HubIPList / Docs

Documentation

Everything you need to point a firewall at a HubIPList feed and keep it updated automatically.

Quick start

Create a list in the console, pick your firewall vendor, and copy the URL it gives you. The feed refreshes on its own; your firewall pulls it on the schedule you set.

Firewall integration

Replace YOUR-LIST with the identifier shown in the console.

Palo Alto Networks (PAN-OS)

External Dynamic List

  1. Go to Objects → External Dynamic Lists and click Add.
  2. Set Type to IP List and paste the feed URL below into Source.
  3. Choose a Repeat interval of hourly or five minutes.
  4. Click Test Source URL to confirm the firewall can reach it, then Commit.
  5. Reference the list in a security policy rule as a source or destination address.

Feed URL

https://hubiplist.com/feeds/YOUR-LIST/paloalto.txt

Fortinet FortiGate

External IP Feed (Threat Feed)

  1. Go to Security Fabric → External Connectors and add an IP Address threat feed.
  2. Paste the feed URL below into the URI of external resource field.
  3. Set Refresh Rate to 5 minutes or more.
  4. Use View Entries to confirm the addresses are loading.
  5. Reference the connector as an address object in a firewall policy.

Feed URL

https://hubiplist.com/feeds/YOUR-LIST/fortigate.txt

SonicWall

Dynamic External Address Group (DEAG)

  1. Go to Object → Match Objects → Addresses and create a Dynamic External Address Group.
  2. Paste the feed URL below and set the download interval.
  3. Save and wait for the first download to complete.
  4. Use the group in an access rule.

Feed URL

https://hubiplist.com/feeds/YOUR-LIST/sonicwall.txt

Check Point

External Network Feed

  1. In SmartConsole go to Security Policies → Shared Policies → Updatable Objects.
  2. Add an External Network Feed and paste the feed URL below.
  3. Set the format to Flat list and the refresh interval.
  4. Install policy for the change to take effect.

Feed URL

https://hubiplist.com/feeds/YOUR-LIST/checkpoint.txt

Linux (nftables / ipset)

set import

  1. Download the feed with curl on a schedule (cron or a systemd timer).
  2. Load the addresses into a named set and reference that set from your rules.
  3. Keep the previous set until the new one loads: a failed download should never empty your blocklist.

Feed URL

https://hubiplist.com/feeds/YOUR-LIST/nftables.txt

Feed formats

Every list is served in several formats. The extension decides what you get.

FormatContents
.txtOne address or CIDR per line. Works with every vendor above.
.csvAddress, source and first seen date. For spreadsheets and reports.
.jsonStructured output with provenance for automation.

Public catalogue

Nearly sixty provider ranges are published without an account — Cloudflare, AWS, Azure, Microsoft 365, Google Cloud, Zoom, Fastly and more. Use them to allow legitimate infrastructure instead of blocking it by accident.

https://hubiplist.com/lists/cloudflare
https://hubiplist.com/lists/fastly
https://hubiplist.com/lists/bunny

The catalogue also publishes threat blocklists computed from our own intelligence — botnet C2 servers, brute-force sources, compromised hosts, do-not-route networks and a consensus list of addresses flagged by two or more independent sources at once. They refresh continuously; point your firewall at the .txt URL and it stays current on its own.

https://hubiplist.com/feeds/public/blocklists/consenso.txt
https://hubiplist.com/feeds/public/blocklists/botnet-c2.txt
https://hubiplist.com/feeds/public/blocklists/no-enrutar.txt

API

Read-only endpoints, no authentication required.

MethodEndpointContents
GET/api/search?ip=1.1.1.1Full investigation of one address.
GET/api/providersPublic provider catalogue.
GET/api/blocklistsThreat blocklist catalogue with live counts.
GET/api/geoContext feed catalogue: countries with range counts, ASN feed template and Tor exit status with its context warning.
GET/feeds/public/geo/ES.txtIPv4 CIDRs delegated to a country (ISO 3166-1 alpha-2), from the five RIRs. One CIDR per line; 400 on a bad code.
GET/feeds/public/asn/15169.txtPrefixes announced by an ASN, per RIPEstat (24 h cache). 400 on a bad ASN, 503 if RIPEstat is down with no cached copy.
GET/feeds/public/tor-exits.txtTor Project exit nodes. CONTEXT ONLY: an exit node is not malicious per se — do not block blindly.
GET/feeds/public/geo/ES.sha256SHA-256 checksum of the geo feed, in sha256sum format (also /feeds/public/asn/ASN.sha256 and /feeds/public/tor-exits.sha256).
GET/feeds/public/blocklists/consenso.txtConsensus blocklist feed (also .csv and .json; other slugs: botnet-c2, brute-force, compromised, no-enrutar).
GET/feeds/public/blocklists/consenso.sha256SHA-256 checksum of the .txt feed, in sha256sum format (also /feeds/public/PROVIDER/generic.txt.sha256).
GET/api/transparency/manifestDaily-signable manifest: count and SHA-256 of every public feed.
GET/api/transparency/ip-history?ip=1.1.1.1Public history of an address: sources, dates and why it no longer applies.
GET/api/my-ipThe caller’s own public address.
GET/api/intel/summaryIndicator counts per source.

Rate limits

Feeds allow 20 requests per 10 seconds per IP. A firewall pulling every 5–60 minutes is far below that. Searches are limited to 30 per minute.

Integrity and transparency

Every public list is generated mechanically from the sources it cites. Nobody edits them by hand — there is no manual step that could quietly add or remove an address. When the underlying evidence expires or is withdrawn by its source, the entry drops out of the list on the next regeneration, on its own.

Every feed carries its SHA-256 checksum, served by this same API in sha256sum format. Download the list and its checksum and verify one against the other:

https://hubiplist.com/feeds/public/blocklists/consenso.sha256
https://hubiplist.com/feeds/public/cloudflare/generic.txt.sha256

Once a day we publish a manifest with the entry count and the SHA-256 of every public list, committed to a public third-party repository, github.com/Hoshikaapp/hubiplist-transparencia. The commit history timestamps every change: if an address disappears from a list, the day it happened stays on record.

https://hubiplist.com/api/transparency/manifest

The history of any address is public too: which sources listed it, since when, until when, and why it no longer applies (the evidence expired or the source withdrew it):

https://hubiplist.com/api/transparency/ip-history?ip=1.1.1.1

And none of this requires trusting us: you can verify any IP against the original sources, which we do not control.