# Cleaning house It's been a while since I did any analysis of my gopher logs and, I wasn't happy with what I found. There has been ongoing abuse from several hosts. The admin of the envs.net pubnix has been informed that both their IPv4 and IPv6 addresses have been blacklisted due to persistent abuse and has been provided with all the log files to back it up. Should they decide to take action to deal with the the abuse and remove the culprits from their system, then I will reconsider the blacklist. I expect better from pubnix and smol-net folks, sadly on more than one occasion I have been disappointed... When I become aware of such abuses, the result is a persistent pf blacklist of your host address. My writing, code and services are all provided freely with hosting paid for out of my own pocket. All I ask in return is a little respect for my infrastructure. ## Update 20/08/2026 Today's lucky winner is gopher.someodd.zip who has on a number of occasions decided to [scrape my entire article catalogue][1]. Not being in the mood for such transgressions, especially from within the halls of gopher, they've earned themselves a permanent fixture in my persistent pf blacklist. It's one thing to be attacked from outside, but quite another when it is from within... [Blacklisted hosts and ranges][2], you may find it useful. It's on a daily cron so, it'll stay current. [1]: gopher://gopher.icu/0/files/someodd.txt [2]: gopher://gopher.icu/0/files/blacklist.txt ## Update 22/08/2026 The ban hammer has been falling hard and fast today as, I've been monitoring connections to the server and playing whack-a-mole. The blacklist is curated by me personally, adding hosts I see causing issues, and also programmatically by a script looking for hosts attempting to connect using unknown usernames. There is no password login enabled here, the reward for trying is a place in the blacklist. The proxy at meuli.net has now also been added to the list. I don't want people using proxies to avoid blacklists. ## Update 29/08/2026 Today's lucky winner is an [ecotel.net][3] host. It appears to have been trying to scrape all my articles but, couldn't even manage to do that correctly, with multiple downloads of the same file. I'm becoming increasingly intolerant of this BS and so starting to blacklist whole subnets. Unfortunately it's like carpet-bombing and you know innocent people are going to get caught in the crossfire. If you should find that you can no longer access gopher.icu then, this is likely the reason. [3]: gopher://gopher.icu/0/files/ecotel.net.txt ## Update 30/08/2026 Today's lucky winner is an [railtel.in][4] host. Same stupidity as the last one and the same result, total subnet blacklist. [4]: gopher://gopher.icu/0/files/railtel.in.txt ## Update 04/09/2026 Today's lucky winner is an [hetzner.com][5] host. Same stupidity as the last one but, this time I have sent the log to abuse@hetzner.com and not blocked the entire subnet. I did inform them that if I see any more of this kind of thing from this subnet, the result will be a subnet blacklist. A second [hetzner.com][6] host also made it into the blacklist for repeated ssh brute force login attempts. This one got reported to abuse@hetzner.com and the whole subnet blacklisted. [5]: gopher://gopher.icu/0/files/hetzner.txt [6]: gopher://gopher.icu/0/files/hetzner2.txt