Angriffsabwehr9 min read5 sections

Attack Defense - What it is & how it works

The product explained from zero: report attacks from your servers to a global list - and automatically block reported attackers on your own systems. Free, anonymous, GDPR compliant.

01

What is Attack Defense?

Attack Defense is a community network in both directions:

  • Report: your servers automatically report attack attempts (SSH brute-force, IMAP/POP3 logins, SMTP auth, web attacks, DDoS, port scans and 100+ more service types) to a central scoring list.
  • Block: every participant automatically blocks the IPs reported by the community on their own servers and firewalls - attackers are stopped everywhere, not just where they were caught.

It works like blocklist.de, but more cautious: every report is a signal, never a verdict. An IP is only listed when at least two independent reports confirm it - or immediately for critical categories (malware, botnet).

Who is it for?

  • Hosters & server admins who run fail2ban, CrowdSec or any server software.
  • Firewall operators (iptables, nftables, ufw, pf/BSD, Windows) who want a free, automatically updated blocklist.
  • Everyone who wants to check whether an IP is a known attacker before letting it in.

What it costs

Nothing. Reporting, blocking and IP checks are free and work without an account. A free account only adds optional report tokens for personal statistics.

02

How it works

Three steps, fully automated:

  1. Server reports: fail2ban bans an attacker and reports the IP to us automatically via HTTP API (CrowdSec and any custom system work too).
  2. We score: every report is a weighted signal. Category, confidence and reporter reputation determine the score. Scores decay exponentially - entries disappear automatically without new activity (7 days).
  3. Everyone blocks automatically: participants pull the current list every 5 minutes. On servers via the fail2ban block jail, on firewalls via the plain-text export. The responsible provider is notified anonymously (RDAP/whois, X-ARF format).

Important: blocking never runs over DNS queries. The DNS zones are check zones - you query them to look up a single IP. The actual blocking uses the HTTP export, synced every 5 minutes.

03

Listing states & the cautious principle

Every IP goes through four states:

StateMeaningDNS answer
CleanNo reports.NXDOMAIN
WatchlistOne report - internal monitoring only, not publicly listed.NXDOMAIN
Soft-listedTwo independent reports - listed with block code.127.0.0.8 (abuse) / 127.0.0.7 (exploit/scanner)
Hard-listedFurther reports or critical category - reject allowed.127.0.0.6 (botnet) and others

The cautious principle:

  • Every report counts equally - with token or anonymous.
  • One single report only reaches the watchlist - no arbitrary listings.
  • Two independent reports list the IP; further reports hard-list it.
  • Critical categories (malware, botnet) list with a single report.
  • Entries expire automatically without new reports (7 days).

Reporter reputation adjusts the weight of a report (0.25x–2.0x), never the listing threshold - trusted reporters keep entries listed longer and push hard-listing faster, unreliable sources are dampened.

04

Check zones & export

Each of the 109 services has its own check zone under attacks.provider.tools, plus a base zone for all attacks:

ssh.attacks.provider.tools      imap.attacks.provider.tools     smtp-auth.attacks.provider.tools
attacks.provider.tools          (base zone - any attack)

Query the reversed IP under the zone label to check a single IP - see the article Check IPs.

For blocking there is the HTTP export - a plain-text list of all currently listed IPs (one per line), optionally filtered by service:

https://reports.provider.tools/api/v1/abuse/export            (all)
https://reports.provider.tools/api/v1/abuse/export?service=ssh

This export is what the fail2ban block jail and the firewall examples sync every 5 minutes.

05

Quick start

  1. On a server with fail2ban: one command - see fail2ban (reporting & auto-blocking). Installs reporting AND blocking in 2 minutes.
  2. On a firewall / router: sync the export and block - see In your firewall. iptables, nftables, ufw, pf (BSD) and Windows examples.
  3. Just want to check an IP? Use the Live Check or dig - see Check IPs.