IP Blocklist Nedir? Nasıl Kullanılır? What Is an IP Blocklist? How Is It Used?
IP blocklist'in ne olduğu, türleri, firewall'a nasıl ekleneceği ve dikkat edilmesi gereken riskler. What an IP blocklist is, its types, how to add one to a firewall, and the risks to watch for.
IP blocklist (IP kara listesi), kötü amaçlı faaliyetleriyle bilinen IP adreslerinin listesidir. Bir firewall, mail sunucusu veya web sunucusu bu listeyi kullanarak, listedeki adreslerden gelen bağlantıları otomatik olarak reddedebilir. Amaç, bilinen bir tehdidin sisteminize ulaşmadan önce, "kapıda" durdurulmasıdır. An IP blocklist is a list of IP addresses known for malicious activity. A firewall, mail server, or web server can use this list to automatically reject connections from those addresses. The goal is to stop a known threat "at the door," before it reaches your system.
Blocklist'ler genellikle honeypot ağları, saldırı raporları, kötü amaçlı yazılım analiz sistemleri ve topluluk katkılarından beslenir. Bir IP'nin listeye girmesi için genellikle birden fazla kaynaktan doğrulanmış kötü amaçlı davranış gerekir. Blocklists are typically fed by honeypot networks, attack reports, malware analysis systems, and community contributions. An IP usually needs verified malicious behavior from multiple sources before being added.
Genel AmaçlıGeneral Purpose
Tarama, brute-force, spam gibi çeşitli kötü amaçlı davranışları kapsayan geniş kapsamlı listeler.Broad lists covering various malicious behaviors like scanning, brute-force, and spam.
Botnet C2Botnet C2
Botnet komuta-kontrol (C2) sunucularına özel listeler — Feodo Tracker gibi kaynaklardan beslenir.Lists specific to botnet command-and-control (C2) servers — fed from sources like Feodo Tracker.
Phishing / Malware DağıtımıPhishing / Malware Distribution
Kimlik avı sayfaları veya zararlı yazılım barındıran/dağıtan IP ve domain'leri kapsar.Covers IPs and domains hosting or distributing phishing pages or malware.
Ülke / ASN BazlıCountry / ASN Based
Belirli bir ülke veya sağlayıcıya ait tüm IP bloklarını kapsayan geo-blocking listeleri.Geo-blocking lists covering all IP blocks belonging to a specific country or provider.
Güvendiğiniz bir kaynaktan blocklist'i TXT, CIDR veya platformunuza özel formatta (FortiGate CLI, iptables vb.) indirin.Download the blocklist from a trusted source in TXT, CIDR, or platform-specific format (FortiGate CLI, iptables, etc.).
Firewall'unuzda bir engelleme kuralı veya adres grubu oluşturup listeyi bu gruba bağlayın.Create a blocking rule or address group in your firewall and link the list to it.
Mümkünse otomatik güncelleme kurun — statik bir liste zamanla eskir, güncel kalmayan bir blocklist yeni tehditleri yakalayamaz.Set up automatic updates if possible — a static list goes stale over time, and an outdated blocklist won't catch new threats.
Engellenen bağlantıları loglayın — bu hem görünürlük sağlar hem de yanlış pozitif şüphesi durumunda geriye dönük inceleme imkanı verir.Log blocked connections — this provides visibility and lets you investigate retroactively if you suspect a false positive.
Yanlış pozitif riski: Hiçbir blocklist %100 hatasız değildir. Dinamik IP dağıtan ağlarda, bir zamanlar kötü amaçlı olan bir adres zamanla meşru bir kullanıcıya geçebilir. Kaliteli blocklist sağlayıcıları bunun için "aging" (yaşlandırma) mekanizması kullanır — belirli bir süre yeni tespit gelmezse IP listeden otomatik düşer. False positive risk: No blocklist is 100% error-free. On networks with dynamic IP allocation, an address once malicious can later pass to a legitimate user. Quality blocklist providers use an "aging" mechanism for this — if no new detection occurs within a set period, the IP is automatically removed from the list.
SiberKapan'ın Blocklist'leriSiberKapan's Blocklists
41844 onaylı IP, TXT/JSON/CIDR/FortiGate CLI/iptables formatlarında, ücretsiz erişilebilir.41844 approved IPs, freely accessible in TXT/JSON/CIDR/FortiGate CLI/iptables formats.