Ana SayfaHome Tehdit VeritabanıThreat Database Tehdit RaporlarıThreat Reports BlogBlog
RehberlerGuides
Tehdit İstihbaratı Nedir?What Is Threat Intelligence? MISP Nedir?What Is MISP? IP Blocklist Nedir?What Is an IP Blocklist? FortiGate'e Feed EklemeAdd Feed to FortiGate Ücretsiz CTİ KaynaklarıFree CTI Resources
Veri & ListelerData & Lists
Tüm ListelerAll Lists Feed ListeleriFeed Lists USOM Domain FeedUSOM Domain Feed SiberKapan Phishing URL FeedSiberKapan Phishing URL Feed FortiGate Saldırı HaritasıFortiGate Attack Map BGP / IP SorgulaBGP / IP Lookup Malware ÖrnekleriMalware Samples
Sisteminize EkleyinAdd to Your System
🔓 Feed Ekleme Rehberi🔓 Feed Setup Guide MISP Feed TAXII 2.1 STIX 2.1 RSS CVE Feed RSS IOC Feed
Veri GönderinContribute Data
FortiGate Webhook KurulumuFortiGate Webhook Setup HoneypotKapan KurSetup HoneypotKapan Nginx Watcher KurSetup Nginx Watcher API DokümantasyonAPI Documentation
HakkındaAbout
HakkımızdaAbout Us MetodolojiMethodology BaşarılarAchievements İletişimContact
Rehber Guide

IP Blocklist Nedir? Nasıl Kullanılır? What Is an IP Blocklist? How Is It Used?

IP blocklist'in ne olduğu, türleri, firewall'a nasıl ekleneceği ve dikkat edilmesi gereken riskler. What an IP blocklist is, its types, how to add one to a firewall, and the risks to watch for.

Tanım Definition

IP blocklist (IP kara listesi), kötü amaçlı faaliyetleriyle bilinen IP adreslerinin listesidir. Bir firewall, mail sunucusu veya web sunucusu bu listeyi kullanarak, listedeki adreslerden gelen bağlantıları otomatik olarak reddedebilir. Amaç, bilinen bir tehdidin sisteminize ulaşmadan önce, "kapıda" durdurulmasıdır. An IP blocklist is a list of IP addresses known for malicious activity. A firewall, mail server, or web server can use this list to automatically reject connections from those addresses. The goal is to stop a known threat "at the door," before it reaches your system.

Blocklist'ler genellikle honeypot ağları, saldırı raporları, kötü amaçlı yazılım analiz sistemleri ve topluluk katkılarından beslenir. Bir IP'nin listeye girmesi için genellikle birden fazla kaynaktan doğrulanmış kötü amaçlı davranış gerekir. Blocklists are typically fed by honeypot networks, attack reports, malware analysis systems, and community contributions. An IP usually needs verified malicious behavior from multiple sources before being added.

Blocklist Türleri Types of Blocklists

Genel AmaçlıGeneral Purpose

Tarama, brute-force, spam gibi çeşitli kötü amaçlı davranışları kapsayan geniş kapsamlı listeler.Broad lists covering various malicious behaviors like scanning, brute-force, and spam.

Botnet C2Botnet C2

Botnet komuta-kontrol (C2) sunucularına özel listeler — Feodo Tracker gibi kaynaklardan beslenir.Lists specific to botnet command-and-control (C2) servers — fed from sources like Feodo Tracker.

Phishing / Malware DağıtımıPhishing / Malware Distribution

Kimlik avı sayfaları veya zararlı yazılım barındıran/dağıtan IP ve domain'leri kapsar.Covers IPs and domains hosting or distributing phishing pages or malware.

Ülke / ASN BazlıCountry / ASN Based

Belirli bir ülke veya sağlayıcıya ait tüm IP bloklarını kapsayan geo-blocking listeleri.Geo-blocking lists covering all IP blocks belonging to a specific country or provider.

Nasıl Kullanılır? How Is It Used?
1

Güvendiğiniz bir kaynaktan blocklist'i TXT, CIDR veya platformunuza özel formatta (FortiGate CLI, iptables vb.) indirin.Download the blocklist from a trusted source in TXT, CIDR, or platform-specific format (FortiGate CLI, iptables, etc.).

2

Firewall'unuzda bir engelleme kuralı veya adres grubu oluşturup listeyi bu gruba bağlayın.Create a blocking rule or address group in your firewall and link the list to it.

3

Mümkünse otomatik güncelleme kurun — statik bir liste zamanla eskir, güncel kalmayan bir blocklist yeni tehditleri yakalayamaz.Set up automatic updates if possible — a static list goes stale over time, and an outdated blocklist won't catch new threats.

4

Engellenen bağlantıları loglayın — bu hem görünürlük sağlar hem de yanlış pozitif şüphesi durumunda geriye dönük inceleme imkanı verir.Log blocked connections — this provides visibility and lets you investigate retroactively if you suspect a false positive.

Yanlış pozitif riski: Hiçbir blocklist %100 hatasız değildir. Dinamik IP dağıtan ağlarda, bir zamanlar kötü amaçlı olan bir adres zamanla meşru bir kullanıcıya geçebilir. Kaliteli blocklist sağlayıcıları bunun için "aging" (yaşlandırma) mekanizması kullanır — belirli bir süre yeni tespit gelmezse IP listeden otomatik düşer. False positive risk: No blocklist is 100% error-free. On networks with dynamic IP allocation, an address once malicious can later pass to a legitimate user. Quality blocklist providers use an "aging" mechanism for this — if no new detection occurs within a set period, the IP is automatically removed from the list.

SiberKapan'ın Blocklist'leriSiberKapan's Blocklists

41844 onaylı IP, TXT/JSON/CIDR/FortiGate CLI/iptables formatlarında, ücretsiz erişilebilir.41844 approved IPs, freely accessible in TXT/JSON/CIDR/FortiGate CLI/iptables formats.

Listeleri İncele Browse Lists