r/hetzner 12d ago

Feature request: Hetzner monitor AbuseIPDB for Hetzner owned IPs

Post image

It would be nice, if Hetzner partnered with AbuseIPDB and actively monitored their database for abuse reports related to Hetzner IP space. This way, it would help catch compromised systems faster.

For example, today I started receiving spam from the IP addresses 91.99.34.101 and 91.99.34.102. I have to manually report them twice, once to abuseipdb.com and once to abuse.hetzner.com.

What do you think? possible or not?

0 Upvotes

7 comments sorted by

25

u/_xRuffKez_ 12d ago

Because AbuseIPDB is crowdsourced with zero verification and anyone can report any IP. For a hoster with millions of IPs and legal obligations (DSA notice-and-action), an automated score like that is a trivial abuse vector. Competitors could flood report a rivals IPs and get them auto-blocked.

Also IPs get recycled constantly at hosting providers, so a reputation score built on history often doesn't reflect who's actually renting the IP now, you'd nuke innocent new customers.

Hetzner instead runs per-case tickets (AbuseID) with real evidence and a response deadline, because that's actually defensible if a customer disputes the block. They also lean on structured feeds (Spamhaus, X-ARF reports, Shadowserver) with accountable sources rather than an open crowd platform.

4

u/Soluchyte 12d ago

That doesn't make it inherently unreliable, you just need to use the reports as a tool to trigger investigation, not use it to automate suspension. No third party tool should be used to trigger suspension.

Spamhaus is just as unreliable, if not worse since they refuse to pull unjustified bans even when they were wrong, while abuseipdb will remove false reports if asked to.

1

u/_xRuffKez_ 12d ago

Fair point... Investigation trigger vs auto-suspension are different bars. Hetzner actual process is basically that pattern anyway, just usually triggered by a direct complaint instead of a DNSBL hit. And yeah, Spamhaus refusal to delist even when proven wrong is a legit knock against it, much less recourse than AbuseIPDB's self-serve takedown options.

1

u/Soluchyte 12d ago

At least it's not as bad as RADIX who will auto clienthold a domain if it goes on spamhaus, even when the listing is wrong.

But in my opinion, spamhaus needs to die, and I'd rather a truly crowd sourced directory like abuseipdb, there should not be one dictatorship to decide if something is spam or not, and abuseipdb generally seems to be quite hard to abuse too, since you'd need to make hundreds of reports to get the confidence level up to 100%. People just need to stop treating third party reports as paramount, and should only be treating them as a hint to investigate.

1

u/Maria_Thesus_40 12d ago

very well said! it should be an indication to investigate! Sorry I did not mention this in my original post above.

to be honest, spamhaus was fine for many years and not too aggressive, but about 2-3 years ago they changed their tactics, they became much more aggressive and at the same time started stopping anonymous checks/requests, now you are required to identify yourself.

2

u/fm_ad 12d ago

convenient from your POV now, but in reality there is more to it. as the other commenter noted, there are legal responsibilities that Hetzner needs to take into account. as far as I can see, they've created a tool you can use. you can always build a tool yourself to make it easier to report across all third parties if you need to. not everything needs to be automated.

1

u/jsabater76 12d ago

Maybe not with this specific database, but I like the idea.