Tor and IPS conflict --SURICATA Rulset where does it come from?

No, “xyz.tar.gz” files are simple (gzip) compressed archives, very similar to the well known zip or rar archives on windows.

So may existing files completely will be overwritten during extraction, because the “-f” flag in the given command is set. This is used to “force” the extraction and overwrite the file instead of asking the user.

This is the desired behavior here, because it makes installing and testing those release builds a lot easier.

I really don’t know the criteria when an address or network get part of such a blocklist. Massive spamming could be a good reason, or perfoming network attacks through the onion network etc.

Sadly it is not possible to remove any exit nodes from those list, because for good reasons there is no complete exit nodes list available in public. Also if you edit the list manually and remove the known or blocked one, those changes will be gone after the next list update.

So the only way to avoid blocking any exit nodes would be to disable the DROP_HOSTILE feature entirely.

-Stefan