ngx-http-blocklistd
This is a simple module for nginx that communicates offending connections (IPs and ports) that visits honeypot locations to blocklistd.
Building and installing
To build it and run it, you need the source code of nginx. To match your current system, run nginx -V and obtain the matching version.
This is an example of building the module on a FreeBSD 15.1 system:
mkdir -p /opt
cd /opt
git clone https://code.petermolnar.net/ngx-http-blocklistd
wget https://nginx.org/download/nginx-1.30.4.tar.gz
tar xf nginx-1.30.4.tar.gz
cd nginx
make clean
./configure --prefix=/usr/local/etc/nginx --with-cc-opt='-I /usr/local/include' --conf-path=/usr/local/etc/nginx/nginx.conf --sbin-path=/usr/local/sbin/nginx --pid-path=/var/run/nginx.pid --error-log-path=/var/log/nginx/error.log --user=www --group=www --with-compat --with-pcre --modules-path=/usr/local/libexec/nginx --with-file-aio --http-client-body-temp-path=/var/tmp/nginx/client_body_temp --http-fastcgi-temp-path=/var/tmp/nginx/fastcgi_temp --http-proxy-temp-path=/var/tmp/nginx/proxy_temp --http-scgi-temp-path=/var/tmp/nginx/scgi_temp --http-uwsgi-temp-path=/var/tmp/nginx/uwsgi_temp --http-log-path=/var/log/nginx/access.log --with-ld-opt='-L /usr/local/lib' --add-dynamic-module=/opt/ngx-http-blocklistd
make modules
cp -a objs/ngx_http_blocklistd_module.so /usr/local/libexec/nginx/ngx_http_blocklistd_module.so
Once done, add it to your nginx.conf:
load_module /usr/local/libexec/nginx/ngx_http_blocklistd.so;
[...]
http {
[...]
server {
[...]
location xyz {
blocklistd;
}
}
}
Notes
nginx needs a restart for all this to work properly. Changes, like including a new module were not picked up by reload.
Also: the blocklistd keyword takes over the processing of the location, but not the access level stage. It means that for example, rate limiting can be applied.
The module returns and internal HTTP 499 which terminates the connection as fast as possible.
Verifying
To verify if it’s running and sending signals you can either watch blocklistctl dump and/or turn on debug error logging in nginx by adding debug at the end of your error_log config line, like error_log /var/log/nginx/error.log debug.
blocklistctl dump -a
blocklistd 212.96.81.209/32:443 1/3 2026/09/19 14:26:39
blocklistd 176.191.96.103/32:443 1/3 2026/09/19 14:49:16
blocklistd 77.30.177.90/32:443 1/3 2026/09/19 15:05:50
blocklistd 165.101.180.152/32:443 1/3 2026/09/19 15:19:37
blocklistd 109.172.187.226/32:443 1/3 2026/09/19 16:04:49
blocklistd 116.179.33.78/32:443 1/3 2026/09/19 16:20:22
blocklistd 188.26.195.253/32:443 1/3 2026/09/19 16:49:16
blocklistd 85.86.59.80/32:443 1/3 2026/09/19 17:15:08
blocklistd 39.109.119.43/32:443 1/3 2026/09/19 18:06:57
blocklistd 176.18.70.175/32:443 1/3 2026/09/19 14:04:56
[...]
pf and blocklistd configuration
For blocklistd to work with pf you need to add it to your pf.conf:
table <blocklistd> persist
[...]
anchor "blocklistd/*"
block in from <blocklistd>
You’ll aso need to extend /etc/blocklistd.conf with http and https entries:
[local]
ssh stream * * * 3 24h
ftp stream * * * 3 24h
smtp stream * * * 3 24h
submission stream * * * 3 24h
submissions stream * * * 3 24h
http stream * * * 3 24h
https stream * * * 3 24h
To list the IPs:
pfctl -a blocklistd/80 -t port80 -T show
pfctl -a blocklistd/443 -t port443 -T show