod related
                    SG-4860 24.11 | Lab VMs 2.8, 24.11

                    B 1 Reply Last reply Aug 7, 2023, 6:26 AM Reply Quote 0
                    • B
                      Bob.Dig LAYER 8 @johnpoz
                      last edited by Aug 7, 2023, 6:26 AM

                      @johnpoz said in stretchoid.com IP list for use in blocking their port scans:

                      @Bob-Dig what were the ips?

                      I already deleted the log file so I can't tell. But when I looked, they were almost identical to ones, which were already in PRI1.

                      1 Reply Last reply Reply Quote 0
                      • First post
                        Last post
                      Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.
                        [[user:consent.lead]]
                        [[user:consent.not_received]]