OPNsense Forum

English Forums => Q-Feeds (Threat intelligence) => Topic started by: meyergru on May 14, 2026, 05:55:03 PM

Title: False positives, probably because of a major Vodafone mishap...
Post by: meyergru on May 14, 2026, 05:55:03 PM
Background: I had a problem with a remote Plex access to my network earlier this month. This problem resurfaced today and now, I have found what eventually caused it.

The client was trying to access from a Deutsche Glasfaser account with IP 93.104.119.235 (nothing private to that, because it is CG-NAT).
As it turns out, at the time of writing, this IP is listed at Q-Feeds. It also was listed at Blocklist.de, because of IMAP attacks on 1st of May.

2026-05-14 17_50_04-IP 94.31.108.115 - Suchen nach IP 94.31.108.115 - Treffer_ 1; ; -- www.blocklist.png

Ironically, this was caused by a prolonged outage of Vodafone's IMAP services. It seems that they also notified some blacklisting services because of failed IMAP attempts that they caused themselves. I already reported this as a false positive, but the IP above is only one example, so in case you see problems, now you know... Q-Feeds should dismiss all reports on this IMAP problems.


Proof:

https://forum.vodafone.de/t5/MeinVodafone-E-Mail/Sammelthread-IMAP-Problem-mit-Vodafone-E-Mail-Konto/td-p/3329568


P.S.: There is no contradiction, as using a free e-mail account on one of Vodafone's domains but still having any other access provider is perfectly fine....