<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>PARC Network — Managed Hosting-Architektur für deinen Magento Shop! on Magento Managed Hosting von und für Shopbetreiber</title><link>https://www.parc-network.de/</link><description>Recent content in PARC Network — Managed Hosting-Architektur für deinen Magento Shop! on Magento Managed Hosting von und für Shopbetreiber</description><generator>Hugo</generator><language>de-DE</language><atom:link href="https://www.parc-network.de/index.xml" rel="self" type="application/rss+xml"/><item><title>A10 Networks — per-IP self-ID via a10protects.com</title><link>https://www.parc-network.de/a10/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://www.parc-network.de/a10/</guid><description>&lt;p class="lead"&gt;&lt;strong&gt;Research-Scanner&lt;/strong&gt; von A10 Networks (a10protects.com). Kein SEO-Tool. Die Scan-IPs sind &lt;strong&gt;self-identifizierend&lt;/strong&gt;: Reverse-DNS &lt;span class="mono"&gt;autoscan-*.research.a10protects.com&lt;/span&gt;. Entdeckt im &lt;a href="https://www.parc-network.de/cins/"&gt;CINS-Abgleich&lt;/a&gt; und per Nachbar-Range-Scan vervollständigt — jede IP einzeln reverse-bestätigt (5). Teil unseres &lt;a href="https://www.parc-network.de/parc-security/"&gt;PARC-Security-Feeds&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;&lt;a href="https://www.parc-network.de/feeds/a10.json" target="_blank" rel="noopener" class="btn btn-secondary"&gt;a10.json — Feed ansehen&lt;/a&gt; &amp;nbsp; &lt;a href="https://www.a10networks.com/" target="_blank" rel="noopener"&gt;www.a10networks.com →&lt;/a&gt;&lt;/p&gt;
&lt;h2 id="verifikation--jede-ip-einzeln"&gt;Verifikation — jede IP einzeln&lt;/h2&gt;
&lt;p&gt;Den Reverse-PTR &lt;span class="mono"&gt;autoscan-*.research.a10protects.com&lt;/span&gt; kann nur der IP-Betreiber setzen — ein nicht-fälschbarer Eigentums-Hinweis. Seed aus den &lt;strong&gt;aktiv scannenden CINS-IPs&lt;/strong&gt;, per Reverse-Scan der umliegenden /24 vervollständigt; jede IP einzeln bestätigt:&lt;/p&gt;
&lt;pre tabindex="0"&gt;&lt;code&gt;5 IPs → alle PTR a10protects.com
&lt;/code&gt;&lt;/pre&gt;&lt;p&gt;Reverse-only (Forward nicht durchgängig prüfbar, wie bei Shodan/Infrawatch). AbuseIPDB führt diese IPs teils mit Score 100 — es sind dennoch benigne Research-Scanner.&lt;/p&gt;</description></item><item><title>Adyen — offizielle IP-Ranges (Webhook/API)</title><link>https://www.parc-network.de/adyen/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://www.parc-network.de/adyen/</guid><description>&lt;p class="lead"&gt;&lt;strong&gt;Adyen&lt;/strong&gt; (NL) ist ein Zahlungsanbieter. Dies sind die &lt;strong&gt;offiziellen IP-Ranges&lt;/strong&gt;, unter denen Adyens Webhook-/API-Server senden bzw. erreichbar sind — aus der offiziellen Quelle zu PARC-Feed normalisiert (11 Einträge). Teil unseres &lt;a href="https://www.parc-network.de/parc-security/"&gt;PARC-Security-Feeds&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;&lt;a href="https://www.parc-network.de/feeds/adyen.json" target="_blank" rel="noopener" class="btn btn-secondary"&gt;adyen.json — Feed ansehen&lt;/a&gt; &amp;nbsp; &lt;a href="https://www.adyen.com/" target="_blank" rel="noopener"&gt;www.adyen.com →&lt;/a&gt;&lt;/p&gt;
&lt;h2 id="quelle--aktualisierung"&gt;Quelle &amp;amp; Aktualisierung&lt;/h2&gt;
&lt;p&gt;Quelle: &lt;span class="mono"&gt;Adyen-Doku (Allowlisting) + out.adyen.com&lt;/span&gt; — offiziell publiziert. Aus der Anbieter-Doku übernommen. Adyen kann die Ranges jederzeit ändern; der PARC-Feed bildet den offiziellen Stand ab. Reine IP-Daten ohne Wertung.&lt;/p&gt;
&lt;h2 id="quellen"&gt;Quellen&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://www.adyen.com/" target="_blank" rel="noopener"&gt;Adyen&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://docs.adyen.com/development-resources/security/integration-security/allowlisting" target="_blank" rel="noopener"&gt;Offizielle IP-Quelle&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;p style="margin-top: 40px;"&gt;&lt;a href="https://www.parc-network.de/parc-security/" class="btn btn-secondary"&gt;← Zurück zu PARC Security&lt;/a&gt; &amp;nbsp; &lt;a href="https://www.parc-network.de/#kontakt" class="btn btn-primary"&gt;Kontakt aufnehmen&lt;/a&gt;&lt;/p&gt;</description></item><item><title>Alpha Strike Labs — die /22 ist verzahnt, nicht block-fremd</title><link>https://www.parc-network.de/alphastrike/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://www.parc-network.de/alphastrike/</guid><description>&lt;p class="lead"&gt;Alpha Strike Labs GmbH (Deutschland) betreibt einen internet-weiten &lt;strong&gt;Security-Research-Scanner&lt;/strong&gt; aus der &lt;strong&gt;eigenen ASN AS208843&lt;/strong&gt;. Kein SEO-Tool. Identifiziert wird über &lt;strong&gt;ASN-Eigentum&lt;/strong&gt; (BGP/RDAP) — aber der Knackpunkt: einer der zwei /22-Blöcke ist &lt;strong&gt;auf IP-Ebene mit fremden ASNs verzahnt&lt;/strong&gt;. Nur die &lt;strong&gt;per-IP-Prüfung&lt;/strong&gt; jeder einzelnen Adresse liefert die sauberen &lt;strong&gt;~1.700 IPs&lt;/strong&gt;. Teil unseres &lt;a href="https://www.parc-network.de/parc-security/"&gt;PARC-Security-Feeds&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;&lt;a href="https://www.parc-network.de/feeds/alphastrike.json" target="_blank" rel="noopener" class="btn btn-secondary"&gt;alphastrike.json — Feed ansehen&lt;/a&gt; &amp;nbsp; &lt;a href="https://www.alphastrike.io/" target="_blank" rel="noopener"&gt;alphastrike.io →&lt;/a&gt;&lt;/p&gt;
&lt;h2 id="die-nadel-im-heuhaufen--in-beide-richtungen"&gt;Die Nadel im Heuhaufen — in beide Richtungen&lt;/h2&gt;
&lt;p&gt;Wir haben &lt;strong&gt;jede der 2.048 Adressen&lt;/strong&gt; beider bei AS208843 gelisteter /22 einzeln auf ihre Origin-ASN geprüft (massdns gegen Team Cymru, mehrfach). Ergebnis:&lt;/p&gt;</description></item><item><title>BinaryEdge — offizielle Minion-API, FCrDNS-bestätigt</title><link>https://www.parc-network.de/binaryedge/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://www.parc-network.de/binaryedge/</guid><description>&lt;p class="lead"&gt;&lt;strong&gt;BinaryEdge&lt;/strong&gt; (Coalition, US/PT) betreibt einen internet-weiten &lt;strong&gt;Security-Scanner&lt;/strong&gt;. Kein SEO-Tool. Die Scan-Knoten („Minions“) sind &lt;strong&gt;offiziell&lt;/strong&gt; per API gelistet (api.binaryedge.io/v1/minions). Wir haben jede der 6.412 gelisteten IPs per &lt;strong&gt;FCrDNS&lt;/strong&gt; geprüft. Teil unseres &lt;a href="https://www.parc-network.de/parc-security/"&gt;PARC-Security-Feeds&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;&lt;a href="https://www.parc-network.de/feeds/binaryedge.json" target="_blank" rel="noopener" class="btn btn-secondary"&gt;binaryedge.json — Feed ansehen&lt;/a&gt; &amp;nbsp; &lt;a href="https://www.binaryedge.io/" target="_blank" rel="noopener"&gt;www.binaryedge.io →&lt;/a&gt;&lt;/p&gt;
&lt;h2 id="verifikation--jede-ip-einzeln"&gt;Verifikation — jede IP einzeln&lt;/h2&gt;
&lt;p&gt;Aus der offiziellen API kamen 6.412 IPv4-Minions. Wir vertrauen der Liste nicht blind, sondern haben &lt;strong&gt;jede IP per Forward-Confirmed Reverse DNS&lt;/strong&gt; geprüft: PTR muss auf &lt;span class="mono"&gt;prod-*-&amp;lt;region&amp;gt;-N.awp.binaryedge.ninja&lt;/span&gt; zeigen und der Forward-A-Record wieder auf dieselbe IP.&lt;/p&gt;</description></item><item><title>BitSight Internet Census — die 17 Scanner-/24, ASN-Eigentum und FCrDNS-Methodik</title><link>https://www.parc-network.de/bitsight/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://www.parc-network.de/bitsight/</guid><description>&lt;p class="lead"&gt;BitSight betreibt unter der Marke „Internet Census Group" einen internet-weiten Security-/Asset-Discovery-Scanner — vergleichbar mit Shodan, Censys oder &lt;a href="https://www.parc-network.de/parc-security/#internet-scanner"&gt;Driftnet&lt;/a&gt;. Anders als Driftnet publiziert BitSight aber &lt;strong&gt;keine offizielle IP-Liste&lt;/strong&gt;, sondern nur eine FCrDNS-Methodik. Hier die &lt;strong&gt;empirisch ermittelten 17 /24&lt;/strong&gt; (Teil unseres &lt;a href="https://www.parc-network.de/parc-security/"&gt;PARC-Security-Feeds&lt;/a&gt;) und wie wir sie über ASN-Eigentum und Reverse-DNS verifiziert haben.&lt;/p&gt;
&lt;p&gt;&lt;a href="https://www.parc-network.de/feeds/bitsight.json" target="_blank" rel="noopener" class="btn btn-secondary"&gt;bitsight.json — Feed ansehen&lt;/a&gt; &amp;nbsp; &lt;a href="https://www.internet-census.org/" target="_blank" rel="noopener"&gt;internet-census.org →&lt;/a&gt;&lt;/p&gt;
&lt;h2 id="die-ermittelten-ranges"&gt;Die ermittelten Ranges&lt;/h2&gt;
&lt;p&gt;Insgesamt &lt;strong&gt;4.352 IPs&lt;/strong&gt; in 17 × /24:&lt;/p&gt;
&lt;pre tabindex="0"&gt;&lt;code&gt;45.156.128.0/24 185.180.142.0/24
45.156.129.0/24 185.180.143.0/24
45.156.130.0/24 185.226.196.0/24
45.156.131.0/24 185.226.197.0/24
109.105.208.0/24 185.226.198.0/24
109.105.209.0/24 185.226.199.0/24
109.105.210.0/24 185.117.225.0/24
109.105.211.0/24 185.180.140.0/24
185.180.141.0/24
&lt;/code&gt;&lt;/pre&gt;&lt;p&gt;Diese Liste gibt es nicht als offiziellen Download — wir haben sie aus dem ASN-Eigentum von &lt;strong&gt;AS211680&lt;/strong&gt; (NSEC, RIPE-Stat) abgeleitet und per FCrDNS gegen &lt;code&gt;*.internet-census.org&lt;/code&gt; validiert. Alle 17 /24 sind NSEC-Eigentum (IRR + RPKI valid).&lt;/p&gt;</description></item><item><title>Braintree — offizielle IP-Ranges (Webhook/API)</title><link>https://www.parc-network.de/braintree/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://www.parc-network.de/braintree/</guid><description>&lt;p class="lead"&gt;&lt;strong&gt;Braintree&lt;/strong&gt; (US) ist ein Zahlungsanbieter. Dies sind die &lt;strong&gt;offiziellen IP-Ranges&lt;/strong&gt;, unter denen Braintrees Webhook-/API-Server senden bzw. erreichbar sind — aus der offiziellen Quelle zu PARC-Feed normalisiert (46 Einträge). Teil unseres &lt;a href="https://www.parc-network.de/parc-security/"&gt;PARC-Security-Feeds&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;&lt;a href="https://www.parc-network.de/feeds/braintree.json" target="_blank" rel="noopener" class="btn btn-secondary"&gt;braintree.json — Feed ansehen&lt;/a&gt; &amp;nbsp; &lt;a href="https://www.braintreepayments.com/" target="_blank" rel="noopener"&gt;www.braintreepayments.com →&lt;/a&gt;&lt;/p&gt;
&lt;h2 id="quelle--aktualisierung"&gt;Quelle &amp;amp; Aktualisierung&lt;/h2&gt;
&lt;p&gt;Quelle: &lt;span class="mono"&gt;assets.braintreegateway.com/json/ips.json&lt;/span&gt; — offiziell publiziert. Die Liste wird von einem maschinenlesbaren Endpoint nachgezogen. Braintree kann die Ranges jederzeit ändern; der PARC-Feed bildet den offiziellen Stand ab. Reine IP-Daten ohne Wertung.&lt;/p&gt;
&lt;h2 id="quellen"&gt;Quellen&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://www.braintreepayments.com/" target="_blank" rel="noopener"&gt;Braintree&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://assets.braintreegateway.com/json/ips.json" target="_blank" rel="noopener"&gt;Offizielle IP-Quelle&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;p style="margin-top: 40px;"&gt;&lt;a href="https://www.parc-network.de/parc-security/" class="btn btn-secondary"&gt;← Zurück zu PARC Security&lt;/a&gt; &amp;nbsp; &lt;a href="https://www.parc-network.de/#kontakt" class="btn btn-primary"&gt;Kontakt aufnehmen&lt;/a&gt;&lt;/p&gt;</description></item><item><title>bruteforceblocker — SSH-Bruteforce-Blacklist</title><link>https://www.parc-network.de/bruteforceblocker/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://www.parc-network.de/bruteforceblocker/</guid><description>&lt;h2 id="steckbrief-zu-bruteforceblocker"&gt;Steckbrief zu bruteforceblocker&lt;/h2&gt;
&lt;table class="fs-table"&gt;&lt;tr&gt;&lt;th&gt;Kategorie / Angriffsfläche&lt;/th&gt;&lt;td&gt;SSH-Bruteforce (Port 22) — Host-Ebene&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;th&gt;Was es ist&lt;/th&gt;&lt;td&gt;Angreifer-IP-Liste eines SSH-Bruteforce-Schutz-Tools&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;th&gt;Wie IPs auf die Liste kommen&lt;/th&gt;&lt;td&gt;Das Tool wertet die &lt;code&gt;sshd&lt;/code&gt;-Logs teilnehmender Server aus; überschreitet eine IP die Schwelle fehlgeschlagener SSH-Anmeldungen, wird sie lokal geblockt und an die zentrale Projekt-Datenbank gemeldet.&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;th&gt;Aufnahme-Schwelle&lt;/th&gt;&lt;td&gt;mindestens 3 fehlgeschlagene Anmeldeversuche&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;th&gt;Autor&lt;/th&gt;&lt;td&gt;Daniel Gerzo („danger“), FreeBSD-Committer, Slowakei&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;th&gt;Seit wann&lt;/th&gt;&lt;td&gt;v1.0 seit 12.04.2005&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;th&gt;Aktualisierungsintervall&lt;/th&gt;&lt;td&gt;Pull-Takt ~3 h; rollierendes 30-Tage-Fenster (Auto-Delisting inaktiver IPs)&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;th&gt;Aggregiert in&lt;/th&gt;&lt;td&gt;FireHOL Level 3 · ipsum&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;th&gt;Offizielle Seite&lt;/th&gt;&lt;td&gt;&lt;a href="https://danger.rulez.sk/index.php/bruteforceblocker/" target="_blank" rel="noopener"&gt;danger.rulez.sk/index.php/bruteforceblocker&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;th&gt;Feed-Quelle&lt;/th&gt;&lt;td&gt;&lt;a href="https://danger.rulez.sk/projects/bruteforceblocker/blist.php" target="_blank" rel="noopener"&gt;blist.php — Original-Liste (TXT)&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/table&gt;
&lt;h2 id="abgleich-mit-abuseipdb-vom-25062026"&gt;Abgleich mit AbuseIPDB vom 25.06.2026&lt;/h2&gt;
&lt;p&gt;Alle &lt;strong&gt;646 IP-Adressen&lt;/strong&gt; aus dem bruteforceblocker-Feed wurden am 25.06.2026 gegen die &lt;strong&gt;AbuseIPDB&lt;/strong&gt; für einen &lt;strong&gt;30-Tage-Zeitraum&lt;/strong&gt; abgefragt und mit zusätzlichen Informationen ergänzt.&lt;/p&gt;</description></item><item><title>BufferOver — per-IP self-ID via bufferover.run</title><link>https://www.parc-network.de/bufferover/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://www.parc-network.de/bufferover/</guid><description>&lt;p class="lead"&gt;Internet-weiter &lt;strong&gt;TLS-/Zertifikat- und DNS-Scanner&lt;/strong&gt; (BufferOver / dns.bufferover.run, US). Kein SEO-Tool. Die Scan-IPs sind &lt;strong&gt;self-identifizierend&lt;/strong&gt;: Reverse-DNS &lt;span class="mono"&gt;*.scan.bufferover.run&lt;/span&gt;. Entdeckt im &lt;a href="https://www.parc-network.de/cins/"&gt;CINS-Abgleich&lt;/a&gt; und per Nachbar-Range-Scan vervollständigt — jede IP einzeln reverse-bestätigt (28). Teil unseres &lt;a href="https://www.parc-network.de/parc-security/"&gt;PARC-Security-Feeds&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;&lt;a href="https://www.parc-network.de/feeds/bufferover.json" target="_blank" rel="noopener" class="btn btn-secondary"&gt;bufferover.json — Feed ansehen&lt;/a&gt; &amp;nbsp; &lt;a href="http://bufferover.run/" target="_blank" rel="noopener"&gt;bufferover.run →&lt;/a&gt;&lt;/p&gt;
&lt;h2 id="verifikation--jede-ip-einzeln"&gt;Verifikation — jede IP einzeln&lt;/h2&gt;
&lt;p&gt;Den Reverse-PTR &lt;span class="mono"&gt;*.scan.bufferover.run&lt;/span&gt; kann nur der IP-Betreiber setzen — ein nicht-fälschbarer Eigentums-Hinweis. Seed aus den &lt;strong&gt;aktiv scannenden CINS-IPs&lt;/strong&gt;, per Reverse-Scan der umliegenden /24 vervollständigt; jede IP einzeln bestätigt:&lt;/p&gt;
&lt;pre tabindex="0"&gt;&lt;code&gt;28 IPs → alle PTR bufferover.run
&lt;/code&gt;&lt;/pre&gt;&lt;p&gt;Reverse-only (Forward nicht durchgängig prüfbar, wie bei Shodan/Infrawatch). AbuseIPDB führt diese IPs teils mit Score 100 — es sind dennoch benigne Research-Scanner.&lt;/p&gt;</description></item><item><title>Cdiscount (Octopia) — dokumentierte Caller-IPs</title><link>https://www.parc-network.de/cdiscount-marketplace/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://www.parc-network.de/cdiscount-marketplace/</guid><description>&lt;p class="lead"&gt;&lt;strong&gt;Cdiscount&lt;/strong&gt; ist einer der größten französischen Marktplätze; die API läuft inzwischen über &lt;strong&gt;Octopia&lt;/strong&gt;. Octopia ruft den Verkäufer-Server aktiv an (Bestell-/Flow-Verarbeitung) — und nennt dafür in der Doku &lt;strong&gt;zwei feste Quell-IPs&lt;/strong&gt;: &lt;span class="mono"&gt;62.122.8.8&lt;/span&gt; und &lt;span class="mono"&gt;62.122.15.8&lt;/span&gt;. Teil unseres &lt;a href="https://www.parc-network.de/parc-security/"&gt;PARC-Security-Feeds&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;&lt;a href="https://www.parc-network.de/feeds/cdiscount-marketplace.json" target="_blank" rel="noopener" class="btn btn-secondary"&gt;cdiscount-marketplace.json — Feed ansehen&lt;/a&gt; &amp;nbsp; &lt;a href="https://developer.octopia-io.net/user-guides/best-practices/" target="_blank" rel="noopener"&gt;developer.octopia-io.net →&lt;/a&gt;&lt;/p&gt;
&lt;h2 id="quelle--aktualisierung"&gt;Quelle &amp;amp; Aktualisierung&lt;/h2&gt;
&lt;p&gt;Quelle: Octopia API — Best Practices. Wortlaut: „Our systems will be calling yours only from these public IPs.&amp;quot; Beide Adressen liegen in Cdiscounts eigenem ASN &lt;span class="mono"&gt;AS48744&lt;/span&gt; (RIPE, FR; &lt;span class="mono"&gt;62.122.8.8&lt;/span&gt; löst rückwärts auf &lt;span class="mono"&gt;cd-62.122.8.8.cdiscount.com&lt;/span&gt; auf — eigene Infrastruktur, per Team-Cymru-ASN-Lookup geprüft). Octopia merkt an, dass diese Calls ohne &lt;span class="mono"&gt;User-Agent&lt;/span&gt;-Header kommen. Der PARC-Feed bildet den dokumentierten Stand ab. Reine IP-Daten ohne Wertung — was damit geschieht, entscheidet der Betreiber.&lt;/p&gt;</description></item><item><title>Checkout.com — offizielle IP-Ranges (Webhook/API)</title><link>https://www.parc-network.de/checkout/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://www.parc-network.de/checkout/</guid><description>&lt;p class="lead"&gt;&lt;strong&gt;Checkout.com&lt;/strong&gt; (GB) ist ein Zahlungsanbieter. Dies sind die &lt;strong&gt;offiziellen IP-Ranges&lt;/strong&gt;, unter denen Checkout.coms Webhook-/API-Server senden bzw. erreichbar sind — aus der offiziellen Quelle zu PARC-Feed normalisiert (3 Einträge). Teil unseres &lt;a href="https://www.parc-network.de/parc-security/"&gt;PARC-Security-Feeds&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;&lt;a href="https://www.parc-network.de/feeds/checkout.json" target="_blank" rel="noopener" class="btn btn-secondary"&gt;checkout.json — Feed ansehen&lt;/a&gt; &amp;nbsp; &lt;a href="https://www.checkout.com/" target="_blank" rel="noopener"&gt;www.checkout.com →&lt;/a&gt;&lt;/p&gt;
&lt;h2 id="quelle--aktualisierung"&gt;Quelle &amp;amp; Aktualisierung&lt;/h2&gt;
&lt;p&gt;Quelle: &lt;span class="mono"&gt;checkout.com/docs/files/ip-lists/webhooks-live.txt&lt;/span&gt; — offiziell publiziert. Die Liste wird von einem maschinenlesbaren Endpoint nachgezogen. Checkout.com kann die Ranges jederzeit ändern; der PARC-Feed bildet den offiziellen Stand ab. Reine IP-Daten ohne Wertung.&lt;/p&gt;
&lt;h2 id="quellen"&gt;Quellen&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://www.checkout.com/" target="_blank" rel="noopener"&gt;Checkout.com&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://www.checkout.com/docs/files/ip-lists/webhooks-live.txt" target="_blank" rel="noopener"&gt;Offizielle IP-Quelle&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;p style="margin-top: 40px;"&gt;&lt;a href="https://www.parc-network.de/parc-security/" class="btn btn-secondary"&gt;← Zurück zu PARC Security&lt;/a&gt; &amp;nbsp; &lt;a href="https://www.parc-network.de/#kontakt" class="btn btn-primary"&gt;Kontakt aufnehmen&lt;/a&gt;&lt;/p&gt;</description></item><item><title>CINS Army (CI Army List) — Threat-Intel-Blacklist</title><link>https://www.parc-network.de/cins/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://www.parc-network.de/cins/</guid><description>&lt;h2 id="steckbrief-zur-cins-army-list"&gt;Steckbrief zur CINS Army List&lt;/h2&gt;
&lt;table class="fs-table"&gt;&lt;tr&gt;&lt;th&gt;Kategorie / Angriffsfläche&lt;/th&gt;&lt;td&gt;Allgemeine bösartige IPs — Netzwerk-Ebene (Scans, Rogue-Traffic, Angriffe), keine Bot-/Crawler-Liste&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;th&gt;Was es ist&lt;/th&gt;&lt;td&gt;Freie Threat-Intel-IP-Liste (&lt;code&gt;ci-badguys.txt&lt;/code&gt;, „CI Army List“) aus dem CINS-Score-System&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;th&gt;Betreiber&lt;/th&gt;&lt;td&gt;Sentinel IPS (Austin, Texas) — CINS = Collective Intelligence Network Security&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;th&gt;Wie IPs auf die Liste kommen&lt;/th&gt;&lt;td&gt;Aus der eigenen Sentinel-IPS-Sensorik (IPS-Appliances bei Kunden weltweit). Jede IP erhält einen &lt;strong&gt;CINS-Score&lt;/strong&gt; aus „Rogue-Packet“-Bewertung und Reputation über die Sensor-Flotte — unabhängig von Community-Reports.&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;th&gt;Aufnahme-Kriterium&lt;/th&gt;&lt;td&gt;Schlechter CINS-Score; die freie Liste enthält &lt;strong&gt;bewusst nur IPs, die nicht bereits breit von anderen Reputationslisten erfasst sind&lt;/strong&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;th&gt;Umfang&lt;/th&gt;&lt;td&gt;~15.000 IPs&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;th&gt;Aktualisierungsintervall&lt;/th&gt;&lt;td&gt;täglich&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;th&gt;Verteilt über / aggregiert in&lt;/th&gt;&lt;td&gt;FireHOL · Emerging Threats (Proofpoint)&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;th&gt;Offizielle Seite&lt;/th&gt;&lt;td&gt;&lt;a href="https://cinsscore.com/" target="_blank" rel="noopener"&gt;cinsscore.com&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;th&gt;Feed-Quelle&lt;/th&gt;&lt;td&gt;&lt;a href="https://cinsscore.com/list/ci-badguys.txt" target="_blank" rel="noopener"&gt;ci-badguys.txt — Offizielle Liste (TXT)&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/table&gt;
&lt;h2 id="abgleich-mit-abuseipdb-vom-26062026"&gt;Abgleich mit AbuseIPDB vom 26.06.2026&lt;/h2&gt;
&lt;p&gt;Alle &lt;strong&gt;15.000 IP-Adressen&lt;/strong&gt; der aktuellen CI Army List (&lt;code&gt;ci-badguys&lt;/code&gt;, Stand 26.06.2026) wurden gegen die &lt;strong&gt;AbuseIPDB&lt;/strong&gt; für einen &lt;strong&gt;30-Tage-Zeitraum&lt;/strong&gt; abgefragt und mit zusätzlichen Informationen ergänzt.&lt;/p&gt;</description></item><item><title>CocCocBot (Cốc Cốc) — der verifizierte Crawler-Block und wie wir ihn per FCrDNS belegt haben</title><link>https://www.parc-network.de/coccoc/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://www.parc-network.de/coccoc/</guid><description>&lt;p class="lead"&gt;CocCocBot ist der Crawler von &lt;strong&gt;Cốc Cốc&lt;/strong&gt;, der zweitgrößten Suchmaschine Vietnams (~574 Mio Suchanfragen/Monat) und zugleich eigenem Browser. Cốc Cốc publiziert &lt;strong&gt;keine offizielle IP-Liste&lt;/strong&gt; und betreibt &lt;strong&gt;keine eigene ASN&lt;/strong&gt;. Wir haben den aktiven Crawler-Block deshalb vollständig per &lt;strong&gt;bidirektionalem FCrDNS&lt;/strong&gt; gegen &lt;span class="mono"&gt;*.coccoc.com&lt;/span&gt; verifiziert. Teil unseres &lt;a href="https://www.parc-network.de/parc-security/"&gt;PARC-Security-Feeds&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;&lt;a href="https://www.parc-network.de/feeds/coccoc.json" target="_blank" rel="noopener" class="btn btn-secondary"&gt;coccoc.json — Feed ansehen&lt;/a&gt; &amp;nbsp; &lt;a href="https://coccoc.com/search/console/en/robots.txt" target="_blank" rel="noopener"&gt;Cốc Cốc — robots.txt-Doku →&lt;/a&gt;&lt;/p&gt;
&lt;h2 id="der-block"&gt;Der Block&lt;/h2&gt;
&lt;p&gt;Ein einziger Eintrag — &lt;strong&gt;&lt;code&gt;103.131.71.0/24&lt;/code&gt;&lt;/strong&gt; (256 Adressen):&lt;/p&gt;
&lt;pre tabindex="0"&gt;&lt;code&gt;103.131.71.0/24
&lt;/code&gt;&lt;/pre&gt;&lt;p&gt;In Bot-Trackern (udger.com) erscheinen 286 distinkte aktive Crawler-IPs (&lt;code&gt;coccocbot-web&lt;/code&gt; + &lt;code&gt;coccocbot-image&lt;/code&gt;, zuletzt aktiv am Tag der Recherche) — allesamt innerhalb dieses /24.&lt;/p&gt;</description></item><item><title>Cookie-Script — dokumentierte Scanner-IP</title><link>https://www.parc-network.de/cookiescript/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://www.parc-network.de/cookiescript/</guid><description>&lt;p class="lead"&gt;&lt;strong&gt;Cookie-Script&lt;/strong&gt; ist eine Consent-Management-Plattform (Cookie-Banner, Cookie-Scan). Der Cookie-Scanner crawlt die Website von außen — Cookie-Script nennt dafür in der Doku eine &lt;strong&gt;feste Scan-Quell-IP&lt;/strong&gt;: &lt;span class="mono"&gt;80.240.129.194&lt;/span&gt; (DigitalOcean Amsterdam, AS14061). Teil unseres &lt;a href="https://www.parc-network.de/parc-security/"&gt;PARC-Security-Feeds&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;&lt;a href="https://www.parc-network.de/feeds/cookiescript.json" target="_blank" rel="noopener" class="btn btn-secondary"&gt;cookiescript.json — Feed ansehen&lt;/a&gt; &amp;nbsp; &lt;a href="https://cookie-script.com/" target="_blank" rel="noopener"&gt;cookie-script.com →&lt;/a&gt;&lt;/p&gt;
&lt;h2 id="quelle--aktualisierung"&gt;Quelle &amp;amp; Aktualisierung&lt;/h2&gt;
&lt;p&gt;Quelle: Cookie-Script-Hilfe. Der Cookie-Scanner sendet alle Anfragen von &lt;span class="mono"&gt;80.240.129.194&lt;/span&gt; (DigitalOcean, Amsterdam — per Team-Cymru-ASN-Lookup geprüft: AS14061). Cookie-Script empfiehlt in der eigenen Doku, mit „Always scan from same IP address&amp;quot; auf genau diese Adresse zu fixieren. Der PARC-Feed bildet den dokumentierten Stand ab. Reine IP-Daten ohne Wertung — was damit geschieht, entscheidet der Betreiber.&lt;/p&gt;</description></item><item><title>Cortex Xpanse — ASN lügt, RDAP-Eigentum identifiziert</title><link>https://www.parc-network.de/xpanse/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://www.parc-network.de/xpanse/</guid><description>&lt;p class="lead"&gt;Cortex Xpanse (Expander) ist der internet-weite &lt;strong&gt;Attack-Surface-Scanner&lt;/strong&gt; von Palo Alto Networks (US). Kein SEO-Tool. Der Knackpunkt: die Scan-IPs werden &lt;strong&gt;über Google Cloud announced&lt;/strong&gt; (die ASN zeigt „Google"), aber die Netzblöcke sind im RDAP auf &lt;strong&gt;Palo Alto Networks / Expanse&lt;/strong&gt; registriert. Weder ASN noch PTR taugen — nur das &lt;strong&gt;RDAP-Eigentum&lt;/strong&gt; identifiziert Xpanse. Teil unseres &lt;a href="https://www.parc-network.de/parc-security/"&gt;PARC-Security-Feeds&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;&lt;a href="https://www.parc-network.de/feeds/xpanse.json" target="_blank" rel="noopener" class="btn btn-secondary"&gt;xpanse.json — Feed ansehen&lt;/a&gt; &amp;nbsp; &lt;a href="https://www.paloaltonetworks.com/cortex/cortex-xpanse" target="_blank" rel="noopener"&gt;www.paloaltonetworks.com →&lt;/a&gt;&lt;/p&gt;
&lt;h2 id="verifikation--jede-ip-einzeln"&gt;Verifikation — jede IP einzeln&lt;/h2&gt;
&lt;p&gt;Im CINS-Abgleich tauchten 858 Xpanse-IPs auf (AbuseIPDB-Score 0 trotz hunderter Reports). Verifikation:&lt;/p&gt;</description></item><item><title>Criminal IP — per-IP self-ID via criminalip.com</title><link>https://www.parc-network.de/criminalip/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://www.parc-network.de/criminalip/</guid><description>&lt;p class="lead"&gt;&lt;strong&gt;Criminal IP&lt;/strong&gt; (AI Spera, KR) betreibt einen internet-weiten &lt;strong&gt;Security-Scanner / CTI-Dienst&lt;/strong&gt;. Kein SEO-Tool. Die Scan-IPs sind &lt;strong&gt;self-identifizierend&lt;/strong&gt;: PTR auf &lt;span class="mono"&gt;security.criminalip.com&lt;/span&gt;. Jede IP einzeln reverse-geprüft. Teil unseres &lt;a href="https://www.parc-network.de/parc-security/"&gt;PARC-Security-Feeds&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;&lt;a href="https://www.parc-network.de/feeds/criminalip.json" target="_blank" rel="noopener" class="btn btn-secondary"&gt;criminalip.json — Feed ansehen&lt;/a&gt; &amp;nbsp; &lt;a href="https://www.criminalip.io/" target="_blank" rel="noopener"&gt;www.criminalip.io →&lt;/a&gt;&lt;/p&gt;
&lt;h2 id="verifikation--jede-ip-einzeln"&gt;Verifikation — jede IP einzeln&lt;/h2&gt;
&lt;p&gt;Die Listen-IPs (185.216.140.x, 80.82.x, 89.248.x, 93.174.93.x, 94.102.x — IP Volume inc) tragen teils generische Hoster-PTR. Wir nehmen &lt;strong&gt;nur die self-identifizierenden&lt;/strong&gt;:&lt;/p&gt;
&lt;pre tabindex="0"&gt;&lt;code&gt;584 IPs → 291 mit PTR security.criminalip.com (nur die kommen rein)
&lt;/code&gt;&lt;/pre&gt;&lt;p&gt;Keine Stichprobe, keine Hochrechnung.&lt;/p&gt;</description></item><item><title>CyberGreen — per-IP self-ID via cybergreen.net</title><link>https://www.parc-network.de/cybergreen/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://www.parc-network.de/cybergreen/</guid><description>&lt;p class="lead"&gt;&lt;strong&gt;Cyber-Risk-Mess-Scanner&lt;/strong&gt; der gemeinnützigen CyberGreen Institute. Kein SEO-Tool. Die Scan-IPs sind &lt;strong&gt;self-identifizierend&lt;/strong&gt;: Reverse-DNS &lt;span class="mono"&gt;scanner*.scanning.cybergreen.net&lt;/span&gt;. Entdeckt im &lt;a href="https://www.parc-network.de/cins/"&gt;CINS-Abgleich&lt;/a&gt; und per Nachbar-Range-Scan vervollständigt — jede IP einzeln reverse-bestätigt (1). Teil unseres &lt;a href="https://www.parc-network.de/parc-security/"&gt;PARC-Security-Feeds&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;&lt;a href="https://www.parc-network.de/feeds/cybergreen.json" target="_blank" rel="noopener" class="btn btn-secondary"&gt;cybergreen.json — Feed ansehen&lt;/a&gt; &amp;nbsp; &lt;a href="https://www.cybergreen.net/" target="_blank" rel="noopener"&gt;www.cybergreen.net →&lt;/a&gt;&lt;/p&gt;
&lt;h2 id="verifikation--jede-ip-einzeln"&gt;Verifikation — jede IP einzeln&lt;/h2&gt;
&lt;p&gt;Den Reverse-PTR &lt;span class="mono"&gt;scanner*.scanning.cybergreen.net&lt;/span&gt; kann nur der IP-Betreiber setzen — ein nicht-fälschbarer Eigentums-Hinweis. Seed aus den &lt;strong&gt;aktiv scannenden CINS-IPs&lt;/strong&gt;, per Reverse-Scan der umliegenden /24 vervollständigt; jede IP einzeln bestätigt:&lt;/p&gt;
&lt;pre tabindex="0"&gt;&lt;code&gt;1 IPs → alle PTR cybergreen.net
&lt;/code&gt;&lt;/pre&gt;&lt;p&gt;Reverse-only (Forward nicht durchgängig prüfbar, wie bei Shodan/Infrawatch). AbuseIPDB führt diese IPs teils mit Score 100 — es sind dennoch benigne Research-Scanner.&lt;/p&gt;</description></item><item><title>CyberResilience — per-IP self-ID via cyberresilience.io</title><link>https://www.parc-network.de/cyberresilience/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://www.parc-network.de/cyberresilience/</guid><description>&lt;p class="lead"&gt;internet-weiter &lt;strong&gt;Port-Scanner&lt;/strong&gt; (CyberResilience). Kein SEO-Tool. Die Scan-IPs sind &lt;strong&gt;self-identifizierend&lt;/strong&gt;: Reverse-DNS &lt;span class="mono"&gt;portscanner-*.prod.cyberresilience.io&lt;/span&gt;. Entdeckt im &lt;a href="https://www.parc-network.de/cins/"&gt;CINS-Abgleich&lt;/a&gt; und per Nachbar-Range-Scan vervollständigt — jede IP einzeln reverse-bestätigt (8). Teil unseres &lt;a href="https://www.parc-network.de/parc-security/"&gt;PARC-Security-Feeds&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;&lt;a href="https://www.parc-network.de/feeds/cyberresilience.json" target="_blank" rel="noopener" class="btn btn-secondary"&gt;cyberresilience.json — Feed ansehen&lt;/a&gt; &amp;nbsp; &lt;a href="https://cyberresilience.io/" target="_blank" rel="noopener"&gt;cyberresilience.io →&lt;/a&gt;&lt;/p&gt;
&lt;h2 id="verifikation--jede-ip-einzeln"&gt;Verifikation — jede IP einzeln&lt;/h2&gt;
&lt;p&gt;Den Reverse-PTR &lt;span class="mono"&gt;portscanner-*.prod.cyberresilience.io&lt;/span&gt; kann nur der IP-Betreiber setzen — ein nicht-fälschbarer Eigentums-Hinweis. Seed aus den &lt;strong&gt;aktiv scannenden CINS-IPs&lt;/strong&gt;, per Reverse-Scan der umliegenden /24 vervollständigt; jede IP einzeln bestätigt:&lt;/p&gt;
&lt;pre tabindex="0"&gt;&lt;code&gt;8 IPs → alle PTR cyberresilience.io
&lt;/code&gt;&lt;/pre&gt;&lt;p&gt;Reverse-only (Forward nicht durchgängig prüfbar, wie bei Shodan/Infrawatch). AbuseIPDB führt diese IPs teils mit Score 100 — es sind dennoch benigne Research-Scanner.&lt;/p&gt;</description></item><item><title>Datenschutz</title><link>https://www.parc-network.de/datenschutz/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://www.parc-network.de/datenschutz/</guid><description>&lt;p&gt;Als Verantwortlicher im Sinne der DSGVO informieren wir Sie nachfolgend über die Verarbeitung personenbezogener Daten beim Besuch dieser Website.&lt;/p&gt;
&lt;nav class="toc" aria-label="Inhaltsverzeichnis"&gt;
&lt;strong&gt;Inhalt&lt;/strong&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="#verantwortlicher"&gt;1. Verantwortlicher&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#zwecke"&gt;2. Zwecke der Verarbeitung und Rechtsgrundlagen&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#verarbeitung"&gt;3. Verarbeitung im Einzelnen&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#empfaenger"&gt;4. Empfänger und Drittland-Transfer&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#speicherdauer"&gt;5. Speicherdauer&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#rechte"&gt;6. Ihre Rechte&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#widerspruch"&gt;7. Widerspruchsrecht (Art. 21 DSGVO)&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#sicherheit"&gt;8. Datensicherheit&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;/nav&gt;
&lt;h2 id="verantwortlicher" style="margin-top: 32px;"&gt;1. Verantwortlicher&lt;/h2&gt;
&lt;p&gt;Verantwortlich für die Verarbeitung personenbezogener Daten ist die &lt;strong&gt;PARC Network GmbH &amp;amp; Co. KG&lt;/strong&gt;. Den Namen und die Kontaktdaten des Verantwortlichen entnehmen Sie unserem &lt;a href="https://www.parc-network.de/impressum/"&gt;Impressum&lt;/a&gt;.&lt;/p&gt;</description></item><item><title>DotBot (Moz) — die verifizierte Crawler-Range, Vier-Quellen-Methodik und warum das ganze /24</title><link>https://www.parc-network.de/dotbot/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://www.parc-network.de/dotbot/</guid><description>&lt;p class="lead"&gt;DotBot ist der Crawler von &lt;strong&gt;Moz&lt;/strong&gt; für den Link-Index hinter Moz Link Explorer — er sammelt Backlink-Daten (Domain/Page Authority), die Moz an zahlende Kunden verkauft. Moz publiziert &lt;strong&gt;keine offizielle IP-Liste&lt;/strong&gt;. Wir haben die aktive Range deshalb über &lt;strong&gt;vier unabhängige Quellen&lt;/strong&gt; verifiziert — inklusive unserer eigenen WAF-Telemetrie — und auf ein einziges &lt;span class="mono"&gt;/24&lt;/span&gt; festgenagelt. Teil unseres &lt;a href="https://www.parc-network.de/parc-security/"&gt;PARC-Security-Feeds&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;&lt;a href="https://www.parc-network.de/feeds/dotbot.json" target="_blank" rel="noopener" class="btn btn-secondary"&gt;dotbot.json — Feed ansehen&lt;/a&gt; &amp;nbsp; &lt;a href="https://moz.com/help/moz-procedures/crawlers/dotbot" target="_blank" rel="noopener"&gt;Moz-Doku zu DotBot →&lt;/a&gt;&lt;/p&gt;
&lt;h2 id="die-range"&gt;Die Range&lt;/h2&gt;
&lt;p&gt;Ein einziger Eintrag — &lt;strong&gt;&lt;code&gt;216.244.66.0/24&lt;/code&gt;&lt;/strong&gt; (256 IPs), Wowrack-Pool Seattle, &lt;strong&gt;AS23033&lt;/strong&gt;:&lt;/p&gt;</description></item><item><title>F6 Security — per-IP self-ID via f6.security</title><link>https://www.parc-network.de/f6/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://www.parc-network.de/f6/</guid><description>&lt;p class="lead"&gt;internet-weiter &lt;strong&gt;Security-Scanner&lt;/strong&gt; (F6). Kein SEO-Tool. Die Scan-IPs sind &lt;strong&gt;self-identifizierend&lt;/strong&gt;: Reverse-DNS &lt;span class="mono"&gt;scan.f6.security&lt;/span&gt;. Entdeckt im &lt;a href="https://www.parc-network.de/cins/"&gt;CINS-Abgleich&lt;/a&gt; und per Nachbar-Range-Scan vervollständigt — jede IP einzeln reverse-bestätigt (7). Teil unseres &lt;a href="https://www.parc-network.de/parc-security/"&gt;PARC-Security-Feeds&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;&lt;a href="https://www.parc-network.de/feeds/f6.json" target="_blank" rel="noopener" class="btn btn-secondary"&gt;f6.json — Feed ansehen&lt;/a&gt; &amp;nbsp; &lt;a href="https://f6.security/" target="_blank" rel="noopener"&gt;f6.security →&lt;/a&gt;&lt;/p&gt;
&lt;h2 id="verifikation--jede-ip-einzeln"&gt;Verifikation — jede IP einzeln&lt;/h2&gt;
&lt;p&gt;Den Reverse-PTR &lt;span class="mono"&gt;scan.f6.security&lt;/span&gt; kann nur der IP-Betreiber setzen — ein nicht-fälschbarer Eigentums-Hinweis. Seed aus den &lt;strong&gt;aktiv scannenden CINS-IPs&lt;/strong&gt;, per Reverse-Scan der umliegenden /24 vervollständigt; jede IP einzeln bestätigt:&lt;/p&gt;
&lt;pre tabindex="0"&gt;&lt;code&gt;7 IPs → alle PTR f6.security
&lt;/code&gt;&lt;/pre&gt;&lt;p&gt;Reverse-only (Forward nicht durchgängig prüfbar, wie bei Shodan/Infrawatch). AbuseIPDB führt diese IPs teils mit Score 100 — es sind dennoch benigne Research-Scanner.&lt;/p&gt;</description></item><item><title>Group-IB — per-IP self-ID via group-ib.com</title><link>https://www.parc-network.de/group-ib/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://www.parc-network.de/group-ib/</guid><description>&lt;p class="lead"&gt;&lt;strong&gt;Group-IB&lt;/strong&gt; betreibt einen internet-weiten &lt;strong&gt;Threat-Intelligence-/Scan-Dienst&lt;/strong&gt;. Kein SEO-Tool. Die Scan-IPs sind &lt;strong&gt;self-identifizierend&lt;/strong&gt;: PTR auf &lt;span class="mono"&gt;group-ib.com&lt;/span&gt;. Jede IP einzeln reverse-geprüft. Teil unseres &lt;a href="https://www.parc-network.de/parc-security/"&gt;PARC-Security-Feeds&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;&lt;a href="https://www.parc-network.de/feeds/group-ib.json" target="_blank" rel="noopener" class="btn btn-secondary"&gt;group-ib.json — Feed ansehen&lt;/a&gt; &amp;nbsp; &lt;a href="https://group-ib.com/" target="_blank" rel="noopener"&gt;group-ib.com →&lt;/a&gt;&lt;/p&gt;
&lt;h2 id="verifikation--jede-ip-einzeln"&gt;Verifikation — jede IP einzeln&lt;/h2&gt;
&lt;p&gt;Die 21 Listen-IPs (80.82.x, 89.248.x, 93.174.93.x, 94.102.x — IP Volume inc) tragen PTR &lt;span class="mono"&gt;group-ib.com&lt;/span&gt;:&lt;/p&gt;
&lt;pre tabindex="0"&gt;&lt;code&gt;21 IPs → 19 mit PTR group-ib.com (nur die kommen rein)
&lt;/code&gt;&lt;/pre&gt;&lt;p&gt;Keine Hochrechnung.&lt;/p&gt;
&lt;h2 id="quellen"&gt;Quellen&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://group-ib.com/" target="_blank" rel="noopener"&gt;Group-IB&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/Connie-Wild/scanner-ip-list" target="_blank" rel="noopener"&gt;Connie-Wild — scanner-ip-list (GitHub)&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;p style="margin-top: 40px;"&gt;&lt;a href="https://www.parc-network.de/parc-security/" class="btn btn-secondary"&gt;← Zurück zu PARC Security&lt;/a&gt; &amp;nbsp; &lt;a href="https://www.parc-network.de/#kontakt" class="btn btn-primary"&gt;Kontakt aufnehmen&lt;/a&gt;&lt;/p&gt;</description></item><item><title>Impressum</title><link>https://www.parc-network.de/impressum/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://www.parc-network.de/impressum/</guid><description>&lt;p&gt;
&lt;strong&gt;PARC Network GmbH &amp;amp; Co. KG&lt;/strong&gt;&lt;br&gt;
Am Weidengraben 27&lt;br&gt;
D-97297 Waldbüttelbrunn
&lt;/p&gt;
&lt;p&gt;
Telefon: &lt;a href="tel:+4993197091331"&gt;0931 / 970 913 31&lt;/a&gt;&lt;br&gt;
E-Mail: &lt;a href="mailto:hallo@parc-network.de"&gt;hallo@parc-network.de&lt;/a&gt;
&lt;/p&gt;
&lt;p&gt;
Registergericht: AG Würzburg&lt;br&gt;
Registernummer: HRA 7122
&lt;/p&gt;
&lt;p&gt;
Umsatzsteuer-Identifikationsnummer gemäß § 27 a Umsatzsteuergesetz: DE292075424
&lt;/p&gt;
&lt;p&gt;
&lt;strong&gt;Hinweis nach § 36 VSBG:&lt;/strong&gt; Wir sind weder bereit noch verpflichtet, an Streitbeilegungsverfahren vor einer Verbraucherschlichtungsstelle teilzunehmen.
&lt;/p&gt;
&lt;h2 style="margin-top: 32px;"&gt;Persönlich haftende Gesellschafterin&lt;/h2&gt;
&lt;p&gt;
&lt;strong&gt;PARC Network Verwaltungs-GmbH&lt;/strong&gt;&lt;br&gt;
Am Weidengraben 27&lt;br&gt;
D-97297 Waldbüttelbrunn
&lt;/p&gt;
&lt;p&gt;
Registergericht: AG Würzburg&lt;br&gt;
Registernummer: HRB 12076
&lt;/p&gt;
&lt;p&gt;
Geschäftsführer: Paul Beck
&lt;/p&gt;</description></item><item><title>Infrawatch — einen Scanner ohne Forward-DNS über autoritatives Reverse-DNS verifizieren</title><link>https://www.parc-network.de/infrawatch/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://www.parc-network.de/infrawatch/</guid><description>&lt;p class="lead"&gt;Infrawatch (&lt;a href="https://infrawatch.com/" target="_blank" rel="noopener"&gt;infrawatch.com&lt;/a&gt;) ist ein internet-weiter &lt;strong&gt;Threat-Intel-Scanner&lt;/strong&gt; — „Real Time Internet Intelligence“, trackt Proxies, VPNs und feindliche Netze. Kein SEO-Tool. Infrawatch mietet &lt;strong&gt;verstreute Einzel-IPs&lt;/strong&gt; quer über das Netz von &lt;strong&gt;Hydra Communications&lt;/strong&gt; (AS25369, ein ISP) — keine eigene Range, keine offizielle Liste. Ein klassischer FCrDNS-Beweis ist nicht möglich (keine Forward-Records). Identifiziert wird stattdessen über &lt;strong&gt;autoritatives Reverse-DNS&lt;/strong&gt; &lt;span class="mono"&gt;*.infrawat.ch&lt;/span&gt;. &lt;strong&gt;1.177 IPs&lt;/strong&gt;: aus der &lt;a href="https://www.parc-network.de/cins/"&gt;CINS-Blacklist&lt;/a&gt; abgeleitet (581) und über einen Reverse-Scan der Nachbar-Ranges vervollständigt. Teil unseres &lt;a href="https://www.parc-network.de/parc-security/"&gt;PARC-Security-Feeds&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;&lt;a href="https://www.parc-network.de/feeds/infrawatch.json" target="_blank" rel="noopener" class="btn btn-secondary"&gt;infrawatch.json — Feed ansehen&lt;/a&gt; &amp;nbsp; &lt;a href="https://infrawatch.com/" target="_blank" rel="noopener"&gt;infrawatch.com →&lt;/a&gt;&lt;/p&gt;</description></item><item><title>Internet Census Group — per-IP self-ID via internet-census.org</title><link>https://www.parc-network.de/internet-census/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://www.parc-network.de/internet-census/</guid><description>&lt;p class="lead"&gt;Die &lt;strong&gt;Internet Census Group&lt;/strong&gt; betreibt einen internet-weiten &lt;strong&gt;Census-/Scan-Dienst&lt;/strong&gt;. Kein SEO-Tool. Die Scan-IPs sind &lt;strong&gt;self-identifizierend&lt;/strong&gt;: PTR auf &lt;span class="mono"&gt;internet-census.org&lt;/span&gt;. Jede IP einzeln reverse-geprüft. Teil unseres &lt;a href="https://www.parc-network.de/parc-security/"&gt;PARC-Security-Feeds&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;&lt;a href="https://www.parc-network.de/feeds/internet-census.json" target="_blank" rel="noopener" class="btn btn-secondary"&gt;internet-census.json — Feed ansehen&lt;/a&gt; &amp;nbsp; &lt;a href="https://www.internet-census.org/" target="_blank" rel="noopener"&gt;www.internet-census.org →&lt;/a&gt;&lt;/p&gt;
&lt;h2 id="verifikation--jede-ip-einzeln"&gt;Verifikation — jede IP einzeln&lt;/h2&gt;
&lt;p&gt;Die 630 Listen-IPs liegen auf diversen Hostern und tragen teils fremde PTR (singlehop.net, linodeusercontent.com u.a.). Nur die echten Self-ID kommen rein:&lt;/p&gt;
&lt;pre tabindex="0"&gt;&lt;code&gt;630 IPs → 267 mit PTR internet-census.org (nur die kommen rein)
&lt;/code&gt;&lt;/pre&gt;&lt;p&gt;Der Rest bleibt draußen.&lt;/p&gt;
&lt;h2 id="quellen"&gt;Quellen&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://www.internet-census.org/" target="_blank" rel="noopener"&gt;Internet Census Group&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/Connie-Wild/scanner-ip-list" target="_blank" rel="noopener"&gt;Connie-Wild — scanner-ip-list (GitHub)&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;p style="margin-top: 40px;"&gt;&lt;a href="https://www.parc-network.de/parc-security/" class="btn btn-secondary"&gt;← Zurück zu PARC Security&lt;/a&gt; &amp;nbsp; &lt;a href="https://www.parc-network.de/#kontakt" class="btn btn-primary"&gt;Kontakt aufnehmen&lt;/a&gt;&lt;/p&gt;</description></item><item><title>InternetData.io — per-IP self-ID via internetdata.io</title><link>https://www.parc-network.de/internetdata/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://www.parc-network.de/internetdata/</guid><description>&lt;p class="lead"&gt;internet-weiter &lt;strong&gt;Protokoll-Scanner&lt;/strong&gt; (InternetData.io). Kein SEO-Tool. Die Scan-IPs sind &lt;strong&gt;self-identifizierend&lt;/strong&gt;: Reverse-DNS &lt;span class="mono"&gt;*-scan-*.io.internetdata.io&lt;/span&gt;. Entdeckt im &lt;a href="https://www.parc-network.de/cins/"&gt;CINS-Abgleich&lt;/a&gt; und per Nachbar-Range-Scan vervollständigt — jede IP einzeln reverse-bestätigt (2). Teil unseres &lt;a href="https://www.parc-network.de/parc-security/"&gt;PARC-Security-Feeds&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;&lt;a href="https://www.parc-network.de/feeds/internetdata.json" target="_blank" rel="noopener" class="btn btn-secondary"&gt;internetdata.json — Feed ansehen&lt;/a&gt; &amp;nbsp; &lt;a href="https://internetdata.io/" target="_blank" rel="noopener"&gt;internetdata.io →&lt;/a&gt;&lt;/p&gt;
&lt;h2 id="verifikation--jede-ip-einzeln"&gt;Verifikation — jede IP einzeln&lt;/h2&gt;
&lt;p&gt;Den Reverse-PTR &lt;span class="mono"&gt;&lt;em&gt;-scan-&lt;/em&gt;.io.internetdata.io&lt;/span&gt; kann nur der IP-Betreiber setzen — ein nicht-fälschbarer Eigentums-Hinweis. Seed aus den &lt;strong&gt;aktiv scannenden CINS-IPs&lt;/strong&gt;, per Reverse-Scan der umliegenden /24 vervollständigt; jede IP einzeln bestätigt:&lt;/p&gt;
&lt;pre tabindex="0"&gt;&lt;code&gt;2 IPs → alle PTR internetdata.io
&lt;/code&gt;&lt;/pre&gt;&lt;p&gt;Reverse-only (Forward nicht durchgängig prüfbar, wie bei Shodan/Infrawatch). AbuseIPDB führt diese IPs teils mit Score 100 — es sind dennoch benigne Research-Scanner.&lt;/p&gt;</description></item><item><title>InterneTTL Project — per-IP self-ID via internettl.org</title><link>https://www.parc-network.de/internettl/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://www.parc-network.de/internettl/</guid><description>&lt;p class="lead"&gt;Das &lt;strong&gt;InterneTTL Project&lt;/strong&gt; betreibt einen internet-weiten &lt;strong&gt;Mess-/Scan-Dienst&lt;/strong&gt;. Kein SEO-Tool. Die Scan-IPs sind &lt;strong&gt;self-identifizierend&lt;/strong&gt;: PTR auf &lt;span class="mono"&gt;internettl.org&lt;/span&gt;. Jede IP einzeln reverse-geprüft. Teil unseres &lt;a href="https://www.parc-network.de/parc-security/"&gt;PARC-Security-Feeds&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;&lt;a href="https://www.parc-network.de/feeds/internettl.json" target="_blank" rel="noopener" class="btn btn-secondary"&gt;internettl.json — Feed ansehen&lt;/a&gt; &amp;nbsp; &lt;a href="http://www.internettl.org/" target="_blank" rel="noopener"&gt;www.internettl.org →&lt;/a&gt;&lt;/p&gt;
&lt;h2 id="verifikation--jede-ip-einzeln"&gt;Verifikation — jede IP einzeln&lt;/h2&gt;
&lt;p&gt;Der /24-Block 104.152.52.0/24 liegt bei Rethem Hosting (AS14987). Den Reverse-PTR &lt;span class="mono"&gt;internettl.org&lt;/span&gt; setzt der Betreiber selbst:&lt;/p&gt;
&lt;pre tabindex="0"&gt;&lt;code&gt;254 IPs (/24) → 221 mit PTR internettl.org (nur die kommen rein)
&lt;/code&gt;&lt;/pre&gt;&lt;p&gt;Keine Hochrechnung.&lt;/p&gt;
&lt;h2 id="quellen"&gt;Quellen&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="http://www.internettl.org/" target="_blank" rel="noopener"&gt;InterneTTL Project&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/Connie-Wild/scanner-ip-list" target="_blank" rel="noopener"&gt;Connie-Wild — scanner-ip-list (GitHub)&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;p style="margin-top: 40px;"&gt;&lt;a href="https://www.parc-network.de/parc-security/" class="btn btn-secondary"&gt;← Zurück zu PARC Security&lt;/a&gt; &amp;nbsp; &lt;a href="https://www.parc-network.de/#kontakt" class="btn btn-primary"&gt;Kontakt aufnehmen&lt;/a&gt;&lt;/p&gt;</description></item><item><title>Intrinsec — per-IP self-ID via intrinsec.com</title><link>https://www.parc-network.de/intrinsec/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://www.parc-network.de/intrinsec/</guid><description>&lt;p class="lead"&gt;&lt;strong&gt;CTI-/Security-Scanner&lt;/strong&gt; der Intrinsec SA (FR). Kein SEO-Tool. Die Scan-IPs sind &lt;strong&gt;self-identifizierend&lt;/strong&gt;: Reverse-DNS &lt;span class="mono"&gt;scan*.intrinsec.com&lt;/span&gt;. Entdeckt im &lt;a href="https://www.parc-network.de/cins/"&gt;CINS-Abgleich&lt;/a&gt; und per Nachbar-Range-Scan vervollständigt — jede IP einzeln reverse-bestätigt (36). Teil unseres &lt;a href="https://www.parc-network.de/parc-security/"&gt;PARC-Security-Feeds&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;&lt;a href="https://www.parc-network.de/feeds/intrinsec.json" target="_blank" rel="noopener" class="btn btn-secondary"&gt;intrinsec.json — Feed ansehen&lt;/a&gt; &amp;nbsp; &lt;a href="https://www.intrinsec.com/" target="_blank" rel="noopener"&gt;www.intrinsec.com →&lt;/a&gt;&lt;/p&gt;
&lt;h2 id="verifikation--jede-ip-einzeln"&gt;Verifikation — jede IP einzeln&lt;/h2&gt;
&lt;p&gt;Den Reverse-PTR &lt;span class="mono"&gt;scan*.intrinsec.com&lt;/span&gt; kann nur der IP-Betreiber setzen — ein nicht-fälschbarer Eigentums-Hinweis. Seed aus den &lt;strong&gt;aktiv scannenden CINS-IPs&lt;/strong&gt;, per Reverse-Scan der umliegenden /24 vervollständigt; jede IP einzeln bestätigt:&lt;/p&gt;
&lt;pre tabindex="0"&gt;&lt;code&gt;36 IPs → alle PTR intrinsec.com
&lt;/code&gt;&lt;/pre&gt;&lt;p&gt;Reverse-only (Forward nicht durchgängig prüfbar, wie bei Shodan/Infrawatch). AbuseIPDB führt diese IPs teils mit Score 100 — es sind dennoch benigne Research-Scanner.&lt;/p&gt;</description></item><item><title>IPIP.net — nur die eigene ASN (AS136180), Linode-Mietblocks ausgeschlossen</title><link>https://www.parc-network.de/ipip/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://www.parc-network.de/ipip/</guid><description>&lt;p class="lead"&gt;&lt;strong&gt;IPIP.net&lt;/strong&gt; (Beijing Tiantexin, CN) betreibt internet-weite &lt;strong&gt;Mess-/Scan-Knoten&lt;/strong&gt; für IP-Geolocation. Kein SEO-Tool. Beweisbar über &lt;strong&gt;ASN-Eigentum&lt;/strong&gt;: AS136180. Wir nehmen &lt;strong&gt;nur die eigene ASN&lt;/strong&gt; — die gemieteten Linode-IPs der Liste lassen sich nicht IPIP zuordnen. Teil unseres &lt;a href="https://www.parc-network.de/parc-security/"&gt;PARC-Security-Feeds&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;&lt;a href="https://www.parc-network.de/feeds/ipip.json" target="_blank" rel="noopener" class="btn btn-secondary"&gt;ipip.json — Feed ansehen&lt;/a&gt; &amp;nbsp; &lt;a href="https://en.ipip.net/about.html" target="_blank" rel="noopener"&gt;en.ipip.net →&lt;/a&gt;&lt;/p&gt;
&lt;h2 id="verifikation--jede-ip-einzeln"&gt;Verifikation — jede IP einzeln&lt;/h2&gt;
&lt;p&gt;Die Connie-Wild-Liste mischt zwei Dinge: IPIPs &lt;strong&gt;eigene CN-Blöcke&lt;/strong&gt; (AS136180) und gemietete &lt;strong&gt;Linode-IPs&lt;/strong&gt; (AS63949). Wir trennen per-IP:&lt;/p&gt;
&lt;pre tabindex="0"&gt;&lt;code&gt;5 /24-Blöcke → 1.280 IPs, alle AS136180 (ASN-Eigentum, per-IP geprüft)
+ 35 Linode-IPs → PTR scan-N.security.ipip.net (reverse-only Self-ID)
übrige Linode → kein ipip-PTR / generisch → raus
&lt;/code&gt;&lt;/pre&gt;&lt;p&gt;Ehrlich: die 1.280 CN-IPs stehen auf &lt;strong&gt;ASN-Eigentum&lt;/strong&gt; — das Reverse zeigt auf den Netzbetreiber &lt;span class="mono"&gt;misaka.io&lt;/span&gt;, kein DNS-Self-ID (Beweis-Stufe wie Shadowserver/umich). Die 35 Linode-IPs self-identifizieren per Reverse-PTR &lt;span class="mono"&gt;scan-N.security.ipip.net&lt;/span&gt; — forward nicht prüfbar (Zone ohne A-Records), also reverse-only wie bei Shodan. Gesamt 1.315.&lt;/p&gt;</description></item><item><title>Kaufland Global Marketplace — offizielle Egress-IPs</title><link>https://www.parc-network.de/kaufland-marketplace/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://www.parc-network.de/kaufland-marketplace/</guid><description>&lt;p class="lead"&gt;&lt;strong&gt;Kaufland Global Marketplace&lt;/strong&gt; ist der Marktplatz von Kaufland (ehemals real.de). Die &lt;strong&gt;Marketplace Seller API&lt;/strong&gt; schickt Push-Notifications an angebundene Shops, lädt Dateien herunter und macht weitere ausgehende Calls — dies sind die &lt;strong&gt;20 offiziellen Egress-IPs&lt;/strong&gt; aus der Kaufland-API-Doku, alle in Google Cloud (AS396982). Teil unseres &lt;a href="https://www.parc-network.de/parc-security/"&gt;PARC-Security-Feeds&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;&lt;a href="https://www.parc-network.de/feeds/kaufland-marketplace.json" target="_blank" rel="noopener" class="btn btn-secondary"&gt;kaufland-marketplace.json — Feed ansehen&lt;/a&gt; &amp;nbsp; &lt;a href="https://sellerapi.kaufland.com/?page=rest-api" target="_blank" rel="noopener"&gt;sellerapi.kaufland.com →&lt;/a&gt;&lt;/p&gt;
&lt;h2 id="quelle--aktualisierung"&gt;Quelle &amp;amp; Aktualisierung&lt;/h2&gt;
&lt;p&gt;Quelle: Kaufland Marketplace Seller API Documentation (Abschnitt zu Egress-/Notification-IPs). Die 20 Adressen sind diejenigen, von denen die Seller-API ausgehend kommuniziert — Push-Notifications, Datei-Downloads und sonstige Outbound-Calls. Alle liegen in Google Cloud (AS396982, einzeln per Team-Cymru-ASN-Lookup geprüft). Der PARC-Feed bildet den dokumentierten Stand 1:1 ab. Reine IP-Daten ohne Wertung — was damit geschieht, entscheidet der Betreiber.&lt;/p&gt;</description></item><item><title>Klarna — offizielle IP-Ranges (Webhook/API)</title><link>https://www.parc-network.de/klarna/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://www.parc-network.de/klarna/</guid><description>&lt;p class="lead"&gt;&lt;strong&gt;Klarna&lt;/strong&gt; (SE) ist ein Zahlungsanbieter. Dies sind die &lt;strong&gt;offiziellen IP-Ranges&lt;/strong&gt;, unter denen Klarnas Webhook-/API-Server senden bzw. erreichbar sind — aus der offiziellen Quelle zu PARC-Feed normalisiert (10 Einträge). Teil unseres &lt;a href="https://www.parc-network.de/parc-security/"&gt;PARC-Security-Feeds&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;&lt;a href="https://www.parc-network.de/feeds/klarna.json" target="_blank" rel="noopener" class="btn btn-secondary"&gt;klarna.json — Feed ansehen&lt;/a&gt; &amp;nbsp; &lt;a href="https://www.klarna.com/" target="_blank" rel="noopener"&gt;www.klarna.com →&lt;/a&gt;&lt;/p&gt;
&lt;h2 id="quelle--aktualisierung"&gt;Quelle &amp;amp; Aktualisierung&lt;/h2&gt;
&lt;p&gt;Quelle: &lt;span class="mono"&gt;Klarna-Doku (Callbacks)&lt;/span&gt; — offiziell publiziert. Aus der Anbieter-Doku übernommen. Klarna kann die Ranges jederzeit ändern; der PARC-Feed bildet den offiziellen Stand ab. Reine IP-Daten ohne Wertung.&lt;/p&gt;
&lt;h2 id="quellen"&gt;Quellen&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://www.klarna.com/" target="_blank" rel="noopener"&gt;Klarna&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://docs.klarna.com/acquirer/klarna/get-started/integration-resilience/callbacks/" target="_blank" rel="noopener"&gt;Offizielle IP-Quelle&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;p style="margin-top: 40px;"&gt;&lt;a href="https://www.parc-network.de/parc-security/" class="btn btn-secondary"&gt;← Zurück zu PARC Security&lt;/a&gt; &amp;nbsp; &lt;a href="https://www.parc-network.de/#kontakt" class="btn btn-primary"&gt;Kontakt aufnehmen&lt;/a&gt;&lt;/p&gt;</description></item><item><title>LinkedInBot — IP-Ranges, ASN-Verifikation und der Microsoft-/AI-Kontext</title><link>https://www.parc-network.de/linkedin/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://www.parc-network.de/linkedin/</guid><description>&lt;p class="lead"&gt;LinkedIn betreibt den &lt;strong&gt;LinkedInBot&lt;/strong&gt; für Link-Previews beim Posten auf LinkedIn. Wie Meta und X publiziert LinkedIn &lt;strong&gt;keine offizielle IP-Liste&lt;/strong&gt; — Verifikation läuft per ASN plus Reverse-DNS gegen &lt;span class="mono"&gt;*.fwd.linkedin.com&lt;/span&gt;. Hier die aggregierten Ranges (Teil unseres &lt;a href="https://www.parc-network.de/parc-security/"&gt;PARC-Security-Feeds&lt;/a&gt;), die Herleitung und der Microsoft-/AI-Kontext.&lt;/p&gt;
&lt;p&gt;&lt;a href="https://www.parc-network.de/feeds/linkedin.json" target="_blank" rel="noopener" class="btn btn-secondary"&gt;linkedin.json — Feed ansehen&lt;/a&gt; &amp;nbsp; &lt;a href="https://www.linkedin.com/post-inspector/" target="_blank" rel="noopener"&gt;LinkedIn Post Inspector →&lt;/a&gt;&lt;/p&gt;
&lt;h2 id="die-ranges"&gt;Die Ranges&lt;/h2&gt;
&lt;p&gt;Insgesamt &lt;strong&gt;51 Prefixes&lt;/strong&gt; (29 IPv4 + 22 IPv6), aggregiert aus zwei LinkedIn-eigenen ASNs. Die vollständige Liste steht im &lt;a href="https://www.parc-network.de/feeds/linkedin.json" target="_blank" rel="noopener"&gt;Feed&lt;/a&gt;; abgeleitet aus dem ASN-Eigentum (keine offizielle LinkedIn-Liste) und gegen aktive Crawler-IPs per FCrDNS validiert.&lt;/p&gt;</description></item><item><title>M2E Pro — offizielle Server-IPs (Cron/API/Repricer)</title><link>https://www.parc-network.de/m2epro/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://www.parc-network.de/m2epro/</guid><description>&lt;p class="lead"&gt;&lt;strong&gt;M2E Pro&lt;/strong&gt; ist eine Magento-Extension für die Marktplatz-Anbindung (Amazon, eBay, Walmart u.a.). Der M2E-Cloud-Server kommuniziert mit dem Shop — dies sind die &lt;strong&gt;offiziellen Server-IPs&lt;/strong&gt; aus der M2E-Pro-Hilfe-Doku (3 Einträge: Cron, API, Repricer). Teil unseres &lt;a href="https://www.parc-network.de/parc-security/"&gt;PARC-Security-Feeds&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;&lt;a href="https://www.parc-network.de/feeds/m2epro.json" target="_blank" rel="noopener" class="btn btn-secondary"&gt;m2epro.json — Feed ansehen&lt;/a&gt; &amp;nbsp; &lt;a href="https://m2epro.com/" target="_blank" rel="noopener"&gt;m2epro.com →&lt;/a&gt;&lt;/p&gt;
&lt;h2 id="quelle--aktualisierung"&gt;Quelle &amp;amp; Aktualisierung&lt;/h2&gt;
&lt;p&gt;Quelle: M2E-Pro-Hilfe-Doku. &lt;span class="mono"&gt;35.202.39.212&lt;/span&gt; (Cron-Server, eingehende Calls zum Shop), &lt;span class="mono"&gt;34.27.176.50&lt;/span&gt; (api.m2epro.com), &lt;span class="mono"&gt;159.69.64.61&lt;/span&gt; (Repricer, repricer.m2e.cloud). API/Repricer laufen über Hostnamen und sind per DNS auflösbar; der PARC-Feed bildet den dokumentierten Stand ab. Reine IP-Daten ohne Wertung.&lt;/p&gt;</description></item><item><title>Magento Hosting Architektur-Modelle</title><link>https://www.parc-network.de/magento-architektur/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://www.parc-network.de/magento-architektur/</guid><description>&lt;p class="lead"&gt;Wir bauen die Hosting-Architektur passend zu deinem Shop — vom schlanken Einstieg auf einem dedizierten Server bis zur geo-verteilten Architektur mit voller Ausfallsicherheit. Hier die Modelle im Überblick.&lt;/p&gt;
&lt;div class="setups"&gt;&lt;div class="setup-block"&gt;
&lt;div class="setup-card" id="architektur-beispiel-1"&gt;
 &lt;h3&gt;Magento Managed Hosting Architektur Beispiel 1&lt;/h3&gt;
 &lt;p&gt;Unser Standard und so ausgelegt, dass es schnell um weitere VMs erweitert oder zu Beispiel 2 ausgebaut werden kann.&lt;/p&gt;
 &lt;div class="diagram-clipped bsp1"&gt;&lt;svg viewBox="0 0 920 390" xmlns="http://www.w3.org/2000/svg" style="width:100%; height:auto;"&gt;
 &lt;defs&gt;
 &lt;style&gt;
 .vm { fill: #fff; stroke: #306060; stroke-width: 1.3; }
 .vm-n { font: 600 11.5px -apple-system, sans-serif; fill: #306060; }
 .vm-f { font: 9px -apple-system, sans-serif; fill: #888; }
 .vm-num { font: 700 7.5px -apple-system, sans-serif; fill: #b0b0b0; letter-spacing: 0.5px; }
 .lbl { font: 600 9px -apple-system, sans-serif; fill: #888; letter-spacing: 1.8px; }
 .row-lbl { font: 700 10px -apple-system, sans-serif; letter-spacing: 1.5px; }
 .row-sublbl { font: 600 8px -apple-system, sans-serif; letter-spacing: 0.5px; fill: #999; }
 .conn { stroke: #b8c8c8; stroke-width: 1.2; fill: none; }
 .seg { stroke: #d0d0d0; stroke-width: 1; stroke-dasharray: 4 4; fill: none; }
 .cloud-bg { fill: #f0f6f6; stroke: #2a8585; stroke-width: 1.3; stroke-dasharray: 4 3; }
 .dedi-bg { fill: #f0f3f8; stroke: #5a7090; stroke-width: 1.3; stroke-dasharray: 4 3; }
 .infra-host { fill: #f0f3f3; stroke: #b8c8c8; stroke-width: 1.2; }
 .infra-cs { fill: #fff; stroke: #99b0b0; stroke-width: 1; }
 .infra-n { font: 600 10px -apple-system, sans-serif; fill: #406060; letter-spacing: 0.3px; }
 .infra-f { font: 600 8px -apple-system, sans-serif; fill: #99a; letter-spacing: 0.4px; }
 
 .vm-box .vm { transition: fill 0.2s ease, stroke 0.2s ease; }
 .vm-box .vm-default, .vm-box .vm-hover { transition: opacity 0.2s ease; }
 .vm-box .vm-hover { opacity: 0; }
 .vm-infra-box .infra-cs { transition: fill 0.2s ease, stroke 0.2s ease; }
 .vm-infra-box .infra-default, .vm-infra-box .infra-hover { transition: opacity 0.2s ease; }
 .vm-infra-box .infra-hover { opacity: 0; }
 @media (hover: hover) {
 .vm-box { cursor: pointer; }
 .vm-box:hover .vm { fill: #2a8585; stroke: #2a8585; }
 .vm-box:hover text { fill: #fff; }
 .vm-box:hover .vm-default { opacity: 0; }
 .vm-box:hover .vm-hover { opacity: 1; }
 .vm-infra-box { cursor: pointer; }
 .vm-infra-box:hover .infra-cs { fill: #2a8585; stroke: #2a8585; }
 .vm-infra-box:hover text { fill: #fff; }
 .vm-infra-box:hover .infra-default { opacity: 0; }
 .vm-infra-box:hover .infra-hover { opacity: 1; }
 }
 &lt;/style&gt;
 &lt;/defs&gt;

 
 &lt;text x="75" y="22" text-anchor="middle" class="lbl"&gt;INTERNET&lt;/text&gt;
 &lt;text x="255" y="22" text-anchor="middle" class="lbl"&gt;SICHERHEIT&lt;/text&gt;
 &lt;text x="425" y="22" text-anchor="middle" class="lbl"&gt;CACHE&lt;/text&gt;
 &lt;text x="580" y="22" text-anchor="middle" class="lbl"&gt;APP&lt;/text&gt;
 &lt;text x="780" y="22" text-anchor="middle" class="lbl"&gt;DATA&lt;/text&gt;

 
 &lt;line x1="150" y1="35" x2="150" y2="240" class="seg"/&gt;
 &lt;line x1="360" y1="35" x2="360" y2="240" class="seg"/&gt;
 &lt;line x1="490" y1="35" x2="490" y2="240" class="seg"/&gt;
 &lt;line x1="670" y1="35" x2="670" y2="240" class="seg"/&gt;

 
 &lt;rect x="160" y="48" width="745" height="190" rx="8" class="dedi-bg" opacity="0.4"/&gt;

 
 &lt;g transform="rotate(-90, 138, 143)"&gt;
 &lt;text x="138" y="143" text-anchor="middle" class="row-lbl" style="fill:#3a5080;"&gt;DEDIZIERTER SERVER&lt;/text&gt;
 &lt;/g&gt;

 

 
 &lt;rect x="37" y="72" width="56" height="32" rx="3" fill="#fafafa" stroke="#b8c8c8" stroke-width="1.2" stroke-dasharray="3 3"/&gt;
 &lt;text x="65" y="93" text-anchor="middle" class="vm-n" style="font-size:10px;"&gt;Monitoring&lt;/text&gt;

 
 &lt;circle cx="65" cy="143" r="14" fill="none" stroke="#777" stroke-width="1.3"/&gt;
 &lt;line x1="51" y1="143" x2="79" y2="143" stroke="#777" stroke-width="1.3"/&gt;
 &lt;line x1="65" y1="129" x2="65" y2="157" stroke="#777" stroke-width="1.3"/&gt;
 &lt;ellipse cx="65" cy="143" rx="7" ry="14" fill="none" stroke="#777" stroke-width="1.3"/&gt;

 
 &lt;rect x="37" y="182" width="56" height="32" rx="3" fill="#fafafa" stroke="#b8c8c8" stroke-width="1.2" stroke-dasharray="3 3"/&gt;
 &lt;text x="65" y="203" text-anchor="middle" class="vm-n" style="font-size:10px;"&gt;Backup&lt;/text&gt;

 

 
 &lt;a href="https://www.parc-network.de/magento-firewall/" class="vm-link" aria-label="Mehr über die OPNsense-Firewall erfahren"&gt;&lt;g class="vm-box" aria-hidden="true"&gt;
 &lt;rect x="175" y="70" width="78" height="40" rx="4" class="vm"/&gt;
 &lt;text x="249" y="79" text-anchor="end" class="vm-num"&gt;VM 1&lt;/text&gt;
 &lt;text x="214" y="91" text-anchor="middle" class="vm-n vm-default"&gt;OPNsense&lt;/text&gt;
 &lt;text x="214" y="104" text-anchor="middle" class="vm-f vm-default"&gt;Firewall&lt;/text&gt;
 &lt;text x="214" y="91" text-anchor="middle" class="vm-n vm-hover"&gt;2 vCPU&lt;/text&gt;
 &lt;text x="214" y="104" text-anchor="middle" class="vm-f vm-hover"&gt;8 GB RAM&lt;/text&gt;
 &lt;/g&gt;&lt;/a&gt;

 
 &lt;g class="vm-box"&gt;
 &lt;rect x="265" y="70" width="78" height="40" rx="4" class="vm"/&gt;
 &lt;text x="339" y="79" text-anchor="end" class="vm-num"&gt;VM 2&lt;/text&gt;
 &lt;text x="304" y="91" text-anchor="middle" class="vm-n vm-default"&gt;SafeLine&lt;/text&gt;
 &lt;text x="304" y="104" text-anchor="middle" class="vm-f vm-default"&gt;Proxy · Bot · WAF&lt;/text&gt;
 &lt;text x="304" y="91" text-anchor="middle" class="vm-n vm-hover"&gt;4 vCPU&lt;/text&gt;
 &lt;text x="304" y="104" text-anchor="middle" class="vm-f vm-hover"&gt;16 GB RAM&lt;/text&gt;
 &lt;/g&gt;

 
 &lt;line x1="214" y1="110" x2="214" y2="125" class="conn" stroke-dasharray="3 3"/&gt;
 &lt;line x1="304" y1="110" x2="304" y2="125" class="conn" stroke-dasharray="3 3"/&gt;
 &lt;a href="https://www.parc-network.de/parc-security/" class="vm-link" aria-label="Mehr über das PARC-Security-Modul erfahren"&gt;&lt;g class="vm-box" aria-hidden="true"&gt;
 &lt;rect x="175" y="125" width="168" height="40" rx="4" class="vm" stroke-dasharray="4 3"/&gt;
 &lt;text x="259" y="144" text-anchor="middle" class="vm-n"&gt;PARC Security&lt;/text&gt;
 &lt;text x="259" y="157" text-anchor="middle" class="vm-f"&gt;Blacklists · IP-Gruppen · Regeln&lt;/text&gt;
 &lt;/g&gt;&lt;/a&gt;

 

 
 &lt;g class="vm-box"&gt;
 &lt;rect x="375" y="125" width="105" height="40" rx="4" class="vm"/&gt;
 &lt;text x="476" y="134" text-anchor="end" class="vm-num"&gt;VM 3&lt;/text&gt;
 &lt;text x="427" y="146" text-anchor="middle" class="vm-n vm-default"&gt;Varnish&lt;/text&gt;
 &lt;text x="427" y="159" text-anchor="middle" class="vm-f vm-default"&gt;Full-Page-Cache&lt;/text&gt;
 &lt;text x="427" y="146" text-anchor="middle" class="vm-n vm-hover"&gt;2 vCPU&lt;/text&gt;
 &lt;text x="427" y="159" text-anchor="middle" class="vm-f vm-hover"&gt;8 GB RAM&lt;/text&gt;
 &lt;/g&gt;

 
 &lt;g class="vm-box"&gt;
 &lt;rect x="505" y="70" width="150" height="40" rx="4" class="vm"/&gt;
 &lt;text x="651" y="79" text-anchor="end" class="vm-num"&gt;VM 4&lt;/text&gt;
 &lt;text x="580" y="91" text-anchor="middle" class="vm-n vm-default"&gt;Nginx&lt;/text&gt;
 &lt;text x="580" y="104" text-anchor="middle" class="vm-f vm-default"&gt;Frontend&lt;/text&gt;
 &lt;text x="580" y="91" text-anchor="middle" class="vm-n vm-hover"&gt;4 vCPU&lt;/text&gt;
 &lt;text x="580" y="104" text-anchor="middle" class="vm-f vm-hover"&gt;8 GB RAM&lt;/text&gt;
 &lt;/g&gt;

 
 &lt;g class="vm-box"&gt;
 &lt;rect x="505" y="125" width="150" height="40" rx="4" class="vm"/&gt;
 &lt;text x="651" y="134" text-anchor="end" class="vm-num"&gt;VM 5&lt;/text&gt;
 &lt;text x="580" y="146" text-anchor="middle" class="vm-n vm-default"&gt;Nginx&lt;/text&gt;
 &lt;text x="580" y="159" text-anchor="middle" class="vm-f vm-default"&gt;Backend / CLI / Index&lt;/text&gt;
 &lt;text x="580" y="146" text-anchor="middle" class="vm-n vm-hover"&gt;4 vCPU&lt;/text&gt;
 &lt;text x="580" y="159" text-anchor="middle" class="vm-f vm-hover"&gt;8 GB RAM&lt;/text&gt;
 &lt;/g&gt;

 
 &lt;g class="vm-box"&gt;
 &lt;rect x="505" y="180" width="150" height="40" rx="4" class="vm"/&gt;
 &lt;text x="651" y="189" text-anchor="end" class="vm-num"&gt;VM 6&lt;/text&gt;
 &lt;text x="580" y="201" text-anchor="middle" class="vm-n vm-default"&gt;RabbitMQ&lt;/text&gt;
 &lt;text x="580" y="214" text-anchor="middle" class="vm-f vm-default"&gt;Message Queue&lt;/text&gt;
 &lt;text x="580" y="201" text-anchor="middle" class="vm-n vm-hover"&gt;1 vCPU&lt;/text&gt;
 &lt;text x="580" y="214" text-anchor="middle" class="vm-f vm-hover"&gt;2 GB RAM&lt;/text&gt;
 &lt;/g&gt;

 
 &lt;g class="vm-box"&gt;
 &lt;rect x="685" y="70" width="200" height="40" rx="4" class="vm"/&gt;
 &lt;text x="881" y="79" text-anchor="end" class="vm-num"&gt;VM 7&lt;/text&gt;
 &lt;text x="785" y="91" text-anchor="middle" class="vm-n vm-default"&gt;MariaDB&lt;/text&gt;
 &lt;text x="785" y="104" text-anchor="middle" class="vm-f vm-default"&gt;Datenbank&lt;/text&gt;
 &lt;text x="785" y="91" text-anchor="middle" class="vm-n vm-hover"&gt;4 vCPU&lt;/text&gt;
 &lt;text x="785" y="104" text-anchor="middle" class="vm-f vm-hover"&gt;24 GB RAM&lt;/text&gt;
 &lt;/g&gt;

 
 &lt;g class="vm-box"&gt;
 &lt;rect x="685" y="125" width="200" height="40" rx="4" class="vm"/&gt;
 &lt;text x="881" y="134" text-anchor="end" class="vm-num"&gt;VM 8&lt;/text&gt;
 &lt;text x="785" y="146" text-anchor="middle" class="vm-n vm-default"&gt;OpenSearch&lt;/text&gt;
 &lt;text x="785" y="159" text-anchor="middle" class="vm-f vm-default"&gt;Produkt-Suche&lt;/text&gt;
 &lt;text x="785" y="146" text-anchor="middle" class="vm-n vm-hover"&gt;3 vCPU&lt;/text&gt;
 &lt;text x="785" y="159" text-anchor="middle" class="vm-f vm-hover"&gt;8 GB RAM&lt;/text&gt;
 &lt;/g&gt;

 
 &lt;g class="vm-box"&gt;
 &lt;rect x="685" y="180" width="200" height="40" rx="4" class="vm"/&gt;
 &lt;text x="881" y="189" text-anchor="end" class="vm-num"&gt;VM 9&lt;/text&gt;
 &lt;text x="785" y="201" text-anchor="middle" class="vm-n vm-default"&gt;Redis&lt;/text&gt;
 &lt;text x="785" y="214" text-anchor="middle" class="vm-f vm-default"&gt;Sessions&lt;/text&gt;
 &lt;text x="785" y="201" text-anchor="middle" class="vm-n vm-hover"&gt;2 vCPU&lt;/text&gt;
 &lt;text x="785" y="214" text-anchor="middle" class="vm-f vm-hover"&gt;4 GB RAM&lt;/text&gt;
 &lt;/g&gt;

 

 
 &lt;line x1="20" y1="270" x2="900" y2="270" class="seg"/&gt;

 
 &lt;text x="40" y="288" class="lbl"&gt;INFRASTRUKTUR&lt;/text&gt;

 
 &lt;rect x="175" y="300" width="712" height="66" rx="4" class="infra-host"/&gt;
 &lt;text x="531" y="318" text-anchor="middle" class="infra-n"&gt;Dedizierter Server&lt;/text&gt;
 &lt;text x="531" y="330" text-anchor="middle" class="infra-f"&gt;PROXMOX VE&lt;/text&gt;

 &lt;g class="vm-infra-box"&gt;
 &lt;rect x="190" y="337" width="62" height="24" rx="3" class="infra-cs"/&gt;
 &lt;text x="221" y="352" text-anchor="middle" class="infra-f infra-default" style="font-size:9px;"&gt;VM 1&lt;/text&gt;
 &lt;text x="221" y="347" text-anchor="middle" class="infra-f infra-hover" style="font-size:7px;"&gt;2 vCPU&lt;/text&gt;
 &lt;text x="221" y="357" text-anchor="middle" class="infra-f infra-hover" style="font-size:7px;"&gt;8 GB RAM&lt;/text&gt;
 &lt;/g&gt;

 &lt;g class="vm-infra-box"&gt;
 &lt;rect x="266" y="337" width="62" height="24" rx="3" class="infra-cs"/&gt;
 &lt;text x="297" y="352" text-anchor="middle" class="infra-f infra-default" style="font-size:9px;"&gt;VM 2&lt;/text&gt;
 &lt;text x="297" y="347" text-anchor="middle" class="infra-f infra-hover" style="font-size:7px;"&gt;4 vCPU&lt;/text&gt;
 &lt;text x="297" y="357" text-anchor="middle" class="infra-f infra-hover" style="font-size:7px;"&gt;16 GB RAM&lt;/text&gt;
 &lt;/g&gt;

 &lt;g class="vm-infra-box"&gt;
 &lt;rect x="342" y="337" width="62" height="24" rx="3" class="infra-cs"/&gt;
 &lt;text x="373" y="352" text-anchor="middle" class="infra-f infra-default" style="font-size:9px;"&gt;VM 3&lt;/text&gt;
 &lt;text x="373" y="347" text-anchor="middle" class="infra-f infra-hover" style="font-size:7px;"&gt;2 vCPU&lt;/text&gt;
 &lt;text x="373" y="357" text-anchor="middle" class="infra-f infra-hover" style="font-size:7px;"&gt;8 GB RAM&lt;/text&gt;
 &lt;/g&gt;

 &lt;g class="vm-infra-box"&gt;
 &lt;rect x="418" y="337" width="62" height="24" rx="3" class="infra-cs"/&gt;
 &lt;text x="449" y="352" text-anchor="middle" class="infra-f infra-default" style="font-size:9px;"&gt;VM 4&lt;/text&gt;
 &lt;text x="449" y="347" text-anchor="middle" class="infra-f infra-hover" style="font-size:7px;"&gt;4 vCPU&lt;/text&gt;
 &lt;text x="449" y="357" text-anchor="middle" class="infra-f infra-hover" style="font-size:7px;"&gt;8 GB RAM&lt;/text&gt;
 &lt;/g&gt;

 &lt;g class="vm-infra-box"&gt;
 &lt;rect x="494" y="337" width="62" height="24" rx="3" class="infra-cs"/&gt;
 &lt;text x="525" y="352" text-anchor="middle" class="infra-f infra-default" style="font-size:9px;"&gt;VM 5&lt;/text&gt;
 &lt;text x="525" y="347" text-anchor="middle" class="infra-f infra-hover" style="font-size:7px;"&gt;4 vCPU&lt;/text&gt;
 &lt;text x="525" y="357" text-anchor="middle" class="infra-f infra-hover" style="font-size:7px;"&gt;8 GB RAM&lt;/text&gt;
 &lt;/g&gt;

 &lt;g class="vm-infra-box"&gt;
 &lt;rect x="570" y="337" width="62" height="24" rx="3" class="infra-cs"/&gt;
 &lt;text x="601" y="352" text-anchor="middle" class="infra-f infra-default" style="font-size:9px;"&gt;VM 6&lt;/text&gt;
 &lt;text x="601" y="347" text-anchor="middle" class="infra-f infra-hover" style="font-size:7px;"&gt;1 vCPU&lt;/text&gt;
 &lt;text x="601" y="357" text-anchor="middle" class="infra-f infra-hover" style="font-size:7px;"&gt;2 GB RAM&lt;/text&gt;
 &lt;/g&gt;

 &lt;g class="vm-infra-box"&gt;
 &lt;rect x="646" y="337" width="62" height="24" rx="3" class="infra-cs"/&gt;
 &lt;text x="677" y="352" text-anchor="middle" class="infra-f infra-default" style="font-size:9px;"&gt;VM 7&lt;/text&gt;
 &lt;text x="677" y="347" text-anchor="middle" class="infra-f infra-hover" style="font-size:7px;"&gt;4 vCPU&lt;/text&gt;
 &lt;text x="677" y="357" text-anchor="middle" class="infra-f infra-hover" style="font-size:7px;"&gt;24 GB RAM&lt;/text&gt;
 &lt;/g&gt;

 &lt;g class="vm-infra-box"&gt;
 &lt;rect x="722" y="337" width="62" height="24" rx="3" class="infra-cs"/&gt;
 &lt;text x="753" y="352" text-anchor="middle" class="infra-f infra-default" style="font-size:9px;"&gt;VM 8&lt;/text&gt;
 &lt;text x="753" y="347" text-anchor="middle" class="infra-f infra-hover" style="font-size:7px;"&gt;3 vCPU&lt;/text&gt;
 &lt;text x="753" y="357" text-anchor="middle" class="infra-f infra-hover" style="font-size:7px;"&gt;8 GB RAM&lt;/text&gt;
 &lt;/g&gt;

 &lt;g class="vm-infra-box"&gt;
 &lt;rect x="798" y="337" width="62" height="24" rx="3" class="infra-cs"/&gt;
 &lt;text x="829" y="352" text-anchor="middle" class="infra-f infra-default" style="font-size:9px;"&gt;VM 9&lt;/text&gt;
 &lt;text x="829" y="347" text-anchor="middle" class="infra-f infra-hover" style="font-size:7px;"&gt;2 vCPU&lt;/text&gt;
 &lt;text x="829" y="357" text-anchor="middle" class="infra-f infra-hover" style="font-size:7px;"&gt;4 GB RAM&lt;/text&gt;
 &lt;/g&gt;

 &lt;/svg&gt;&lt;/div&gt;
 &lt;button class="arch-zones-toggle" data-diagram="bsp1" aria-expanded="false"&gt;
 &lt;span&gt;Architektur-Details&lt;/span&gt;
 &lt;svg class="arch-zones-toggle-arrow" viewBox="0 0 24 24" width="20" height="20" fill="none" stroke="currentColor" stroke-width="2.4" stroke-linecap="round" stroke-linejoin="round"&gt;
 &lt;polyline points="6 9 12 15 18 9"&gt;&lt;/polyline&gt;
 &lt;/svg&gt;
 &lt;/button&gt;
 &lt;div class="arch-zones"&gt;
 &lt;div class="arch-zones-more" id="archZonesMore"&gt;
 &lt;div class="arch-zone"&gt;
 &lt;div class="arch-zone-label"&gt;Internet&lt;/div&gt;
 &lt;div class="arch-zone-text"&gt;Eingehender Traffic wie echte Kunden, Suchmaschinen-Bots, Security-Scanner, Brute-Force-Versuche, böse IPs, Spam-Bots und sonstiges Hintergrundrauschen aus dem Internet. Aktuell sind über 30% aller HTTP-Requests weltweit Bot-Traffic — &lt;strong&gt;bis 2027 wird Bot-Traffic den menschlichen überholen!&lt;/strong&gt;&lt;/div&gt;
 &lt;/div&gt;
 &lt;div class="arch-zone"&gt;
 &lt;div class="arch-zone-label"&gt;Sicherheit&lt;/div&gt;
 &lt;div class="arch-zone-text"&gt;Diese Schicht hält den unerwünschten Traffic von den nachfolgenden Schichten fern, schont so Ressourcen und sorgt vor allem für ein ungestörtes Einkaufserlebnis. &lt;a href="https://www.parc-network.de/magento-firewall/"&gt;OPNsense&lt;/a&gt;, SafeLine und &lt;a href="https://www.parc-network.de/parc-security/"&gt;&lt;strong&gt;PARC Security&lt;/strong&gt;&lt;/a&gt; ergänzen sich gegenseitig: Die OPNsense Firewall blockt auf Layer 3/4 (Ports, IP-Bereiche, ungewollte Verbindungen). Die SafeLine Web Application Firewall mit semantischer Angriffs-Erkennung filtert auf Layer 7 (SQL-Injection, XSS, Bot-Traffic, Credential-Stuffing). Das PARC Security-Modul versorgt OPNsense und SafeLine mit aktuellen Blacklists und stellt IP-Gruppen für gute wie böse Bots bereit, auf denen viele WAF-Regeln basieren. &lt;strong&gt;Interessant zu wissen:&lt;/strong&gt; Klassische CDN-WAFs wie Cloudflare, Akamai oder AWS CloudFront terminieren TLS auf ihrer Edge — der Traffic wird dort zur Inspektion entschlüsselt und ist dadurch technisch einsehbar. SafeLine terminiert TLS und entschlüsselt auf eurer eigenen Infrastruktur!
 &lt;div class="arch-zone-cta"&gt;
 &lt;a href="https://www.parc-network.de/magento-firewall/" class="arch-zone-pill"&gt;→ OPNsense Firewall&lt;/a&gt;
 &lt;a href="https://www.parc-network.de/parc-security/" class="arch-zone-pill"&gt;→ PARC Security&lt;/a&gt;
 &lt;/div&gt;
 &lt;/div&gt;
 &lt;/div&gt;
 &lt;div class="arch-zone"&gt;
 &lt;div class="arch-zone-label"&gt;Cache&lt;/div&gt;
 &lt;div class="arch-zone-text"&gt;Varnish liefert Anfragen direkt aus dem Cache (Full-Page-Cache, FPC), ohne dass die nachfolgenden Schichten — Nginx, PHP-FPM, Datenbank — aktiv werden müssen. Das spart nicht nur Ressourcen, sondern hat als Konsequenz erheblichen Einfluss auf die Ausliefergeschwindigkeit der Seiten. Produkt- und Kategorieseiten werden beispielsweise blitzschnell ausgeliefert.&lt;/div&gt;
 &lt;/div&gt;
 &lt;div class="arch-zone"&gt;
 &lt;div class="arch-zone-label"&gt;App&lt;/div&gt;
 &lt;div class="arch-zone-text"&gt;In unserer Architektur sind Frontend und Backend standardmäßig getrennt. Der Kunde wird durch Indexer, längere Crons oder große Import-/Export-Vorgänge nicht bei seinem Einkaufserlebnis gestört. Aber auch die Sicherheit wird durch die Trennung verbessert: Das Magento-Backend (Admin-Interface) ist beispielsweise nur über VPN oder IP-Restriktionen erreichbar. Außerdem ermöglicht die Trennung die horizontale Skalierung des Frontends — bei wachsendem Traffic werden mehrere Frontend-Nodes parallel betrieben, während Backend, Cron und Indexer zentral bleiben. &lt;strong&gt;RabbitMQ&lt;/strong&gt; verteilt asynchrone Magento-Aufgaben (Massen-Attribut-Updates, Bilder-Generierung, Exports, ERP-Sync) auf einen oder mehrere Worker, damit der Server nicht überlastet wird — und macht eine horizontale Frontend-Skalierung erst sauber möglich.&lt;/div&gt;
 &lt;/div&gt;
 &lt;div class="arch-zone"&gt;
 &lt;div class="arch-zone-label"&gt;Data&lt;/div&gt;
 &lt;div class="arch-zone-text"&gt;Die Hauptdatenbank ist &lt;strong&gt;MariaDB&lt;/strong&gt; — bewusst statt MySQL, weil sie sich bei Bedarf direkt in einen Galera-Cluster (mit ProxySQL als Router) umwandeln lässt. &lt;strong&gt;OpenSearch&lt;/strong&gt; übernimmt die Produktsuche und lässt sich analog durch eine Coordination-Node und weitere Such-Instanzen horizontal skalieren. &lt;strong&gt;Redis&lt;/strong&gt; hält die Frontend- und Backend-Sessions.&lt;/div&gt;
 &lt;/div&gt;
 &lt;div class="arch-zone"&gt;
 &lt;div class="arch-zone-label"&gt;Infra&amp;shy;struktur&lt;/div&gt;
 &lt;div class="arch-zone-text"&gt;Bei der Infrastruktur setzen wir grundsätzlich auf dedizierte Server auf Basis von &lt;strong&gt;Proxmox VE&lt;/strong&gt;. Jeder Dienst läuft gekapselt in einer eigenen VM — Optimierung, Skalierung und Updates passieren gezielt dort, wo es nötig ist. Das Setup ist von Anfang an so ausgelegt, dass es sich jederzeit um weitere Cloud- oder dedizierte Server erweitern lässt, um mehr Ausfallsicherheit und Performance zu erreichen.&lt;/div&gt;
 &lt;/div&gt;
 &lt;p class="arch-config-caption"&gt;&lt;em&gt;Beispielkonfiguration bei Hetzner: 1× EX44 (64 GB RAM) + Storage Box (BX11) — Stand 14.06.2026&lt;/em&gt;&lt;/p&gt;</description></item><item><title>Max-Planck-Institut für Informatik — per-IP self-ID via mpi-inf.mpg.de</title><link>https://www.parc-network.de/mpi-inf/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://www.parc-network.de/mpi-inf/</guid><description>&lt;p class="lead"&gt;&lt;strong&gt;akademischer Internet-Mess-Scanner&lt;/strong&gt; des Max-Planck-Instituts für Informatik (DE). Kein SEO-Tool. Die Scan-IPs sind &lt;strong&gt;self-identifizierend&lt;/strong&gt;: Reverse-DNS &lt;span class="mono"&gt;inet-research-scan-*.mpi-inf.mpg.de&lt;/span&gt;. Entdeckt im &lt;a href="https://www.parc-network.de/cins/"&gt;CINS-Abgleich&lt;/a&gt; und per Nachbar-Range-Scan vervollständigt — jede IP einzeln reverse-bestätigt (26). Teil unseres &lt;a href="https://www.parc-network.de/parc-security/"&gt;PARC-Security-Feeds&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;&lt;a href="https://www.parc-network.de/feeds/mpi-inf.json" target="_blank" rel="noopener" class="btn btn-secondary"&gt;mpi-inf.json — Feed ansehen&lt;/a&gt; &amp;nbsp; &lt;a href="https://www.mpi-inf.mpg.de/" target="_blank" rel="noopener"&gt;www.mpi-inf.mpg.de →&lt;/a&gt;&lt;/p&gt;
&lt;h2 id="verifikation--jede-ip-einzeln"&gt;Verifikation — jede IP einzeln&lt;/h2&gt;
&lt;p&gt;Den Reverse-PTR &lt;span class="mono"&gt;inet-research-scan-*.mpi-inf.mpg.de&lt;/span&gt; kann nur der IP-Betreiber setzen — ein nicht-fälschbarer Eigentums-Hinweis. Seed aus den &lt;strong&gt;aktiv scannenden CINS-IPs&lt;/strong&gt;, per Reverse-Scan der umliegenden /24 vervollständigt; jede IP einzeln bestätigt:&lt;/p&gt;
&lt;pre tabindex="0"&gt;&lt;code&gt;26 IPs → alle PTR mpi-inf.mpg.de
&lt;/code&gt;&lt;/pre&gt;&lt;p&gt;Reverse-only (Forward nicht durchgängig prüfbar, wie bei Shodan/Infrawatch). AbuseIPDB führt diese IPs teils mit Score 100 — es sind dennoch benigne Research-Scanner.&lt;/p&gt;</description></item><item><title>Meta-Crawler (Facebook · Instagram · WhatsApp · Threads) — die 5 Bots, ASN-Verifikation und IP-Ranges</title><link>https://www.parc-network.de/meta/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://www.parc-network.de/meta/</guid><description>&lt;p class="lead"&gt;Meta Platforms betreibt für Facebook, Instagram, Messenger, Threads und WhatsApp &lt;strong&gt;fünf verschiedene Crawler&lt;/strong&gt; — vom harmlosen Link-Preview-Bot bis zum AI-Training-Scraper. Meta publiziert die User-Agent-Tokens offiziell, aber &lt;strong&gt;keine IP-Liste&lt;/strong&gt;: Verifikation läuft laut Meta-Doku über die ASN. Hier die fünf Bots, was man mit ihnen tun sollte, und wie unser &lt;a href="https://www.parc-network.de/parc-security/"&gt;PARC-Security-Feed&lt;/a&gt; die Ranges aller fünf Meta-ASNs zusammenfasst.&lt;/p&gt;
&lt;p&gt;&lt;a href="https://www.parc-network.de/feeds/meta.json" target="_blank" rel="noopener" class="btn btn-secondary"&gt;meta.json — Feed ansehen&lt;/a&gt; &amp;nbsp; &lt;a href="https://developers.facebook.com/documentation/sharing/webmasters/web-crawlers" target="_blank" rel="noopener"&gt;Offizielle Meta-Crawler-Doku →&lt;/a&gt;&lt;/p&gt;
&lt;h2 id="die-fünf-meta-crawler"&gt;Die fünf Meta-Crawler&lt;/h2&gt;
&lt;table&gt;
	&lt;thead&gt;
			&lt;tr&gt;
					&lt;th&gt;Crawler&lt;/th&gt;
					&lt;th&gt;User-Agent&lt;/th&gt;
					&lt;th&gt;Zweck&lt;/th&gt;
					&lt;th&gt;robots.txt&lt;/th&gt;
			&lt;/tr&gt;
	&lt;/thead&gt;
	&lt;tbody&gt;
			&lt;tr&gt;
					&lt;td&gt;&lt;strong&gt;FacebookExternalHit&lt;/strong&gt;&lt;/td&gt;
					&lt;td&gt;&lt;code&gt;facebookexternalhit/1.1&lt;/code&gt;&lt;/td&gt;
					&lt;td&gt;Link-Previews beim Teilen (Open Graph)&lt;/td&gt;
					&lt;td&gt;kann sie bei Security-/Integrity-Checks ignorieren&lt;/td&gt;
			&lt;/tr&gt;
			&lt;tr&gt;
					&lt;td&gt;&lt;strong&gt;Meta-WebIndexer&lt;/strong&gt;&lt;/td&gt;
					&lt;td&gt;&lt;code&gt;meta-webindexer/1.1&lt;/code&gt;&lt;/td&gt;
					&lt;td&gt;Indexierung für Meta-AI-Search&lt;/td&gt;
					&lt;td&gt;befolgt robots.txt&lt;/td&gt;
			&lt;/tr&gt;
			&lt;tr&gt;
					&lt;td&gt;&lt;strong&gt;Meta-ExternalAds&lt;/strong&gt;&lt;/td&gt;
					&lt;td&gt;&lt;code&gt;meta-externalads/1.1&lt;/code&gt;&lt;/td&gt;
					&lt;td&gt;Werbe-/Geschäfts-Optimierung&lt;/td&gt;
					&lt;td&gt;befolgt robots.txt&lt;/td&gt;
			&lt;/tr&gt;
			&lt;tr&gt;
					&lt;td&gt;&lt;strong&gt;Meta-ExternalAgent&lt;/strong&gt;&lt;/td&gt;
					&lt;td&gt;&lt;code&gt;meta-externalagent/1.1&lt;/code&gt;&lt;/td&gt;
					&lt;td&gt;AI-Training (Llama u. a.) + AI-Indexierung&lt;/td&gt;
					&lt;td&gt;befolgt robots.txt&lt;/td&gt;
			&lt;/tr&gt;
			&lt;tr&gt;
					&lt;td&gt;&lt;strong&gt;Meta-ExternalFetcher&lt;/strong&gt;&lt;/td&gt;
					&lt;td&gt;&lt;code&gt;meta-externalfetcher/1.1&lt;/code&gt;&lt;/td&gt;
					&lt;td&gt;user-getriggerte AI-Fetches&lt;/td&gt;
					&lt;td&gt;&lt;strong&gt;umgeht robots.txt&lt;/strong&gt; (user-getriggert)&lt;/td&gt;
			&lt;/tr&gt;
	&lt;/tbody&gt;
&lt;/table&gt;
&lt;h2 id="allowlisten-oder-blocken"&gt;Allowlisten oder blocken?&lt;/h2&gt;
&lt;p&gt;Anders als ein Security-Scanner ist Meta nicht pauschal „rein oder raus&amp;quot; — die fünf Crawler haben unterschiedliche Use-Cases (siehe Tabelle oben): &lt;code&gt;FacebookExternalHit&lt;/code&gt; erzeugt die Link-Previews beim Teilen auf Facebook/Instagram/WhatsApp, &lt;code&gt;Meta-WebIndexer&lt;/code&gt; betrifft die Sichtbarkeit in Meta-AI-Search, &lt;code&gt;Meta-ExternalAgent&lt;/code&gt; und &lt;code&gt;Meta-ExternalFetcher&lt;/code&gt; AI-Training bzw. user-getriggerte AI-Fetches (&lt;code&gt;Meta-ExternalFetcher&lt;/code&gt; umgeht robots.txt), &lt;code&gt;Meta-ExternalAds&lt;/code&gt; die Ads-Optimierung.&lt;/p&gt;</description></item><item><title>MJ12bot — „nicht IP-identifizierbar" stimmt nicht: 90 FCrDNS-Knoten</title><link>https://www.parc-network.de/mj12bot/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://www.parc-network.de/mj12bot/</guid><description>&lt;p class="lead"&gt;&lt;strong&gt;MJ12bot&lt;/strong&gt; ist der Backlink-Crawler von &lt;strong&gt;Majestic&lt;/strong&gt; (UK). Majestic schreibt, er sei ein „community based distributed crawler" und „nicht per IP blockbar". &lt;strong&gt;Empirisch stimmt das nicht:&lt;/strong&gt; der aktuelle Kern self-identifiziert sauber per &lt;strong&gt;FCrDNS&lt;/strong&gt; &lt;span class="mono"&gt;crawl-&amp;lt;zufall&amp;gt;.mj12bot.com&lt;/span&gt; und sitzt zu &lt;strong&gt;72 % auf OVH&lt;/strong&gt; (AS16276) plus Veloxserv. Teil unseres &lt;a href="https://www.parc-network.de/parc-security/"&gt;PARC-Security-Feeds&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;&lt;a href="https://www.parc-network.de/feeds/mj12bot.json" target="_blank" rel="noopener" class="btn btn-secondary"&gt;mj12bot.json — Feed ansehen&lt;/a&gt; &amp;nbsp; &lt;a href="https://mj12bot.com/" target="_blank" rel="noopener"&gt;mj12bot.com →&lt;/a&gt;&lt;/p&gt;
&lt;h2 id="verifikation--jede-ip-einzeln"&gt;Verifikation — jede IP einzeln&lt;/h2&gt;
&lt;p&gt;Das PTR-Muster &lt;span class="mono"&gt;crawl-&amp;lt;zufall&amp;gt;.mj12bot.com&lt;/span&gt; ist &lt;strong&gt;FCrDNS-bestätigt&lt;/strong&gt; (Reverse + Forward-A-Record zurück auf dieselbe IP) — nur Majestic kann das setzen. Wir haben die Flotte &lt;strong&gt;aus drei unabhängigen Quellen trianguliert&lt;/strong&gt;:&lt;/p&gt;</description></item><item><title>Modat — der Scanner, der seine Liste publiziert und sie auch einhält</title><link>https://www.parc-network.de/modat/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://www.parc-network.de/modat/</guid><description>&lt;p class="lead"&gt;Modat ist ein internet-weiter &lt;strong&gt;Attack-Surface-/Asset-Discovery-Scanner&lt;/strong&gt; von &lt;strong&gt;Modat B.V.&lt;/strong&gt; (Niederlande, eigene ASN &lt;span class="mono"&gt;MODAT-01&lt;/span&gt;). Kein SEO-Tool. Modat handelt vorbildlich: feste IPs, sprechendes Reverse-DNS, und eine &lt;strong&gt;offizielle, publizierte IP-Liste&lt;/strong&gt;. Anders als bei manch anderem „offiziellen“ Feed ist sie hier &lt;strong&gt;vollständig&lt;/strong&gt; und &lt;strong&gt;vollständig FCrDNS-verifizierbar&lt;/strong&gt;: &lt;strong&gt;35 CIDRs = 186 IPs&lt;/strong&gt;. Teil unseres &lt;a href="https://www.parc-network.de/parc-security/"&gt;PARC-Security-Feeds&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;&lt;a href="https://www.parc-network.de/feeds/modat.json" target="_blank" rel="noopener" class="btn btn-secondary"&gt;modat.json — Feed ansehen&lt;/a&gt; &amp;nbsp; &lt;a href="https://scanner.modat.io/ipv4.txt" target="_blank" rel="noopener"&gt;Modat — offizielle Liste →&lt;/a&gt;&lt;/p&gt;
&lt;h2 id="die-offizielle-liste--und-warum-sie-diesmal-stimmt"&gt;Die offizielle Liste — und warum sie diesmal stimmt&lt;/h2&gt;
&lt;p&gt;Modat publiziert seine Scan-IPs unter &lt;span class="mono"&gt;scanner.modat.io/ipv4.txt&lt;/span&gt; — &lt;strong&gt;35 CIDR-Blöcke (186 Adressen)&lt;/strong&gt;. Bei ONYPHE hatten wir gelernt, dass „offizielle“ Listen oft unvollständig sind. Hier nicht: Wir haben die Liste gegen unsere &lt;a href="https://www.parc-network.de/cins/"&gt;CINS-Blacklist&lt;/a&gt; gehalten — CINS hat &lt;strong&gt;107 aktiv scannende Modat-IPs&lt;/strong&gt; erfasst, und &lt;strong&gt;jede einzelne liegt innerhalb der offiziellen Liste&lt;/strong&gt;. Kein einziger Scanner außerhalb. Die Liste ist also vollständig und wird direkt übernommen.&lt;/p&gt;</description></item><item><title>Mollie — offizielle IP-Ranges (Webhook/API)</title><link>https://www.parc-network.de/mollie/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://www.parc-network.de/mollie/</guid><description>&lt;p class="lead"&gt;&lt;strong&gt;Mollie&lt;/strong&gt; (NL) ist ein Zahlungsanbieter. Dies sind die &lt;strong&gt;offiziellen IP-Ranges&lt;/strong&gt;, unter denen Mollies Webhook-/API-Server senden bzw. erreichbar sind — aus der offiziellen Quelle zu PARC-Feed normalisiert (16 Einträge). Teil unseres &lt;a href="https://www.parc-network.de/parc-security/"&gt;PARC-Security-Feeds&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;&lt;a href="https://www.parc-network.de/feeds/mollie.json" target="_blank" rel="noopener" class="btn btn-secondary"&gt;mollie.json — Feed ansehen&lt;/a&gt; &amp;nbsp; &lt;a href="https://www.mollie.com/" target="_blank" rel="noopener"&gt;www.mollie.com →&lt;/a&gt;&lt;/p&gt;
&lt;h2 id="quelle--aktualisierung"&gt;Quelle &amp;amp; Aktualisierung&lt;/h2&gt;
&lt;p&gt;Quelle: &lt;span class="mono"&gt;ip-ranges.mollie.com/ips.txt&lt;/span&gt; — offiziell publiziert. Die Liste wird von einem maschinenlesbaren Endpoint nachgezogen. Mollie kann die Ranges jederzeit ändern; der PARC-Feed bildet den offiziellen Stand ab. Reine IP-Daten ohne Wertung.&lt;/p&gt;
&lt;h2 id="quellen"&gt;Quellen&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://www.mollie.com/" target="_blank" rel="noopener"&gt;Mollie&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://ip-ranges.mollie.com/ips.txt" target="_blank" rel="noopener"&gt;Offizielle IP-Quelle&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;p style="margin-top: 40px;"&gt;&lt;a href="https://www.parc-network.de/parc-security/" class="btn btn-secondary"&gt;← Zurück zu PARC Security&lt;/a&gt; &amp;nbsp; &lt;a href="https://www.parc-network.de/#kontakt" class="btn btn-primary"&gt;Kontakt aufnehmen&lt;/a&gt;&lt;/p&gt;</description></item><item><title>Naver Yeti — wie wir 618 Crawler-IPs vollständig per FCrDNS verifiziert haben</title><link>https://www.parc-network.de/naver/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://www.parc-network.de/naver/</guid><description>&lt;p class="lead"&gt;Yeti ist der Web-Crawler von &lt;strong&gt;Naver&lt;/strong&gt;, der größten Suchmaschine Südkoreas. Naver publiziert &lt;strong&gt;keine offizielle IP-Liste&lt;/strong&gt; — die eigene Doku verweist stattdessen auf &lt;strong&gt;Reverse-DNS-Verifikation&lt;/strong&gt; gegen &lt;span class="mono"&gt;*.web.naver.com&lt;/span&gt; (dasselbe Prinzip wie Googles „verify Googlebot"). Wir haben die vier aktiven Crawler-Blöcke deshalb vollständig gesweept und &lt;strong&gt;jede einzelne&lt;/strong&gt; der 618 gefundenen IPs bidirektional bestätigt. Teil unseres &lt;a href="https://www.parc-network.de/parc-security/"&gt;PARC-Security-Feeds&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;&lt;a href="https://www.parc-network.de/feeds/naver.json" target="_blank" rel="noopener" class="btn btn-secondary"&gt;naver.json — Feed ansehen&lt;/a&gt; &amp;nbsp; &lt;a href="https://help.naver.com/service/5626/contents/8026" target="_blank" rel="noopener"&gt;Naver — Yeti-Robot-Doku →&lt;/a&gt;&lt;/p&gt;
&lt;h2 id="der-feed"&gt;Der Feed&lt;/h2&gt;
&lt;p&gt;&lt;strong&gt;38 CIDR-Prefixes = 618 verifizierte IPs&lt;/strong&gt;, verteilt auf vier KR-Blöcke:&lt;/p&gt;</description></item><item><title>NETSCOUT ATLAS — eigener Arbor-Block (AS20052), PTR internet-albedo.net</title><link>https://www.parc-network.de/netscout/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://www.parc-network.de/netscout/</guid><description>&lt;p class="lead"&gt;&lt;strong&gt;NETSCOUT&lt;/strong&gt; betreibt mit &lt;strong&gt;ATLAS&lt;/strong&gt; (über Arbor Networks) einen internet-weiten &lt;strong&gt;Mess-/Scan-Dienst&lt;/strong&gt;. Kein SEO-Tool. Doppelt belegt: &lt;strong&gt;Eigen-ASN AS20052&lt;/strong&gt; (ARBOR) und self-identifizierende PTR auf &lt;span class="mono"&gt;internet-albedo.net&lt;/span&gt;. Teil unseres &lt;a href="https://www.parc-network.de/parc-security/"&gt;PARC-Security-Feeds&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;&lt;a href="https://www.parc-network.de/feeds/netscout.json" target="_blank" rel="noopener" class="btn btn-secondary"&gt;netscout.json — Feed ansehen&lt;/a&gt; &amp;nbsp; &lt;a href="https://www.internet-albedo.net/" target="_blank" rel="noopener"&gt;www.internet-albedo.net →&lt;/a&gt;&lt;/p&gt;
&lt;h2 id="verifikation--jede-ip-einzeln"&gt;Verifikation — jede IP einzeln&lt;/h2&gt;
&lt;p&gt;Der /23-Block 146.88.240.0/23 gehört &lt;strong&gt;AS20052 (ARBOR-AS, Arbor Networks — NETSCOUT)&lt;/strong&gt;. Per-IP-ASN bestätigt:&lt;/p&gt;
&lt;pre tabindex="0"&gt;&lt;code&gt;510 / 510 Host-IPs → alle AS20052 (0 Fremd-IPs, vollständig)
&lt;/code&gt;&lt;/pre&gt;&lt;p&gt;455 davon self-identifizieren zusätzlich per PTR auf &lt;span class="mono"&gt;internet-albedo.net&lt;/span&gt; (NETSCOUTs Scan-Domain).&lt;/p&gt;
&lt;h2 id="quellen"&gt;Quellen&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://www.internet-albedo.net/" target="_blank" rel="noopener"&gt;internet-albedo.net (NETSCOUT ATLAS)&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://bgp.he.net/AS20052" target="_blank" rel="noopener"&gt;AS20052&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/Connie-Wild/scanner-ip-list" target="_blank" rel="noopener"&gt;Connie-Wild — scanner-ip-list (GitHub)&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;p style="margin-top: 40px;"&gt;&lt;a href="https://www.parc-network.de/parc-security/" class="btn btn-secondary"&gt;← Zurück zu PARC Security&lt;/a&gt; &amp;nbsp; &lt;a href="https://www.parc-network.de/#kontakt" class="btn btn-primary"&gt;Kontakt aufnehmen&lt;/a&gt;&lt;/p&gt;</description></item><item><title>netsecscan.net — per-IP self-ID via netsecscan.net</title><link>https://www.parc-network.de/netsecscan/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://www.parc-network.de/netsecscan/</guid><description>&lt;p class="lead"&gt;&lt;strong&gt;netsecscan.net&lt;/strong&gt; betreibt einen internet-weiten &lt;strong&gt;Security-Scanner&lt;/strong&gt;. Kein SEO-Tool. Die Scan-IPs sind &lt;strong&gt;self-identifizierend&lt;/strong&gt;: PTR auf &lt;span class="mono"&gt;netsecscan.net&lt;/span&gt;. Jede IP einzeln reverse-geprüft. Teil unseres &lt;a href="https://www.parc-network.de/parc-security/"&gt;PARC-Security-Feeds&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;&lt;a href="https://www.parc-network.de/feeds/netsecscan.json" target="_blank" rel="noopener" class="btn btn-secondary"&gt;netsecscan.json — Feed ansehen&lt;/a&gt; &amp;nbsp; &lt;a href="http://www.netsecscan.net/" target="_blank" rel="noopener"&gt;www.netsecscan.net →&lt;/a&gt;&lt;/p&gt;
&lt;h2 id="verifikation--jede-ip-einzeln"&gt;Verifikation — jede IP einzeln&lt;/h2&gt;
&lt;p&gt;Die 16 Listen-IPs (89.248.167.x, IP Volume inc) tragen PTR &lt;span class="mono"&gt;netsecscan.net&lt;/span&gt;:&lt;/p&gt;
&lt;pre tabindex="0"&gt;&lt;code&gt;16 IPs → 14 mit PTR netsecscan.net (nur die kommen rein)
&lt;/code&gt;&lt;/pre&gt;&lt;p&gt;Keine Hochrechnung.&lt;/p&gt;
&lt;h2 id="quellen"&gt;Quellen&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="http://www.netsecscan.net/" target="_blank" rel="noopener"&gt;netsecscan.net&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/Connie-Wild/scanner-ip-list" target="_blank" rel="noopener"&gt;Connie-Wild — scanner-ip-list (GitHub)&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;p style="margin-top: 40px;"&gt;&lt;a href="https://www.parc-network.de/parc-security/" class="btn btn-secondary"&gt;← Zurück zu PARC Security&lt;/a&gt; &amp;nbsp; &lt;a href="https://www.parc-network.de/#kontakt" class="btn btn-primary"&gt;Kontakt aufnehmen&lt;/a&gt;&lt;/p&gt;</description></item><item><title>Nexi — offizielle IP-Ranges (Webhook/Notifications)</title><link>https://www.parc-network.de/nexi/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://www.parc-network.de/nexi/</guid><description>&lt;p class="lead"&gt;&lt;strong&gt;Nexi&lt;/strong&gt; (IT) ist ein Zahlungsanbieter. Dies sind die &lt;strong&gt;offiziellen IP-Ranges&lt;/strong&gt;, unter denen Nexis Webhook-/Notification-Server senden — aus der offiziellen Quelle zu PARC-Feed normalisiert (16 Einträge). Teil unseres &lt;a href="https://www.parc-network.de/parc-security/"&gt;PARC-Security-Feeds&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;&lt;a href="https://www.parc-network.de/feeds/nexi.json" target="_blank" rel="noopener" class="btn btn-secondary"&gt;nexi.json — Feed ansehen&lt;/a&gt; &amp;nbsp; &lt;a href="https://www.nexigroup.com/" target="_blank" rel="noopener"&gt;www.nexigroup.com →&lt;/a&gt;&lt;/p&gt;
&lt;h2 id="quelle--aktualisierung"&gt;Quelle &amp;amp; Aktualisierung&lt;/h2&gt;
&lt;p&gt;Quelle: &lt;span class="mono"&gt;ip-ranges.nex.io/ip-ranges.json&lt;/span&gt; — offiziell publiziert. Die Liste wird von einem maschinenlesbaren Endpoint nachgezogen. Nexi kann die Ranges ändern; der PARC-Feed bildet den offiziellen Stand ab. Reine IP-Daten ohne Wertung.&lt;/p&gt;
&lt;h2 id="quellen"&gt;Quellen&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://www.nexigroup.com/" target="_blank" rel="noopener"&gt;Nexi&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://ip-ranges.nex.io/ip-ranges.json" target="_blank" rel="noopener"&gt;Offizielle IP-Quelle&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;p style="margin-top: 40px;"&gt;&lt;a href="https://www.parc-network.de/parc-security/" class="btn btn-secondary"&gt;← Zurück zu PARC Security&lt;/a&gt; &amp;nbsp; &lt;a href="https://www.parc-network.de/#kontakt" class="btn btn-primary"&gt;Kontakt aufnehmen&lt;/a&gt;&lt;/p&gt;</description></item><item><title>Nokia Deepfield (Cloud Genome) — der verifizierte Scanner-Block und wie wir ihn per FCrDNS belegt haben</title><link>https://www.parc-network.de/deepfield/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://www.parc-network.de/deepfield/</guid><description>&lt;p class="lead"&gt;Deepfield ist Nokias internet-weiter Mess- und Mapping-Scanner (&lt;strong&gt;Cloud Genome&lt;/strong&gt;). Er crawlt fortlaufend Milliarden IPv4- und IPv6-Adressen, CDN-Domains und Netzsysteme, um eine „Service-Delivery-Map" des Internets zu bauen. &lt;strong&gt;Kein SEO-Tool, kein Content-Crawler im klassischen Sinn.&lt;/strong&gt; Nokia publiziert &lt;strong&gt;keine offizielle IP-Liste&lt;/strong&gt; — wir haben die aktiven Scanner-Blöcke deshalb vollständig per &lt;strong&gt;bidirektionalem FCrDNS&lt;/strong&gt; gegen &lt;span class="mono"&gt;*.deepfield.net&lt;/span&gt; verifiziert. Teil unseres &lt;a href="https://www.parc-network.de/parc-security/"&gt;PARC-Security-Feeds&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;&lt;a href="https://www.parc-network.de/feeds/deepfield.json" target="_blank" rel="noopener" class="btn btn-secondary"&gt;deepfield.json — Feed ansehen&lt;/a&gt; &amp;nbsp; &lt;a href="https://www.nokia.com/ip-networks/deepfield/genome/" target="_blank" rel="noopener"&gt;Nokia — Deepfield Genome →&lt;/a&gt;&lt;/p&gt;
&lt;h2 id="die-blöcke"&gt;Die Blöcke&lt;/h2&gt;
&lt;p&gt;&lt;strong&gt;280 IPv4 + 31 IPv6 = 311 Adressen&lt;/strong&gt;, verteilt auf zwei Infrastrukturen:&lt;/p&gt;</description></item><item><title>Nuvei — offizielle IP-Ranges (Webhook/Notifications)</title><link>https://www.parc-network.de/nuvei/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://www.parc-network.de/nuvei/</guid><description>&lt;p class="lead"&gt;&lt;strong&gt;Nuvei&lt;/strong&gt; (CA/IL) ist ein Zahlungsanbieter. Dies sind die &lt;strong&gt;offiziellen IP-Ranges&lt;/strong&gt;, unter denen Nuveis Webhook-/Notification-Server senden — aus der offiziellen Quelle zu PARC-Feed normalisiert (7 Einträge). Teil unseres &lt;a href="https://www.parc-network.de/parc-security/"&gt;PARC-Security-Feeds&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;&lt;a href="https://www.parc-network.de/feeds/nuvei.json" target="_blank" rel="noopener" class="btn btn-secondary"&gt;nuvei.json — Feed ansehen&lt;/a&gt; &amp;nbsp; &lt;a href="https://www.nuvei.com/" target="_blank" rel="noopener"&gt;www.nuvei.com →&lt;/a&gt;&lt;/p&gt;
&lt;h2 id="quelle--aktualisierung"&gt;Quelle &amp;amp; Aktualisierung&lt;/h2&gt;
&lt;p&gt;Quelle: &lt;span class="mono"&gt;Nuvei-Doku (DMN/Webhooks)&lt;/span&gt; — offiziell publiziert. Aus der Anbieter-Doku übernommen. Nuvei kann die Ranges ändern; der PARC-Feed bildet den offiziellen Stand ab. Reine IP-Daten ohne Wertung.&lt;/p&gt;
&lt;h2 id="quellen"&gt;Quellen&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://www.nuvei.com/" target="_blank" rel="noopener"&gt;Nuvei&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://docs.nuvei.com/documentation/integration/webhooks/" target="_blank" rel="noopener"&gt;Offizielle IP-Quelle&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;p style="margin-top: 40px;"&gt;&lt;a href="https://www.parc-network.de/parc-security/" class="btn btn-secondary"&gt;← Zurück zu PARC Security&lt;/a&gt; &amp;nbsp; &lt;a href="https://www.parc-network.de/#kontakt" class="btn btn-primary"&gt;Kontakt aufnehmen&lt;/a&gt;&lt;/p&gt;</description></item><item><title>OnlyScans — per-IP self-ID via onlyscans.net</title><link>https://www.parc-network.de/onlyscans/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://www.parc-network.de/onlyscans/</guid><description>&lt;p class="lead"&gt;internet-weiter &lt;strong&gt;Scanner&lt;/strong&gt; (OnlyScans). Kein SEO-Tool. Die Scan-IPs sind &lt;strong&gt;self-identifizierend&lt;/strong&gt;: Reverse-DNS &lt;span class="mono"&gt;*.scanners.onlyscans.net&lt;/span&gt;. Entdeckt im &lt;a href="https://www.parc-network.de/cins/"&gt;CINS-Abgleich&lt;/a&gt; und per Nachbar-Range-Scan vervollständigt — jede IP einzeln reverse-bestätigt (8). Teil unseres &lt;a href="https://www.parc-network.de/parc-security/"&gt;PARC-Security-Feeds&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;&lt;a href="https://www.parc-network.de/feeds/onlyscans.json" target="_blank" rel="noopener" class="btn btn-secondary"&gt;onlyscans.json — Feed ansehen&lt;/a&gt; &amp;nbsp; &lt;a href="https://onlyscans.net/" target="_blank" rel="noopener"&gt;onlyscans.net →&lt;/a&gt;&lt;/p&gt;
&lt;h2 id="verifikation--jede-ip-einzeln"&gt;Verifikation — jede IP einzeln&lt;/h2&gt;
&lt;p&gt;Den Reverse-PTR &lt;span class="mono"&gt;*.scanners.onlyscans.net&lt;/span&gt; kann nur der IP-Betreiber setzen — ein nicht-fälschbarer Eigentums-Hinweis. Seed aus den &lt;strong&gt;aktiv scannenden CINS-IPs&lt;/strong&gt;, per Reverse-Scan der umliegenden /24 vervollständigt; jede IP einzeln bestätigt:&lt;/p&gt;
&lt;pre tabindex="0"&gt;&lt;code&gt;8 IPs → alle PTR onlyscans.net
&lt;/code&gt;&lt;/pre&gt;&lt;p&gt;Reverse-only (Forward nicht durchgängig prüfbar, wie bei Shodan/Infrawatch). AbuseIPDB führt diese IPs teils mit Score 100 — es sind dennoch benigne Research-Scanner.&lt;/p&gt;</description></item><item><title>ONYPHE — der verifizierte Scanner-Block und warum die offizielle Liste nicht reicht</title><link>https://www.parc-network.de/onyphe/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://www.parc-network.de/onyphe/</guid><description>&lt;p class="lead"&gt;ONYPHE ist ein internet-weiter &lt;strong&gt;Attack-Surface- und CTI-Scanner&lt;/strong&gt; aus Frankreich (seit 2017) — scannt Internet und Dark Web nach exponierten Assets. &lt;strong&gt;Kein SEO-Tool.&lt;/strong&gt; ONYPHE handelt vorbildlich („Ethical Internet Scanning"): feste IPs, Reverse-DNS auf das eigene Projekt, Opt-out per E-Mail. Sie publizieren sogar eine &lt;strong&gt;offizielle Liste&lt;/strong&gt; — die aber, wie wir festgestellt haben, &lt;strong&gt;nicht den gesamten aktiven Probe-Bestand abdeckt&lt;/strong&gt;. Den Rest haben wir per &lt;strong&gt;bidirektionalem FCrDNS&lt;/strong&gt; gegen &lt;span class="mono"&gt;*.probe.onyphe.net&lt;/span&gt; belegt. Teil unseres &lt;a href="https://www.parc-network.de/parc-security/"&gt;PARC-Security-Feeds&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;&lt;a href="https://www.parc-network.de/feeds/onyphe.json" target="_blank" rel="noopener" class="btn btn-secondary"&gt;onyphe.json — Feed ansehen&lt;/a&gt; &amp;nbsp; &lt;a href="https://www.onyphe.io/ip-ranges.txt" target="_blank" rel="noopener"&gt;ONYPHE — offizielle Liste →&lt;/a&gt;&lt;/p&gt;</description></item><item><title>Open Port Statistics — per-IP self-ID via openportstats.com</title><link>https://www.parc-network.de/openportstats/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://www.parc-network.de/openportstats/</guid><description>&lt;p class="lead"&gt;&lt;strong&gt;Open Port Statistics&lt;/strong&gt; betreibt einen internet-weiten &lt;strong&gt;Port-Scan-Dienst&lt;/strong&gt;. Kein SEO-Tool. Die Scan-IPs sind &lt;strong&gt;self-identifizierend&lt;/strong&gt;: PTR auf &lt;span class="mono"&gt;openportstats.com&lt;/span&gt;. Jede IP einzeln reverse-geprüft. Teil unseres &lt;a href="https://www.parc-network.de/parc-security/"&gt;PARC-Security-Feeds&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;&lt;a href="https://www.parc-network.de/feeds/openportstats.json" target="_blank" rel="noopener" class="btn btn-secondary"&gt;openportstats.json — Feed ansehen&lt;/a&gt; &amp;nbsp; &lt;a href="http://openportstats.com/" target="_blank" rel="noopener"&gt;openportstats.com →&lt;/a&gt;&lt;/p&gt;
&lt;h2 id="verifikation--jede-ip-einzeln"&gt;Verifikation — jede IP einzeln&lt;/h2&gt;
&lt;p&gt;Die 144 Listen-IPs (u.a. 185.216.140.x) tragen überwiegend PTR &lt;span class="mono"&gt;openportstats.com&lt;/span&gt; — nur die nehmen wir:&lt;/p&gt;
&lt;pre tabindex="0"&gt;&lt;code&gt;144 IPs → 132 mit PTR openportstats.com (nur die kommen rein)
&lt;/code&gt;&lt;/pre&gt;&lt;p&gt;Keine Hochrechnung.&lt;/p&gt;
&lt;h2 id="quellen"&gt;Quellen&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="http://openportstats.com/" target="_blank" rel="noopener"&gt;Open Port Statistics&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/Connie-Wild/scanner-ip-list" target="_blank" rel="noopener"&gt;Connie-Wild — scanner-ip-list (GitHub)&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;p style="margin-top: 40px;"&gt;&lt;a href="https://www.parc-network.de/parc-security/" class="btn btn-secondary"&gt;← Zurück zu PARC Security&lt;/a&gt; &amp;nbsp; &lt;a href="https://www.parc-network.de/#kontakt" class="btn btn-primary"&gt;Kontakt aufnehmen&lt;/a&gt;&lt;/p&gt;</description></item><item><title>OPNsense Firewall für deine Magento Shop-Infrastruktur</title><link>https://www.parc-network.de/magento-firewall/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://www.parc-network.de/magento-firewall/</guid><description>&lt;figure class="diagram"&gt;
&lt;div class="svg-scroll"&gt;&lt;svg viewBox="0 0 1180 386" width="1180" height="386" xmlns="http://www.w3.org/2000/svg"
font-family="system-ui, -apple-system, 'Segoe UI', Roboto, sans-serif"
role="img" aria-label="Vier Zonen mit Ampelbalken: ungefilterter Traffic rot, teilgefiltert gelb nach OPNsense, sicherheitstechnisch gefiltert grün nach SafeLine."&gt;
&lt;defs&gt;
&lt;marker id="arr" viewBox="0 0 10 10" refX="8" refY="5" markerWidth="7" markerHeight="7" orient="auto-start-reverse"&gt;
&lt;path d="M0,0 L10,5 L0,10 z" fill="#b0bac4"/&gt;
&lt;/marker&gt;
&lt;linearGradient id="traffic" x1="0" y1="0" x2="1" y2="0"&gt;
&lt;stop offset="0%" stop-color="#d62828"/&gt;
&lt;stop offset="28%" stop-color="#d62828"/&gt;
&lt;stop offset="31%" stop-color="#e74c3c"/&gt;
&lt;stop offset="51%" stop-color="#e74c3c"/&gt;
&lt;stop offset="55%" stop-color="#f1c40f"/&gt;
&lt;stop offset="73%" stop-color="#f1c40f"/&gt;
&lt;stop offset="77%" stop-color="#27ae60"/&gt;
&lt;stop offset="100%" stop-color="#27ae60"/&gt;
&lt;/linearGradient&gt;
&lt;/defs&gt;
&lt;!-- ===== Zonengrenzen ===== --&gt;
&lt;line x1="156" y1="60" x2="156" y2="330" stroke="#c5cdd6" stroke-width="1.4" stroke-dasharray="3 5"/&gt;
&lt;line x1="409" y1="60" x2="409" y2="330" stroke="#c5cdd6" stroke-width="1.4" stroke-dasharray="3 5"/&gt;
&lt;line x1="918" y1="60" x2="918" y2="330" stroke="#c5cdd6" stroke-width="1.4" stroke-dasharray="3 5"/&gt;
&lt;!-- ===== Zonen-Labels ===== --&gt;
&lt;text x="84" y="30" text-anchor="middle" font-size="11.5" font-weight="700" letter-spacing="1.2" fill="#9aa5b1"&gt;ÖFFENTLICHES&lt;tspan x="84" dy="15"&gt;NETZ&lt;/tspan&gt;&lt;/text&gt;
&lt;text x="276" y="30" text-anchor="middle" font-size="11.5" font-weight="700" letter-spacing="1.2" fill="#9aa5b1"&gt;HOSTER&lt;/text&gt;
&lt;text x="663" y="30" text-anchor="middle" font-size="11.5" font-weight="700" letter-spacing="1.2" fill="#9aa5b1"&gt;SICHERHEITSSCHICHT · DEINE INFRASTRUKTUR&lt;/text&gt;
&lt;text x="1049" y="30" text-anchor="middle" font-size="11.5" font-weight="700" letter-spacing="1.2" fill="#9aa5b1"&gt;WEITERE&lt;tspan x="1049" dy="15"&gt;SCHICHTEN&lt;/tspan&gt;&lt;/text&gt;
&lt;!-- ===== Internet (Kugel auf Box-Höhe) ===== --&gt;
&lt;g transform="translate(88,156)"&gt;
&lt;circle r="52" fill="#eef1f4" stroke="#cdd5de" stroke-width="1.5"/&gt;
&lt;circle r="52" fill="none" stroke="#8a96a3" stroke-width="1.3"/&gt;
&lt;ellipse rx="20" ry="52" fill="none" stroke="#8a96a3" stroke-width="1.3"/&gt;
&lt;ellipse rx="52" ry="20" fill="none" stroke="#8a96a3" stroke-width="1.3"/&gt;
&lt;line x1="-52" y1="0" x2="52" y2="0" stroke="#8a96a3" stroke-width="1.3"/&gt;
&lt;/g&gt;
&lt;text x="88" y="232" text-anchor="middle" font-size="15" font-weight="700" fill="#3b4754"&gt;Internet&lt;/text&gt;
&lt;text x="88" y="250" text-anchor="middle" font-size="11" fill="#9aa5b1"&gt;Kunden · Bots · Angriffe&lt;/text&gt;
&lt;!-- ===== Pfeile + Boxen (alle 166 x 104, Mitte y=156) ===== --&gt;
&lt;line x1="144" y1="156" x2="189" y2="156" stroke="#b0bac4" stroke-width="2.4" marker-end="url(#arr)"/&gt;
&lt;rect x="193" y="104" width="166" height="104" rx="12" fill="#ffffff" stroke="#cdd5de" stroke-width="1.8"/&gt;
&lt;text x="276" y="138" text-anchor="middle" font-size="16" font-weight="800" fill="#3b4754"&gt;Hoster-Firewall&lt;/text&gt;
&lt;text x="276" y="159" text-anchor="middle" font-size="11.5" fill="#9aa5b1"&gt;Hetzner · IONOS · …&lt;/text&gt;
&lt;rect x="200" y="174" width="152" height="24" rx="12" fill="#eef1f4" stroke="#cdd5de" stroke-width="1"/&gt;
&lt;text x="276" y="190" text-anchor="middle" font-size="9.5" font-weight="700" fill="#6b7682" letter-spacing="0.3"&gt;VOLUMETRISCHE DDoS&lt;/text&gt;
&lt;line x1="361" y1="156" x2="452" y2="156" stroke="#b0bac4" stroke-width="2.4" marker-end="url(#arr)"/&gt;
&lt;rect x="456" y="104" width="166" height="104" rx="12" fill="#fff5f5" stroke="#d23b3b" stroke-width="2.6"/&gt;
&lt;text x="539" y="138" text-anchor="middle" font-size="19" font-weight="800" fill="#c0202a"&gt;OPNsense&lt;/text&gt;
&lt;text x="539" y="159" text-anchor="middle" font-size="13" fill="#7a4a4a"&gt;Firewall&lt;/text&gt;
&lt;rect x="487" y="174" width="104" height="24" rx="12" fill="#d23b3b"/&gt;
&lt;text x="539" y="190" text-anchor="middle" font-size="11.5" font-weight="700" fill="#ffffff"&gt;LAYER 3 – 4&lt;/text&gt;
&lt;line x1="624" y1="156" x2="694" y2="156" stroke="#b0bac4" stroke-width="2.4" marker-end="url(#arr)"/&gt;
&lt;rect x="698" y="104" width="166" height="104" rx="12" fill="#ffffff" stroke="#cdd5de" stroke-width="1.8"/&gt;
&lt;text x="781" y="134" text-anchor="middle" font-size="19" font-weight="800" fill="#3b4754"&gt;SafeLine&lt;/text&gt;
&lt;text x="781" y="152" text-anchor="middle" font-size="11" fill="#9aa5b1"&gt;Reverse Proxy&lt;/text&gt;
&lt;text x="781" y="166" text-anchor="middle" font-size="11" fill="#9aa5b1"&gt;Bot Det. &amp;amp; WAF&lt;/text&gt;
&lt;rect x="713" y="174" width="136" height="24" rx="12" fill="#eef1f4" stroke="#cdd5de" stroke-width="1"/&gt;
&lt;text x="781" y="190" text-anchor="middle" font-size="11.5" font-weight="700" fill="#6b7682"&gt;LAYER 5 – 7&lt;/text&gt;
&lt;!-- ===== PARC Security ===== --&gt;
&lt;rect x="560" y="244" width="200" height="56" rx="12" fill="#fafbfc" stroke="#cdd5de" stroke-width="1.6" stroke-dasharray="6 4"/&gt;
&lt;text x="660" y="270" text-anchor="middle" font-size="15" font-weight="800" fill="#3b4754"&gt;PARC Security&lt;/text&gt;
&lt;text x="660" y="288" text-anchor="middle" font-size="11" fill="#9aa5b1"&gt;Blacklists · IP-Gruppen · Regeln&lt;/text&gt;
&lt;line x1="612" y1="244" x2="556" y2="210" stroke="#b0bac4" stroke-width="1.5" stroke-dasharray="5 4" marker-end="url(#arr)"/&gt;
&lt;line x1="708" y1="244" x2="764" y2="210" stroke="#b0bac4" stroke-width="1.5" stroke-dasharray="5 4" marker-end="url(#arr)"/&gt;
&lt;!-- ===== Ausgang -&gt; weitere Schichten ===== --&gt;
&lt;line x1="868" y1="156" x2="960" y2="156" stroke="#b0bac4" stroke-width="2.4" marker-end="url(#arr)"/&gt;
&lt;rect x="966" y="104" width="166" height="30" rx="6" fill="#fafbfc" stroke="#cdd5de" stroke-width="1.6"/&gt;
&lt;text x="1049" y="124" text-anchor="middle" font-size="12.5" font-weight="600" fill="#6b7682"&gt;Cache&lt;/text&gt;
&lt;rect x="966" y="141" width="166" height="30" rx="6" fill="#fafbfc" stroke="#cdd5de" stroke-width="1.6"/&gt;
&lt;text x="1049" y="161" text-anchor="middle" font-size="12.5" font-weight="600" fill="#6b7682"&gt;App&lt;/text&gt;
&lt;rect x="966" y="178" width="166" height="30" rx="6" fill="#fafbfc" stroke="#cdd5de" stroke-width="1.6"/&gt;
&lt;text x="1049" y="198" text-anchor="middle" font-size="12.5" font-weight="600" fill="#6b7682"&gt;Data&lt;/text&gt;
&lt;!-- ===== Traffic-Ampelbalken mit Text drin ===== --&gt;
&lt;rect x="40" y="344" width="1100" height="26" rx="7" fill="url(#traffic)"/&gt;
&lt;text x="331" y="361" text-anchor="middle" font-size="11.5" font-weight="700" fill="#ffffff"&gt;ungefilterter Traffic&lt;/text&gt;
&lt;text x="743" y="361" text-anchor="middle" font-size="10.5" font-weight="700" fill="#4a3a00"&gt;teilgefiltert (L3–4)&lt;/text&gt;
&lt;text x="1002" y="361" text-anchor="middle" font-size="10.5" font-weight="700" fill="#ffffff"&gt;sicherheitstechnisch gefiltert&lt;/text&gt;
&lt;/svg&gt;&lt;/div&gt;
&lt;figcaption class="muted"&gt;
Stufenweise Filterung als Ampel: ungefilterter Traffic (rot) trifft zuerst auf die
Hoster-Firewall, die nur volumetrische Angriffe absiebt — danach bleibt er fast so rot.
Erst OPNsense entfernt auf Layer 3–4 böse IPs, Ports und ungewollte Verbindungen (gelb).
Die Prüfung auf Anwendungsebene und die finale Freigabe (grün) übernimmt die
SafeLine WAF.
&lt;/figcaption&gt;
&lt;/figure&gt;
&lt;nav class="toc" aria-label="Inhaltsverzeichnis"&gt;
&lt;strong&gt;Auf dieser Seite&lt;/strong&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="#warum-firewall"&gt;1. Warum überhaupt eine Netzwerk-Firewall?&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#hoster"&gt;2. Warum filtert das nicht der Hoster?&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#ip-listen"&gt;3. Gute und böse IPs&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#netztrennung"&gt;4. Klare Grenzen — außen, innen, dazwischen&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#warum-opnsense"&gt;5. Warum genau OPNsense?&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#dimensionierung"&gt;6. Richtig dimensioniert&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;/nav&gt;
&lt;h2 id="warum-firewall"&gt;1. Warum überhaupt eine Netzwerk-Firewall?&lt;/h2&gt;
&lt;p class="lead"&gt;Um zu verstehen, warum deine Magento-Infrastruktur eine Netzwerk-Firewall
wie &lt;a href="https://opnsense.org" target="_blank" rel="noopener"&gt;OPNsense&lt;/a&gt; braucht, lohnt sich zuerst ein Blick auf das, was den ganzen Tag an deinem
Shop anklopft: den Internet-Traffic.&lt;/p&gt;</description></item><item><title>PARC Security — verifizierte und normalisierte IP-Feeds für deine Magento Hosting-Infrastruktur</title><link>https://www.parc-network.de/parc-security/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://www.parc-network.de/parc-security/</guid><description>&lt;figure class="diagram"&gt;
&lt;div class="svg-scroll"&gt;&lt;svg viewBox="0 0 1180 386" width="1180" height="386" xmlns="http://www.w3.org/2000/svg"
font-family="system-ui, -apple-system, 'Segoe UI', Roboto, sans-serif"
role="img" aria-label="PARC Security versorgt OPNsense und SafeLine mit verifizierten, normalisierten IP-Listen. Stufenweise Filterung von rot (ungefiltert) bis grün (sicherheitstechnisch gefiltert)."&gt;
&lt;defs&gt;
&lt;marker id="arr" viewBox="0 0 10 10" refX="8" refY="5" markerWidth="7" markerHeight="7" orient="auto-start-reverse"&gt;
&lt;path d="M0,0 L10,5 L0,10 z" fill="#b0bac4"/&gt;
&lt;/marker&gt;
&lt;linearGradient id="traffic" x1="0" y1="0" x2="1" y2="0"&gt;
&lt;stop offset="0%" stop-color="#d62828"/&gt;
&lt;stop offset="28%" stop-color="#d62828"/&gt;
&lt;stop offset="31%" stop-color="#e74c3c"/&gt;
&lt;stop offset="51%" stop-color="#e74c3c"/&gt;
&lt;stop offset="55%" stop-color="#f1c40f"/&gt;
&lt;stop offset="73%" stop-color="#f1c40f"/&gt;
&lt;stop offset="77%" stop-color="#27ae60"/&gt;
&lt;stop offset="100%" stop-color="#27ae60"/&gt;
&lt;/linearGradient&gt;
&lt;/defs&gt;
&lt;!-- ===== Zonengrenzen ===== --&gt;
&lt;line x1="156" y1="60" x2="156" y2="330" stroke="#c5cdd6" stroke-width="1.4" stroke-dasharray="3 5"/&gt;
&lt;line x1="409" y1="60" x2="409" y2="330" stroke="#c5cdd6" stroke-width="1.4" stroke-dasharray="3 5"/&gt;
&lt;line x1="918" y1="60" x2="918" y2="330" stroke="#c5cdd6" stroke-width="1.4" stroke-dasharray="3 5"/&gt;
&lt;!-- ===== Zonen-Labels ===== --&gt;
&lt;text x="84" y="30" text-anchor="middle" font-size="11.5" font-weight="700" letter-spacing="1.2" fill="#9aa5b1"&gt;ÖFFENTLICHES&lt;tspan x="84" dy="15"&gt;NETZ&lt;/tspan&gt;&lt;/text&gt;
&lt;text x="276" y="30" text-anchor="middle" font-size="11.5" font-weight="700" letter-spacing="1.2" fill="#9aa5b1"&gt;HOSTER&lt;/text&gt;
&lt;text x="663" y="30" text-anchor="middle" font-size="11.5" font-weight="700" letter-spacing="1.2" fill="#9aa5b1"&gt;SICHERHEITSSCHICHT · DEINE INFRASTRUKTUR&lt;/text&gt;
&lt;text x="1049" y="30" text-anchor="middle" font-size="11.5" font-weight="700" letter-spacing="1.2" fill="#9aa5b1"&gt;WEITERE&lt;tspan x="1049" dy="15"&gt;SCHICHTEN&lt;/tspan&gt;&lt;/text&gt;
&lt;!-- ===== Internet (Kugel auf Box-Höhe) ===== --&gt;
&lt;g transform="translate(88,156)"&gt;
&lt;circle r="52" fill="#eef1f4" stroke="#cdd5de" stroke-width="1.5"/&gt;
&lt;circle r="52" fill="none" stroke="#8a96a3" stroke-width="1.3"/&gt;
&lt;ellipse rx="20" ry="52" fill="none" stroke="#8a96a3" stroke-width="1.3"/&gt;
&lt;ellipse rx="52" ry="20" fill="none" stroke="#8a96a3" stroke-width="1.3"/&gt;
&lt;line x1="-52" y1="0" x2="52" y2="0" stroke="#8a96a3" stroke-width="1.3"/&gt;
&lt;/g&gt;
&lt;text x="88" y="232" text-anchor="middle" font-size="15" font-weight="700" fill="#3b4754"&gt;Internet&lt;/text&gt;
&lt;text x="88" y="250" text-anchor="middle" font-size="11" fill="#9aa5b1"&gt;Kunden · Bots · Angriffe&lt;/text&gt;
&lt;!-- ===== Pfeile + Boxen (alle 166 x 104, Mitte y=156) ===== --&gt;
&lt;line x1="144" y1="156" x2="189" y2="156" stroke="#b0bac4" stroke-width="2.4" marker-end="url(#arr)"/&gt;
&lt;rect x="193" y="104" width="166" height="104" rx="12" fill="#ffffff" stroke="#cdd5de" stroke-width="1.8"/&gt;
&lt;text x="276" y="138" text-anchor="middle" font-size="16" font-weight="800" fill="#3b4754"&gt;Hoster-Firewall&lt;/text&gt;
&lt;text x="276" y="159" text-anchor="middle" font-size="11.5" fill="#9aa5b1"&gt;Hetzner · IONOS · …&lt;/text&gt;
&lt;rect x="200" y="174" width="152" height="24" rx="12" fill="#eef1f4" stroke="#cdd5de" stroke-width="1"/&gt;
&lt;text x="276" y="190" text-anchor="middle" font-size="9.5" font-weight="700" fill="#6b7682" letter-spacing="0.3"&gt;VOLUMETRISCHE DDoS&lt;/text&gt;
&lt;line x1="361" y1="156" x2="452" y2="156" stroke="#b0bac4" stroke-width="2.4" marker-end="url(#arr)"/&gt;
&lt;rect x="456" y="104" width="166" height="104" rx="12" fill="#ffffff" stroke="#cdd5de" stroke-width="1.8"/&gt;
&lt;text x="539" y="138" text-anchor="middle" font-size="19" font-weight="800" fill="#3b4754"&gt;OPNsense&lt;/text&gt;
&lt;text x="539" y="159" text-anchor="middle" font-size="13" fill="#9aa5b1"&gt;Firewall&lt;/text&gt;
&lt;rect x="487" y="174" width="104" height="24" rx="12" fill="#eef1f4" stroke="#cdd5de" stroke-width="1"/&gt;
&lt;text x="539" y="190" text-anchor="middle" font-size="11.5" font-weight="700" fill="#6b7682"&gt;LAYER 3 – 4&lt;/text&gt;
&lt;line x1="624" y1="156" x2="694" y2="156" stroke="#b0bac4" stroke-width="2.4" marker-end="url(#arr)"/&gt;
&lt;rect x="698" y="104" width="166" height="104" rx="12" fill="#ffffff" stroke="#cdd5de" stroke-width="1.8"/&gt;
&lt;text x="781" y="134" text-anchor="middle" font-size="19" font-weight="800" fill="#3b4754"&gt;SafeLine&lt;/text&gt;
&lt;text x="781" y="152" text-anchor="middle" font-size="11" fill="#9aa5b1"&gt;Reverse Proxy&lt;/text&gt;
&lt;text x="781" y="166" text-anchor="middle" font-size="11" fill="#9aa5b1"&gt;Bot Det. &amp;amp; WAF&lt;/text&gt;
&lt;rect x="713" y="174" width="136" height="24" rx="12" fill="#eef1f4" stroke="#cdd5de" stroke-width="1"/&gt;
&lt;text x="781" y="190" text-anchor="middle" font-size="11.5" font-weight="700" fill="#6b7682"&gt;LAYER 5 – 7&lt;/text&gt;
&lt;!-- ===== PARC Security ===== --&gt;
&lt;rect x="560" y="244" width="200" height="56" rx="12" fill="#fff5f5" stroke="#d23b3b" stroke-width="2.6" stroke-dasharray="6 4"/&gt;
&lt;text x="660" y="270" text-anchor="middle" font-size="15" font-weight="800" fill="#c0202a"&gt;PARC Security&lt;/text&gt;
&lt;text x="660" y="288" text-anchor="middle" font-size="11" fill="#7a4a4a"&gt;Blacklists · IP-Gruppen · Regeln&lt;/text&gt;
&lt;line x1="612" y1="244" x2="556" y2="210" stroke="#b0bac4" stroke-width="1.5" stroke-dasharray="5 4" marker-end="url(#arr)"/&gt;
&lt;line x1="708" y1="244" x2="764" y2="210" stroke="#b0bac4" stroke-width="1.5" stroke-dasharray="5 4" marker-end="url(#arr)"/&gt;
&lt;!-- ===== Ausgang -&gt; weitere Schichten ===== --&gt;
&lt;line x1="868" y1="156" x2="960" y2="156" stroke="#b0bac4" stroke-width="2.4" marker-end="url(#arr)"/&gt;
&lt;rect x="966" y="104" width="166" height="30" rx="6" fill="#fafbfc" stroke="#cdd5de" stroke-width="1.6"/&gt;
&lt;text x="1049" y="124" text-anchor="middle" font-size="12.5" font-weight="600" fill="#6b7682"&gt;Cache&lt;/text&gt;
&lt;rect x="966" y="141" width="166" height="30" rx="6" fill="#fafbfc" stroke="#cdd5de" stroke-width="1.6"/&gt;
&lt;text x="1049" y="161" text-anchor="middle" font-size="12.5" font-weight="600" fill="#6b7682"&gt;App&lt;/text&gt;
&lt;rect x="966" y="178" width="166" height="30" rx="6" fill="#fafbfc" stroke="#cdd5de" stroke-width="1.6"/&gt;
&lt;text x="1049" y="198" text-anchor="middle" font-size="12.5" font-weight="600" fill="#6b7682"&gt;Data&lt;/text&gt;
&lt;!-- ===== Traffic-Ampelbalken mit Text drin ===== --&gt;
&lt;rect x="40" y="344" width="1100" height="26" rx="7" fill="url(#traffic)"/&gt;
&lt;text x="331" y="361" text-anchor="middle" font-size="11.5" font-weight="700" fill="#ffffff"&gt;ungefilterter Traffic&lt;/text&gt;
&lt;text x="743" y="361" text-anchor="middle" font-size="10.5" font-weight="700" fill="#4a3a00"&gt;teilgefiltert (L3–4)&lt;/text&gt;
&lt;text x="1002" y="361" text-anchor="middle" font-size="10.5" font-weight="700" fill="#ffffff"&gt;sicherheitstechnisch gefiltert&lt;/text&gt;
&lt;/svg&gt;&lt;/div&gt;
&lt;figcaption class="muted"&gt;
&lt;strong&gt;PARC Security&lt;/strong&gt; versorgt sowohl &lt;a href="https://www.parc-network.de/magento-firewall/"&gt;OPNsense&lt;/a&gt; (Layer 3–4) als auch
SafeLine WAF (Layer 5–7) mit verifizierten, normalisierten IP-Listen —
kuratiert nach Anbieter, IPv4 und IPv6 zusammen, täglich revalidiert.
&lt;/figcaption&gt;
&lt;/figure&gt;
&lt;h2 id="für-unsere-magento-architektur-und-viele-weitere-plattformen--kostenlos-für-die-community"&gt;Für unsere Magento-Architektur und viele weitere Plattformen — kostenlos für die Community&lt;/h2&gt;
&lt;p&gt;Die IP-Feeds sind &lt;strong&gt;plattform-unabhängig&lt;/strong&gt;. Du kannst sie überall einsetzen — vor einem Magento-Shop ebenso wie vor Shopware, WooCommerce, Joomla, WordPress, Foren oder beliebiger anderer Web-Software, auf einer &lt;a href="https://www.parc-network.de/magento-firewall/"&gt;OPNsense&lt;/a&gt; oder pfSense, in der SafeLine WAF oder einer anderen Web Application Firewall. Wann immer du auf Firewall-, WAF- oder Reverse-Proxy-Ebene Crawler-, Bot- oder Bedrohungs-Verkehr steuern willst, kannst du diese Listen dafür verwenden.&lt;/p&gt;</description></item><item><title>PAYONE — offizielle IP-Ranges (Notifications)</title><link>https://www.parc-network.de/payone/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://www.parc-network.de/payone/</guid><description>&lt;p class="lead"&gt;&lt;strong&gt;PAYONE&lt;/strong&gt; (DE — Joint Venture von Worldline und der Sparkassen-Finanzgruppe) ist ein Zahlungsanbieter. Dies sind die &lt;strong&gt;offiziellen IP-Ranges&lt;/strong&gt;, aus denen PAYONE die &lt;strong&gt;Server-to-Server-Notifications&lt;/strong&gt; (TransactionStatus) an Händlersysteme sendet — aus der offiziellen Firewall-Doku zu PARC-Feed normalisiert (4 CIDRs). Teil unseres &lt;a href="https://www.parc-network.de/parc-security/"&gt;PARC-Security-Feeds&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;&lt;a href="https://www.parc-network.de/feeds/payone.json" target="_blank" rel="noopener" class="btn btn-secondary"&gt;payone.json — Feed ansehen&lt;/a&gt; &amp;nbsp; &lt;a href="https://www.payone.com/" target="_blank" rel="noopener"&gt;payone.com →&lt;/a&gt;&lt;/p&gt;
&lt;h2 id="quelle--aktualisierung"&gt;Quelle &amp;amp; Aktualisierung&lt;/h2&gt;
&lt;p&gt;Quelle: &lt;span class="mono"&gt;developer.payone.com — Firewall configuration&lt;/span&gt;, offiziell publiziert. 4 CIDR-Blöcke (185.139.244.0/24, 185.139.246.0/24, 91.208.214.0/24, 185.8.55.0/24). PAYONE kann die Ranges ändern; der PARC-Feed bildet den offiziellen Stand ab. Reine IP-Daten ohne Wertung.&lt;/p&gt;</description></item><item><title>PayPal — offizielle IP-Ranges (Webhook/API)</title><link>https://www.parc-network.de/paypal/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://www.parc-network.de/paypal/</guid><description>&lt;p class="lead"&gt;&lt;strong&gt;PayPal&lt;/strong&gt; (US) ist ein Zahlungsanbieter. Dies sind die &lt;strong&gt;offiziellen IP-Ranges&lt;/strong&gt;, unter denen PayPals Webhook-/API-Server senden bzw. erreichbar sind — aus der offiziellen Quelle zu PARC-Feed normalisiert (8 Einträge). Teil unseres &lt;a href="https://www.parc-network.de/parc-security/"&gt;PARC-Security-Feeds&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;&lt;a href="https://www.parc-network.de/feeds/paypal.json" target="_blank" rel="noopener" class="btn btn-secondary"&gt;paypal.json — Feed ansehen&lt;/a&gt; &amp;nbsp; &lt;a href="https://www.paypal.com/" target="_blank" rel="noopener"&gt;www.paypal.com →&lt;/a&gt;&lt;/p&gt;
&lt;h2 id="quelle--aktualisierung"&gt;Quelle &amp;amp; Aktualisierung&lt;/h2&gt;
&lt;p&gt;Quelle: &lt;span class="mono"&gt;PayPal-Doku (ts1056)&lt;/span&gt; — offiziell publiziert. Aus der Anbieter-Doku übernommen. PayPal kann die Ranges jederzeit ändern; der PARC-Feed bildet den offiziellen Stand ab. Reine IP-Daten ohne Wertung.&lt;/p&gt;
&lt;h2 id="quellen"&gt;Quellen&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://www.paypal.com/" target="_blank" rel="noopener"&gt;PayPal&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://www.paypal.com/us/cshelp/article/what-are-the-internet-protocol-ip-addresses-for-paypal-server-endpoints-ts1056" target="_blank" rel="noopener"&gt;Offizielle IP-Quelle&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;p style="margin-top: 40px;"&gt;&lt;a href="https://www.parc-network.de/parc-security/" class="btn btn-secondary"&gt;← Zurück zu PARC Security&lt;/a&gt; &amp;nbsp; &lt;a href="https://www.parc-network.de/#kontakt" class="btn btn-primary"&gt;Kontakt aufnehmen&lt;/a&gt;&lt;/p&gt;</description></item><item><title>Pentest-Tools.com — offizielle Quell-IP-Liste</title><link>https://www.parc-network.de/pentest-tools/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://www.parc-network.de/pentest-tools/</guid><description>&lt;p class="lead"&gt;&lt;strong&gt;Pentest-Tools.com&lt;/strong&gt; (RO) betreibt einen aktiven &lt;strong&gt;Pentest-/Scanning-Dienst&lt;/strong&gt;. Kein SEO-Tool. Die Scan-IPs sind &lt;strong&gt;offiziell&lt;/strong&gt; auf der Support-Seite gelistet und bündeln sich unter dem eigenen Hostnamen &lt;span class="mono"&gt;scanners.pentest-tools.com&lt;/span&gt;. Teil unseres &lt;a href="https://www.parc-network.de/parc-security/"&gt;PARC-Security-Feeds&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;&lt;a href="https://www.parc-network.de/feeds/pentest-tools.json" target="_blank" rel="noopener" class="btn btn-secondary"&gt;pentest-tools.json — Feed ansehen&lt;/a&gt; &amp;nbsp; &lt;a href="https://pentest-tools.com/" target="_blank" rel="noopener"&gt;pentest-tools.com →&lt;/a&gt;&lt;/p&gt;
&lt;h2 id="verifikation--jede-ip-einzeln"&gt;Verifikation — jede IP einzeln&lt;/h2&gt;
&lt;p&gt;Die 126 IPs stammen aus der &lt;strong&gt;offiziellen Quell-IP-Liste&lt;/strong&gt; und decken sich mit den A-Records von &lt;span class="mono"&gt;scanners.pentest-tools.com&lt;/span&gt;. Alle liegen bei Linode (AS63949) mit generischer &lt;span class="mono"&gt;*.ip.linodeusercontent.com&lt;/span&gt;-PTR — ein FCrDNS-Self-ID ist hier nicht möglich, die Verifikation stützt sich auf die offizielle Liste plus den eigenen Scanner-FQDN.&lt;/p&gt;</description></item><item><title>Ping-Dash — per-IP self-ID via ping-dash.com</title><link>https://www.parc-network.de/ping-dash/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://www.parc-network.de/ping-dash/</guid><description>&lt;p class="lead"&gt;&lt;strong&gt;Monitoring-/Scan-Dienst&lt;/strong&gt; (Ping-Dash). Kein SEO-Tool. Die Scan-IPs sind &lt;strong&gt;self-identifizierend&lt;/strong&gt;: Reverse-DNS &lt;span class="mono"&gt;scanner-*.ping-dash.com&lt;/span&gt;. Entdeckt im &lt;a href="https://www.parc-network.de/cins/"&gt;CINS-Abgleich&lt;/a&gt; und per Nachbar-Range-Scan vervollständigt — jede IP einzeln reverse-bestätigt (1). Teil unseres &lt;a href="https://www.parc-network.de/parc-security/"&gt;PARC-Security-Feeds&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;&lt;a href="https://www.parc-network.de/feeds/ping-dash.json" target="_blank" rel="noopener" class="btn btn-secondary"&gt;ping-dash.json — Feed ansehen&lt;/a&gt; &amp;nbsp; &lt;a href="https://ping-dash.com/" target="_blank" rel="noopener"&gt;ping-dash.com →&lt;/a&gt;&lt;/p&gt;
&lt;h2 id="verifikation--jede-ip-einzeln"&gt;Verifikation — jede IP einzeln&lt;/h2&gt;
&lt;p&gt;Den Reverse-PTR &lt;span class="mono"&gt;scanner-*.ping-dash.com&lt;/span&gt; kann nur der IP-Betreiber setzen — ein nicht-fälschbarer Eigentums-Hinweis. Seed aus den &lt;strong&gt;aktiv scannenden CINS-IPs&lt;/strong&gt;, per Reverse-Scan der umliegenden /24 vervollständigt; jede IP einzeln bestätigt:&lt;/p&gt;
&lt;pre tabindex="0"&gt;&lt;code&gt;1 IPs → alle PTR ping-dash.com
&lt;/code&gt;&lt;/pre&gt;&lt;p&gt;Reverse-only (Forward nicht durchgängig prüfbar, wie bei Shodan/Infrawatch). AbuseIPDB führt diese IPs teils mit Score 100 — es sind dennoch benigne Research-Scanner.&lt;/p&gt;</description></item><item><title>Rapid7 (Project Sonar) — Scanner per Reverse-DNS scanners.labs.rapid7.com</title><link>https://www.parc-network.de/rapid7/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://www.parc-network.de/rapid7/</guid><description>&lt;p class="lead"&gt;Rapid7 betreibt mit &lt;strong&gt;Project Sonar / Labs&lt;/strong&gt; einen internet-weiten Scanner (USA) für Security-Research. Kein SEO-Tool. Die Scan-IPs sind &lt;strong&gt;self-identifizierend&lt;/strong&gt;: alle reversen auf &lt;span class="mono"&gt;scanners.labs.rapid7.com&lt;/span&gt;. Wir haben &lt;strong&gt;jede einzelne der 108 IPs&lt;/strong&gt; per Reverse-DNS bestätigt. Teil unseres &lt;a href="https://www.parc-network.de/parc-security/"&gt;PARC-Security-Feeds&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;&lt;a href="https://www.parc-network.de/feeds/rapid7.json" target="_blank" rel="noopener" class="btn btn-secondary"&gt;rapid7.json — Feed ansehen&lt;/a&gt; &amp;nbsp; &lt;a href="https://www.rapid7.com/research/project-sonar/" target="_blank" rel="noopener"&gt;Project Sonar →&lt;/a&gt;&lt;/p&gt;
&lt;h2 id="verifikation"&gt;Verifikation&lt;/h2&gt;
&lt;pre tabindex="0"&gt;&lt;code&gt;109.123.117.229 → scanners.labs.rapid7.com ✓
&lt;/code&gt;&lt;/pre&gt;&lt;p&gt;24 CIDR-Blöcke = 108 IPs. Den Reverse-PTR &lt;span class="mono"&gt;scanners.labs.rapid7.com&lt;/span&gt; kann nur der IP-Betreiber setzen — also Rapid7. Wir haben den &lt;strong&gt;Range-Seed aus der MISP-Warninglist&lt;/strong&gt; übernommen und &lt;strong&gt;jede IP einzeln reverse-verifiziert&lt;/strong&gt;: 108 von 108 bestätigt. Keine Stichprobe, keine Hochrechnung.&lt;/p&gt;</description></item><item><title>Reposify (CrowdStrike) — der verifizierte Scanner-Block und wie wir ihn per FCrDNS belegt haben</title><link>https://www.parc-network.de/reposify/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://www.parc-network.de/reposify/</guid><description>&lt;p class="lead"&gt;Reposify ist ein internet-weiter &lt;strong&gt;Attack-Surface-Scanner&lt;/strong&gt; — er sucht das Internet nach exponierten Assets ab, um Firmen ihre externe Angriffsfläche zu zeigen. 2022 von &lt;strong&gt;CrowdStrike&lt;/strong&gt; übernommen. &lt;strong&gt;Kein SEO-Tool.&lt;/strong&gt; Reposify publiziert &lt;strong&gt;keine offizielle IP-Liste&lt;/strong&gt; — wir haben die aktiven Scanner-EIPs deshalb vollständig per &lt;strong&gt;bidirektionalem FCrDNS&lt;/strong&gt; gegen &lt;span class="mono"&gt;*.reposify.net&lt;/span&gt; verifiziert. Teil unseres &lt;a href="https://www.parc-network.de/parc-security/"&gt;PARC-Security-Feeds&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;&lt;a href="https://www.parc-network.de/feeds/reposify.json" target="_blank" rel="noopener" class="btn btn-secondary"&gt;reposify.json — Feed ansehen&lt;/a&gt; &amp;nbsp; &lt;a href="https://www.crowdstrike.com/" target="_blank" rel="noopener"&gt;CrowdStrike (Reposify) →&lt;/a&gt;&lt;/p&gt;
&lt;h2 id="die-blöcke"&gt;Die Blöcke&lt;/h2&gt;
&lt;p&gt;&lt;strong&gt;449 IPv4&lt;/strong&gt;, in AWS (us-east-1, Northern Virginia):&lt;/p&gt;
&lt;pre tabindex="0"&gt;&lt;code&gt;44.220.185.0/24 228 IPs scanner-44-220-185-NN.reposify.net
44.220.188.0/24 221 IPs scanner-44-220-188-NN.reposify.net
&lt;/code&gt;&lt;/pre&gt;&lt;p&gt;Jede Adresse ist einzeln als &lt;code&gt;/32&lt;/code&gt; im Feed — &lt;strong&gt;keine /24-Aggregation&lt;/strong&gt;, weil in denselben AWS-/24 auch generische EC2-Instanzen anderer Kunden liegen. Es kommt nur rein, was sich per DNS selbst beweist.&lt;/p&gt;</description></item><item><title>research-scanner.com — per-IP self-ID via research-scanner.com</title><link>https://www.parc-network.de/research-scanner/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://www.parc-network.de/research-scanner/</guid><description>&lt;p class="lead"&gt;internet-weiter &lt;strong&gt;Research-Scanner&lt;/strong&gt; (research-scanner.com). Kein SEO-Tool. Die Scan-IPs sind &lt;strong&gt;self-identifizierend&lt;/strong&gt;: Reverse-DNS &lt;span class="mono"&gt;*.research-scanner.com&lt;/span&gt;. Entdeckt im &lt;a href="https://www.parc-network.de/cins/"&gt;CINS-Abgleich&lt;/a&gt; und per Nachbar-Range-Scan vervollständigt — jede IP einzeln reverse-bestätigt (12). Teil unseres &lt;a href="https://www.parc-network.de/parc-security/"&gt;PARC-Security-Feeds&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;&lt;a href="https://www.parc-network.de/feeds/research-scanner.json" target="_blank" rel="noopener" class="btn btn-secondary"&gt;research-scanner.json — Feed ansehen&lt;/a&gt; &amp;nbsp; &lt;a href="https://research-scanner.com/" target="_blank" rel="noopener"&gt;research-scanner.com →&lt;/a&gt;&lt;/p&gt;
&lt;h2 id="verifikation--jede-ip-einzeln"&gt;Verifikation — jede IP einzeln&lt;/h2&gt;
&lt;p&gt;Den Reverse-PTR &lt;span class="mono"&gt;*.research-scanner.com&lt;/span&gt; kann nur der IP-Betreiber setzen — ein nicht-fälschbarer Eigentums-Hinweis. Seed aus den &lt;strong&gt;aktiv scannenden CINS-IPs&lt;/strong&gt;, per Reverse-Scan der umliegenden /24 vervollständigt; jede IP einzeln bestätigt:&lt;/p&gt;
&lt;pre tabindex="0"&gt;&lt;code&gt;12 IPs → alle PTR research-scanner.com
&lt;/code&gt;&lt;/pre&gt;&lt;p&gt;Reverse-only (Forward nicht durchgängig prüfbar, wie bei Shodan/Infrawatch). AbuseIPDB führt diese IPs teils mit Score 100 — es sind dennoch benigne Research-Scanner.&lt;/p&gt;</description></item><item><title>Semrush Bot — verifizierte IP-Ranges, ASN-Prüfung und die Googlebot-Imitation</title><link>https://www.parc-network.de/semrush/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://www.parc-network.de/semrush/</guid><description>&lt;p class="lead"&gt;Semrush ist eines der größten SEO-/Backlink-Tools — und sein Crawler gehört zu den aktivsten kommerziellen Bots im Web. Hier die &lt;strong&gt;verifizierten IP-Ranges&lt;/strong&gt; (Teil unseres &lt;a href="https://www.parc-network.de/parc-security/"&gt;PARC-Security-Feeds&lt;/a&gt;) und, wichtiger noch: wie man den Bot &lt;strong&gt;sicher erkennt&lt;/strong&gt;. Denn Semrush crawlt seit Jahren auch mit gefälschtem Googlebot-User-Agent — eine Erkennung allein über den User-Agent ist daher wertlos.&lt;/p&gt;
&lt;p&gt;&lt;a href="https://www.parc-network.de/feeds/semrush.json" target="_blank" rel="noopener" class="btn btn-secondary"&gt;semrush.json — Feed ansehen&lt;/a&gt; &amp;nbsp; &lt;a href="https://www.semrush.com/bot/" target="_blank" rel="noopener"&gt;Offizielle Semrush-Bot-Seite →&lt;/a&gt;&lt;/p&gt;
&lt;h2 id="die-verifizierten-ranges"&gt;Die verifizierten Ranges&lt;/h2&gt;
&lt;p&gt;Insgesamt &lt;strong&gt;1.539 IPs&lt;/strong&gt; in 6 × /24 plus 3 einzelnen /32:&lt;/p&gt;</description></item><item><title>Shadowforce — per-IP self-ID via shadowforce.io</title><link>https://www.parc-network.de/shadowforce/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://www.parc-network.de/shadowforce/</guid><description>&lt;p class="lead"&gt;internet-weiter &lt;strong&gt;Security-Scanner&lt;/strong&gt; (Shadowforce). Kein SEO-Tool. Die Scan-IPs sind &lt;strong&gt;self-identifizierend&lt;/strong&gt;: Reverse-DNS &lt;span class="mono"&gt;*.scan.shadowforce.io&lt;/span&gt;. Entdeckt im &lt;a href="https://www.parc-network.de/cins/"&gt;CINS-Abgleich&lt;/a&gt; und per Nachbar-Range-Scan vervollständigt — jede IP einzeln reverse-bestätigt (15). Teil unseres &lt;a href="https://www.parc-network.de/parc-security/"&gt;PARC-Security-Feeds&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;&lt;a href="https://www.parc-network.de/feeds/shadowforce.json" target="_blank" rel="noopener" class="btn btn-secondary"&gt;shadowforce.json — Feed ansehen&lt;/a&gt; &amp;nbsp; &lt;a href="https://shadowforce.io/" target="_blank" rel="noopener"&gt;shadowforce.io →&lt;/a&gt;&lt;/p&gt;
&lt;h2 id="verifikation--jede-ip-einzeln"&gt;Verifikation — jede IP einzeln&lt;/h2&gt;
&lt;p&gt;Den Reverse-PTR &lt;span class="mono"&gt;*.scan.shadowforce.io&lt;/span&gt; kann nur der IP-Betreiber setzen — ein nicht-fälschbarer Eigentums-Hinweis. Seed aus den &lt;strong&gt;aktiv scannenden CINS-IPs&lt;/strong&gt;, per Reverse-Scan der umliegenden /24 vervollständigt; jede IP einzeln bestätigt:&lt;/p&gt;
&lt;pre tabindex="0"&gt;&lt;code&gt;15 IPs → alle PTR shadowforce.io
&lt;/code&gt;&lt;/pre&gt;&lt;p&gt;Reverse-only (Forward nicht durchgängig prüfbar, wie bei Shodan/Infrawatch). AbuseIPDB führt diese IPs teils mit Score 100 — es sind dennoch benigne Research-Scanner.&lt;/p&gt;</description></item><item><title>Shadowserver — Scanner-Ranges per ASN-Eigentum (AS22168), per-IP geprüft</title><link>https://www.parc-network.de/shadowserver/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://www.parc-network.de/shadowserver/</guid><description>&lt;p class="lead"&gt;Die &lt;strong&gt;Shadowserver Foundation&lt;/strong&gt; (gemeinnützig, USA) betreibt einen der größten internet-weiten &lt;strong&gt;Security-Scanner&lt;/strong&gt; aus der &lt;strong&gt;eigenen ASN AS22168&lt;/strong&gt;. Kein SEO-Tool. Identifiziert wird über &lt;strong&gt;ASN-Eigentum&lt;/strong&gt; (BGP/RDAP): 26 announced Prefixe = &lt;strong&gt;8.704 IPs&lt;/strong&gt;. Jede einzelne IP haben wir auf ihre Origin-ASN geprüft. Teil unseres &lt;a href="https://www.parc-network.de/parc-security/"&gt;PARC-Security-Feeds&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;&lt;a href="https://www.parc-network.de/feeds/shadowserver.json" target="_blank" rel="noopener" class="btn btn-secondary"&gt;shadowserver.json — Feed ansehen&lt;/a&gt; &amp;nbsp; &lt;a href="https://www.shadowserver.org/" target="_blank" rel="noopener"&gt;shadowserver.org →&lt;/a&gt;&lt;/p&gt;
&lt;h2 id="verifikation-per-ip--komplett-homogen"&gt;Verifikation per-IP — komplett homogen&lt;/h2&gt;
&lt;p&gt;Shadowserver-Scan-IPs haben kein self-identifizierendes Reverse-DNS, gehören aber einer &lt;strong&gt;eigenen, registrierten ASN&lt;/strong&gt; — ein belastbarer Eigentums-Beweis (anders als gemietete Cloud-IPs). Nach dem Alpha-Strike-Befund (dort waren 38 % der Range fremd) haben wir hier &lt;strong&gt;nicht der announced-Liste vertraut&lt;/strong&gt;, sondern &lt;strong&gt;jede der 8.704 IPs einzeln&lt;/strong&gt; auf ihre Origin-ASN geprüft:&lt;/p&gt;</description></item><item><title>Shodan — den bekanntesten Internet-Scanner per Reverse-DNS verifizieren</title><link>https://www.parc-network.de/shodan/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://www.parc-network.de/shodan/</guid><description>&lt;p class="lead"&gt;Shodan ist &lt;strong&gt;der bekannteste Internet-Scanner&lt;/strong&gt; (USA) — die Suchmaschine für mit dem Internet verbundene Geräte. Kein SEO-Tool. Shodan betreibt verteilte &lt;strong&gt;census-Knoten&lt;/strong&gt; über mehrere Hoster, ohne eigene Range. Sie identifizieren sich per &lt;strong&gt;Reverse-DNS&lt;/strong&gt; &lt;span class="mono"&gt;*.census.shodan.io&lt;/span&gt; und &lt;span class="mono"&gt;*.scanf.shodan.io&lt;/span&gt;. Wir haben jede IP &lt;strong&gt;einzeln per Reverse-DNS bestätigt&lt;/strong&gt;. Teil unseres &lt;a href="https://www.parc-network.de/parc-security/"&gt;PARC-Security-Feeds&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;&lt;a href="https://www.parc-network.de/feeds/shodan.json" target="_blank" rel="noopener" class="btn btn-secondary"&gt;shodan.json — Feed ansehen&lt;/a&gt; &amp;nbsp; &lt;a href="https://www.shodan.io/" target="_blank" rel="noopener"&gt;shodan.io →&lt;/a&gt;&lt;/p&gt;
&lt;h2 id="verifikation-per-autoritativem-reverse-dns"&gt;Verifikation per autoritativem Reverse-DNS&lt;/h2&gt;
&lt;p&gt;Die Scan-IPs reversen auf benannte Knoten (&lt;span class="mono"&gt;soda.census.shodan.io&lt;/span&gt;, &lt;span class="mono"&gt;waffles.scanf.shodan.io&lt;/span&gt; …). Den Reverse-PTR kann nur der IP-Betreiber setzen — also Shodan. Das ist ein &lt;strong&gt;nicht-fälschbarer Eigentums-Beweis&lt;/strong&gt;.&lt;/p&gt;</description></item><item><title>Stretchoid — einen anonymen Azure-Scanner ohne offizielle Liste verifizierbar machen</title><link>https://www.parc-network.de/stretchoid/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://www.parc-network.de/stretchoid/</guid><description>&lt;p class="lead"&gt;Stretchoid ist ein internet-weiter &lt;strong&gt;Recon-/Port-Scanner&lt;/strong&gt; mit &lt;strong&gt;anonymem Betreiber&lt;/strong&gt;. Kein SEO-Tool. Es gibt &lt;strong&gt;keine offizielle IP-Liste und keine eigene Range&lt;/strong&gt; — die Scanner laufen auf rotierenden &lt;strong&gt;Microsoft-Azure-IPs&lt;/strong&gt; (AS8075). Trotzdem fassbar, weil Stretchoid einen selbstidentifizierenden Reverse-DNS &lt;span class="mono"&gt;*.stretchoid.com&lt;/span&gt; setzt, der &lt;strong&gt;FCrDNS-verifizierbar&lt;/strong&gt; ist. Die aktiven IPs leiten wir aus &lt;strong&gt;zwei Quellen&lt;/strong&gt; ab und bestätigen jede einzeln: &lt;strong&gt;1.909 verifizierte IPs&lt;/strong&gt;. Teil unseres &lt;a href="https://www.parc-network.de/parc-security/"&gt;PARC-Security-Feeds&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;&lt;a href="https://www.parc-network.de/feeds/stretchoid.json" target="_blank" rel="noopener" class="btn btn-secondary"&gt;stretchoid.json — Feed ansehen&lt;/a&gt; &amp;nbsp; &lt;span class="mono"&gt;stretchoid.com&lt;/span&gt; &lt;span style="opacity:.6"&gt;(Opt-out-Falle — bewusst nicht verlinkt)&lt;/span&gt;&lt;/p&gt;
&lt;h2 id="woher-die-ips-kommen--zwei-quellen-ein-filter"&gt;Woher die IPs kommen — zwei Quellen, ein Filter&lt;/h2&gt;
&lt;p&gt;Stretchoid publiziert nichts. Es gibt keine offizielle Range-Liste und kein eigenes ASN — die Scanner laufen auf gemieteten Azure-IPs, die rotieren. Ein klassischer Range-Block wie bei Censys oder ONYPHE ist damit unmöglich. Wir nutzen stattdessen zwei Beobachtungs-Quellen und denselben Filter:&lt;/p&gt;</description></item><item><title>Stripe — offizielle IP-Ranges (Webhook/API)</title><link>https://www.parc-network.de/stripe/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://www.parc-network.de/stripe/</guid><description>&lt;p class="lead"&gt;&lt;strong&gt;Stripe&lt;/strong&gt; (US/IE) ist ein Zahlungsanbieter. Dies sind die &lt;strong&gt;offiziellen IP-Ranges&lt;/strong&gt;, unter denen Stripes Webhook-/API-Server senden bzw. erreichbar sind — aus der offiziellen Quelle zu PARC-Feed normalisiert (15 Einträge). Teil unseres &lt;a href="https://www.parc-network.de/parc-security/"&gt;PARC-Security-Feeds&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;&lt;a href="https://www.parc-network.de/feeds/stripe.json" target="_blank" rel="noopener" class="btn btn-secondary"&gt;stripe.json — Feed ansehen&lt;/a&gt; &amp;nbsp; &lt;a href="https://stripe.com/" target="_blank" rel="noopener"&gt;stripe.com →&lt;/a&gt;&lt;/p&gt;
&lt;h2 id="quelle--aktualisierung"&gt;Quelle &amp;amp; Aktualisierung&lt;/h2&gt;
&lt;p&gt;Quelle: &lt;span class="mono"&gt;stripe.com/files/ips/ips_webhooks.txt&lt;/span&gt; — offiziell publiziert. Die Liste wird von einem maschinenlesbaren Endpoint nachgezogen. Stripe kann die Ranges jederzeit ändern; der PARC-Feed bildet den offiziellen Stand ab. Reine IP-Daten ohne Wertung.&lt;/p&gt;
&lt;h2 id="quellen"&gt;Quellen&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://stripe.com/" target="_blank" rel="noopener"&gt;Stripe&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://stripe.com/files/ips/ips_webhooks.txt" target="_blank" rel="noopener"&gt;Offizielle IP-Quelle&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;p style="margin-top: 40px;"&gt;&lt;a href="https://www.parc-network.de/parc-security/" class="btn btn-secondary"&gt;← Zurück zu PARC Security&lt;/a&gt; &amp;nbsp; &lt;a href="https://www.parc-network.de/#kontakt" class="btn btn-primary"&gt;Kontakt aufnehmen&lt;/a&gt;&lt;/p&gt;</description></item><item><title>The Recyber Project — per-IP self-ID via recyber.net</title><link>https://www.parc-network.de/recyber/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://www.parc-network.de/recyber/</guid><description>&lt;p class="lead"&gt;Das &lt;strong&gt;Recyber Project&lt;/strong&gt; betreibt einen internet-weiten &lt;strong&gt;Security-Scanner&lt;/strong&gt;. Kein SEO-Tool. Die Scan-IPs sind &lt;strong&gt;self-identifizierend&lt;/strong&gt;: PTR auf &lt;span class="mono"&gt;recyber.net&lt;/span&gt;. Wir haben jede IP einzeln reverse-geprüft. Teil unseres &lt;a href="https://www.parc-network.de/parc-security/"&gt;PARC-Security-Feeds&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;&lt;a href="https://www.parc-network.de/feeds/recyber.json" target="_blank" rel="noopener" class="btn btn-secondary"&gt;recyber.json — Feed ansehen&lt;/a&gt; &amp;nbsp; &lt;a href="https://www.recyber.net/" target="_blank" rel="noopener"&gt;www.recyber.net →&lt;/a&gt;&lt;/p&gt;
&lt;h2 id="verifikation--jede-ip-einzeln"&gt;Verifikation — jede IP einzeln&lt;/h2&gt;
&lt;p&gt;Die zwei Listen-/24 (89.248.163.0/24, 89.248.165.0/24) liegen bei IP Volume inc (AS202425). Der Reverse-PTR &lt;span class="mono"&gt;recyber.net&lt;/span&gt; kann nur der IP-Betreiber setzen:&lt;/p&gt;
&lt;pre tabindex="0"&gt;&lt;code&gt;508 IPs (2 /24) → 350 mit PTR recyber.net (nur die kommen rein)
&lt;/code&gt;&lt;/pre&gt;&lt;p&gt;Die 158 ohne self-ID (no-reverse / fremde PTR) bleiben draußen. Keine Hochrechnung.&lt;/p&gt;</description></item><item><title>Twitterbot / X-Crawler — IP-Ranges, ASN-Verifikation und das Grok-AI-Training-Risiko</title><link>https://www.parc-network.de/twitter-x/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://www.parc-network.de/twitter-x/</guid><description>&lt;p class="lead"&gt;X (vormals Twitter) betreibt den &lt;strong&gt;Twitterbot&lt;/strong&gt; für Link-Previews (Twitter-Cards) — und seit der Übernahme durch &lt;strong&gt;xAI&lt;/strong&gt; (Mai 2025) kommen aus denselben Netzen vermutlich auch &lt;strong&gt;AI-Trainings-Crawls für Grok&lt;/strong&gt;. X publiziert &lt;strong&gt;keine offizielle IP-Liste&lt;/strong&gt;; Verifikation läuft ausschließlich über die ASN. Hier die aggregierten Ranges (Teil unseres &lt;a href="https://www.parc-network.de/parc-security/"&gt;PARC-Security-Feeds&lt;/a&gt;) und wie wir sie ermittelt und validiert haben.&lt;/p&gt;
&lt;p&gt;&lt;a href="https://www.parc-network.de/feeds/twitter-x.json" target="_blank" rel="noopener" class="btn btn-secondary"&gt;twitter-x.json — Feed ansehen&lt;/a&gt; &amp;nbsp; &lt;a href="https://developer.x.com/en/docs/twitter-for-websites/cards/guides/troubleshooting-cards" target="_blank" rel="noopener"&gt;X-Cards-Doku →&lt;/a&gt;&lt;/p&gt;
&lt;h2 id="die-ranges"&gt;Die Ranges&lt;/h2&gt;
&lt;p&gt;Insgesamt &lt;strong&gt;20 Prefixes&lt;/strong&gt; (17 IPv4 + 3 IPv6), aggregiert aus fünf X-eigenen ASNs:&lt;/p&gt;</description></item><item><title>University of Michigan — Scan-Forschung aus eigenem /16 (AS36375)</title><link>https://www.parc-network.de/umich/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://www.parc-network.de/umich/</guid><description>&lt;p class="lead"&gt;Die &lt;strong&gt;University of Michigan&lt;/strong&gt; betreibt langjährige internet-weite &lt;strong&gt;Scan-Forschung&lt;/strong&gt; (u.a. ZMap/Censys-Ursprünge) aus dem &lt;strong&gt;eigenen Netzblock&lt;/strong&gt;. Kein SEO-Tool. Identifiziert über &lt;strong&gt;ASN-Eigentum&lt;/strong&gt;: AS36375, eigenes 141.212.0.0/16. Teil unseres &lt;a href="https://www.parc-network.de/parc-security/"&gt;PARC-Security-Feeds&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;&lt;a href="https://www.parc-network.de/feeds/umich.json" target="_blank" rel="noopener" class="btn btn-secondary"&gt;umich.json — Feed ansehen&lt;/a&gt; &amp;nbsp; &lt;a href="https://cse.engin.umich.edu/about/resources/connection-attempts/" target="_blank" rel="noopener"&gt;cse.engin.umich.edu →&lt;/a&gt;&lt;/p&gt;
&lt;h2 id="verifikation--jede-ip-einzeln"&gt;Verifikation — jede IP einzeln&lt;/h2&gt;
&lt;p&gt;Die 6 announced /24-Blöcke (141.212.120–125) liegen alle im &lt;strong&gt;eigenen /16 der Universität&lt;/strong&gt; (ARIN-Allokation von 1990). Nach der Alpha-Strike-Lehre haben wir nicht der Liste vertraut, sondern &lt;strong&gt;jede IP einzeln auf ihre Origin-ASN&lt;/strong&gt; geprüft:&lt;/p&gt;
&lt;pre tabindex="0"&gt;&lt;code&gt;1.524 / 1.524 Host-IPs → alle AS36375 (0 Fremd-IPs, vollständig)
&lt;/code&gt;&lt;/pre&gt;&lt;p&gt;700 davon self-identifizieren zusätzlich per Reverse-DNS auf &lt;span class="mono"&gt;umich.edu&lt;/span&gt;.&lt;/p&gt;</description></item><item><title>Visionheight — per-IP self-ID via visionheight.com</title><link>https://www.parc-network.de/visionheight/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://www.parc-network.de/visionheight/</guid><description>&lt;p class="lead"&gt;internet-weiter &lt;strong&gt;Research-Scanner&lt;/strong&gt; (Visionheight). Kein SEO-Tool. Die Scan-IPs sind &lt;strong&gt;self-identifizierend&lt;/strong&gt;: Reverse-DNS &lt;span class="mono"&gt;scan.visionheight.com&lt;/span&gt;. Entdeckt im &lt;a href="https://www.parc-network.de/cins/"&gt;CINS-Abgleich&lt;/a&gt; und per Nachbar-Range-Scan vervollständigt — jede IP einzeln reverse-bestätigt (15). Teil unseres &lt;a href="https://www.parc-network.de/parc-security/"&gt;PARC-Security-Feeds&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;&lt;a href="https://www.parc-network.de/feeds/visionheight.json" target="_blank" rel="noopener" class="btn btn-secondary"&gt;visionheight.json — Feed ansehen&lt;/a&gt; &amp;nbsp; &lt;a href="https://visionheight.com/" target="_blank" rel="noopener"&gt;visionheight.com →&lt;/a&gt;&lt;/p&gt;
&lt;h2 id="verifikation--jede-ip-einzeln"&gt;Verifikation — jede IP einzeln&lt;/h2&gt;
&lt;p&gt;Den Reverse-PTR &lt;span class="mono"&gt;scan.visionheight.com&lt;/span&gt; kann nur der IP-Betreiber setzen — ein nicht-fälschbarer Eigentums-Hinweis. Seed aus den &lt;strong&gt;aktiv scannenden CINS-IPs&lt;/strong&gt;, per Reverse-Scan der umliegenden /24 vervollständigt; jede IP einzeln bestätigt:&lt;/p&gt;
&lt;pre tabindex="0"&gt;&lt;code&gt;15 IPs → alle PTR visionheight.com
&lt;/code&gt;&lt;/pre&gt;&lt;p&gt;Reverse-only (Forward nicht durchgängig prüfbar, wie bei Shodan/Infrawatch). AbuseIPDB führt diese IPs teils mit Score 100 — es sind dennoch benigne Research-Scanner.&lt;/p&gt;</description></item><item><title>Worldline (Direct) — offizielle IP-Ranges (Webhook/Notifications)</title><link>https://www.parc-network.de/worldline/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://www.parc-network.de/worldline/</guid><description>&lt;p class="lead"&gt;&lt;strong&gt;Worldline (Direct)&lt;/strong&gt; (FR/BE) ist ein Zahlungsanbieter. Dies sind die &lt;strong&gt;offiziellen IP-Ranges&lt;/strong&gt;, unter denen Worldline (Direct)s Webhook-/Notification-Server senden — aus der offiziellen Quelle zu PARC-Feed normalisiert (4 Einträge). &lt;strong&gt;Hinweis:&lt;/strong&gt; identische Ranges wie PAYONE — beide laufen auf derselben Worldline-Plattform (PAYONE ist ein Worldline-Joint-Venture). Teil unseres &lt;a href="https://www.parc-network.de/parc-security/"&gt;PARC-Security-Feeds&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;&lt;a href="https://www.parc-network.de/feeds/worldline.json" target="_blank" rel="noopener" class="btn btn-secondary"&gt;worldline.json — Feed ansehen&lt;/a&gt; &amp;nbsp; &lt;a href="https://docs.direct.worldline-solutions.com/" target="_blank" rel="noopener"&gt;docs.direct.worldline-solutions.com →&lt;/a&gt;&lt;/p&gt;
&lt;h2 id="quelle--aktualisierung"&gt;Quelle &amp;amp; Aktualisierung&lt;/h2&gt;
&lt;p&gt;Quelle: &lt;span class="mono"&gt;Worldline-Direct-Doku (Firewall configuration)&lt;/span&gt; — offiziell publiziert. Aus der Anbieter-Doku übernommen. Worldline (Direct) kann die Ranges ändern; der PARC-Feed bildet den offiziellen Stand ab. Reine IP-Daten ohne Wertung.&lt;/p&gt;</description></item><item><title>XoviBot (XOVI) — die verifizierten Crawler-Ranges, Smoking-Gun-PTR und der Mischpool-Trick</title><link>https://www.parc-network.de/xovibot/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://www.parc-network.de/xovibot/</guid><description>&lt;p class="lead"&gt;XoviBot ist der Crawler der Kölner &lt;strong&gt;XOVI&lt;/strong&gt;-SEO-Plattform (Backlink-Index, Keyword-Tracking, Rank-Monitoring). XOVI publiziert &lt;strong&gt;keine offizielle IP-Liste&lt;/strong&gt;. Wir haben die aktiven Ranges über &lt;strong&gt;drei Quellen&lt;/strong&gt; belegt — Tracker-Datenbanken, ASN-Aggregation und einen vollständigen Subnet-Scan mit einem eindeutigen Reverse-DNS-Treffer. Teil unseres &lt;a href="https://www.parc-network.de/parc-security/"&gt;PARC-Security-Feeds&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;&lt;a href="https://www.parc-network.de/feeds/xovibot.json" target="_blank" rel="noopener" class="btn btn-secondary"&gt;xovibot.json — Feed ansehen&lt;/a&gt; &amp;nbsp; &lt;a href="https://www.xovibot.net/" target="_blank" rel="noopener"&gt;XoviBot-Info →&lt;/a&gt;&lt;/p&gt;
&lt;h2 id="die-ranges"&gt;Die Ranges&lt;/h2&gt;
&lt;p&gt;&lt;strong&gt;1 CIDR + 8 Einzel-IPs = 9 Einträge&lt;/strong&gt;, alle bei deutschen Tier-2-Hostern:&lt;/p&gt;
&lt;pre tabindex="0"&gt;&lt;code&gt;78.138.117.0/24 Hauptpool — PlusServer (AS61157), komplettes /24
85.114.158.169/32 MyLoc / WIIT (AS24961) — 6 PTR-freie Slots
85.114.158.174/32
85.114.158.179/32
85.114.158.206/32
85.114.158.209/32
85.114.158.210/32
212.224.119.138/32 firstcolo (AS44066)
212.224.119.141/32
&lt;/code&gt;&lt;/pre&gt;&lt;p&gt;XOVI sitzt als Kölner Firma logischerweise bei deutschen Hostern, die klassisch SEO-/Marketing-Tools beherbergen.&lt;/p&gt;</description></item></channel></rss>