Coder Social home page Coder Social logo

blocklistproject / lists Goto Github PK

View Code? Open in Web Editor NEW
3.3K 66.0 314.0 4 GB

Primary Block Lists

License: The Unlicense

JavaScript 100.00%
pihole blocklist adblock adblock-list pi-hole-blocklists pi-hole-lists pihole-blocklists pihole-adblocker-list

lists's People

Contributors

acodinggenie avatar blocklistproject avatar buzink avatar caspermcfadden95 avatar dragonflypacificgallery avatar fishcharlie avatar fooflington avatar gap579137 avatar hapx101 avatar iam-py-test avatar inigoleaga avatar jennyfromtheblockchains avatar jinksy31337 avatar jmajeremy avatar justdustn avatar kateferrandino avatar kenaithewolf avatar m4t7e avatar nickspaargaren avatar rilindo avatar sanderhollaar avatar simpoltin avatar spirillen avatar theyapps avatar thomasmerz avatar trainax avatar ustav avatar vjohannesb avatar vonneudeck avatar ymhcanada avatar

Stargazers

 avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar

Watchers

 avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar

lists's Issues

"Github" string on torrent.txt got github.com DNS request blocked by firewall

URL you wish to be removed: 0.0.0.0 div>Hosted On GitHub

Why you believe this to be a false positive: I was using this blocklist as a source for a firewall solution to drop torrent websites DNS packets. Having that line on the file caused DNS requests to github.com to be dropped. That line sounds like a defect which demanded me to stop using this blocklist on my firewall. Can't trust this list anymore.

List it is on: https://github.com/blocklistproject/Lists/blob/master/torrent.txt#L1853

Other info I think you should know: this is a good blocklist and I intend to keep using it, but can't set my code to auto-fetch it and use it as a valid source due to this issue.

bbci.co.uk

URL you wish to be removed: bbci.co.uk

Why you believe this to be a false positive: This is BBC

List it is on: Ads

Other info you think we should know:

files.fm

URL you wish to be removed: files.fm

Why you believe this to be a false positive: This is a normal upload site

List it is on: malware

Other info you think we should know:

nyt5-assets.prd.map.nytimes.com

URL you wish to be removed:

nyt5-assets.prd.map.nytimes.com
static.prd.map.nytimes.com

Why you believe this to be a false positive:

This is the fonts and static assets (like images) for the NY Times.

List it is on:

Ads

Other info you think we should know:

Here's the output of dig when the list is not active:

; <<>> DiG 9.14.2 <<>> g1.nyt.com
;; global options: +cmd
;; Got answer:
;; ->>HEADER<<- opcode: QUERY, status: NOERROR, id: 24963
;; flags: qr rd ra; QUERY: 1, ANSWER: 6, AUTHORITY: 0, ADDITIONAL: 1

;; OPT PSEUDOSECTION:
; EDNS: version: 0, flags:; udp: 512
;; QUESTION SECTION:
;g1.nyt.com.                    IN      A

;; ANSWER SECTION:
g1.nyt.com.             227     IN      CNAME   nyt5-assets.prd.map.nytimes.com.
nyt5-assets.prd.map.nytimes.com. 80 IN  CNAME   nytimes.map.fastly.net.
nytimes.map.fastly.net. 29      IN      A       151.101.1.164
nytimes.map.fastly.net. 29      IN      A       151.101.65.164
nytimes.map.fastly.net. 29      IN      A       151.101.129.164
nytimes.map.fastly.net. 29      IN      A       151.101.193.164

;; Query time: 3415 msec
;; SERVER: <local pihole>
;; WHEN: Wed Aug 05 13:52:45 Mountain Daylight Time 2020
;; MSG SIZE  rcvd: 181

hostsVN blocklist in gambling.txt

I noticed this blocklist in gambling.txt. It's an ads and trackers blocklist so I think ads.txt would be a more appropriate place for it to be included.

gstaticadssl.l.google.com

URL you wish to be removed: gstaticadssl.l.google.com

Why you believe this to be a false positive: This is where Google Fonts are served from. (fonts.gstatic.com is a CNAME redirect to this).

List it is on: ads, malware

Other info you think we should know:

cdn.cookielaw.org

URL you wish to be removed: cdn.cookielaw.org
Why you believe this to be a false positive: it's about regulations/complience
List it is on: gambling

Other info you think we should know:

hubspot.com

URL you wish to be removed: hubspot.com

Why you believe this to be a false positive: Used for website.grader.com to work

List it is on: tracking

Other info you think we should know:

downloads.intercomcdn.com

URL you wish to be removed: downloads.intercomcdn.com

Why you believe this to be a false positive: Part of support solution

List it is on: malware

Other info you think we should know:

yospace.com

URL you wish to be removed: yospace.com

Why you believe this to be a false positive: It's used for streaming, for example on comhemplay.se

List it is on: tracking

Other info you think we should know:

tns-sifo.se

URL you wish to be removed: tns-sifo.se

Why you believe this to be a false positive: It's for surveys

List it is on: Ads and Tracking

Other info you think we should know:

Feeds description and data freshness

  1. Are you going to provide some description of the feeds and how they are generated?
    I do understand that many names are self-explanatory but for example the crypto list what crypto currencies does it includes?
  2. I'm considering to use your feeds @ ioc2rpz community web-site (free RPZ feeds) but have concerns regarding how fresh is the data. How often do you update the lists? On github I see that many lists were published 25 days ago including fraud, scam and malware (actually was updated a week ago).

widget.intercom.io

URL you wish to be removed: widget.intercom.io

Why you believe this to be a false positive: Used for chat software

List it is on: ads

Other info you think we should know:

Whitelist llnwd.net

URL you wish to be removed: llnwd.net

Why you believe this to be a false positive: Standard query response 0xb230 No such name A www.nintendo.de CNAME nintendoeu-1.hs.llnwd.net

List it is on: ads.txt

Other info you think we should know: Please do not block entire domain. This will only increase the false positive. The owner of llnwd.net is Limelight Networks a CDN Service Provider. By Blocking this domain you also block Nintendo (EU), BubbleUP and DailyMotion.

cs11.wpc.v0cdn.net (Windows-Updates)

URL you wish to be removed: cs11.wpc.v0cdn.net

Why you believe this to be a false positive: The Pi-hole is blocking Windows-Updates cause of this domain:
Bildschirmfoto vom 2020-07-17 00-30-35
If it is needed for Windows-Updates it's probably not ads.

List it is on: ads

Other info you think we should know: Other Windows-Update-servers may be blocked cause of this too.

wpc.v0cdn.net

URL you wish to be removed: wpc.v0cdn.net

Why you believe this to be a false positive: It's needed for legitimate site tele2.se to work

List it is on: ads

Other info you think we should know:

*gigya.com

URL you wish to be removed: *.gigya.com

Why you believe this to be a false positive: It's needed to be able to sign in on manutd.com

List it is on: Tracking

Other info you think we should know:

secured-login.net

URL you wish to be removed: www.secured-login.net, secured-login.net

Why you believe this to be a false positive: This is a domain owned and operated by KnowBe4, a security awareness company. This domain is used by companies to launch authorized phishing simulations and is not actually a fradulent site.

List it is on: fraud

Other info you think we should know:

Potential false positive due to CNAME

URL you wish to be removed: us-east-1-a.route.herokuapp.com

Why you believe this to be a false positive: it is a cname for learning-machines.herokuapp.com which is a website about machine learning using rust

List it is on: ads.txt

Other info you think we should know: It is also the cname for over 8000 other domains, a large amount of which are of the format direwolf-[0-9a-f]{10}.herokuapp.com, but some are other formats, and not all are subdomains of herokuapp.com. I don't know whether these domains should be blocked, just thought it might be useful to mention

^appledetails.u$

Wondering which TLD this record belongs to:

appledetails.u from this file https://github.com/blocklistproject/Lists/blob/master/phishing.txt?raw=true

s-media-cache-ak0.pinimg.com potential false positive

URL you wish to be removed: s-media-cache-ak0.pinimg.com

Why you believe this to be a false positive:

s-media-cache-ak0.pinimg.com blocks access to https://s-media-cache-ak0.pinimg.com/originals/28/86/42/288642dec69cb52611e17a2afadc940e.jpg. That url redirects to https://i.pinimg.com/originals/28/86/42/288642dec69cb52611e17a2afadc940e.jpg which isn’t blocked, and is just an image from a video game.

The original url is found in duckduckgo image search results: View file at https://duckduckgo.com/?t=ffab&q=arvak&iax=images&ia=images&iai=https%3A%2F%2Fs-media-cache-ak0.pinimg.com%2Foriginals%2F28%2F86%2F42%2F288642dec69cb52611e17a2afadc940e.jpg

List it is on: ads.txt

Other info you think we should know:

intercomassets.com

URL you wish to be removed: intercomassets.com

Why you believe this to be a false positive: Part of a support solution

List it is on: tracking

Other info you think we should know:

hwcdn.net

URL you wish to be removed: hwcdn.net

Why you believe this to be a false positive: It's needed for legit sites like criticker.com to work

List it is on: ads

Other info you think we should know:

PeoplePerHour.com

URL you wish to be removed: www.peopleperhour.com

Why you believe this to be a false positive: This is a false positive because PeoplePerHour is a legitimate website that connects freelancers with employers.

List it is on: Fraud

Other info you think we should know: Check PPH's Google information panel by googling it

js.intercomcdn.com

URL you wish to be removed: js.intercomcdn.com

Why you believe this to be a false positive: It's part of support solution

List it is on: ads

Other info you think we should know:

Remove postfinance.ch from Phishing List

URL you wish to be removed:
postfinance.ch

Why you believe this to be a false positive:
postfinance.ch belongs to PostFinance (https://www.postfinance.ch) a Swiss bank and it should therefore not be on the phishing list. There is one additional A record but the IP address belongs to Post CH AG, the parent company of PostFinace.

; <<>> DiG 9.16.3-Debian <<>> postfinance.ch
;; global options: +cmd
;; Got answer:
;; ->>HEADER<<- opcode: QUERY, status: NOERROR, id: 25882
;; flags: qr rd ad; QUERY: 1, ANSWER: 2, AUTHORITY: 0, ADDITIONAL: 0
;; WARNING: recursion requested but not available

;; QUESTION SECTION:
;postfinance.ch.                        IN      A

;; ANSWER SECTION:
postfinance.ch.         0       IN      A       194.41.166.40
postfinance.ch.         0       IN      A       194.41.226.24

;; Query time: 90 msec
;; SERVER: 172.31.64.1#53(172.31.64.1)
;; WHEN: Sat Jun 20 06:56:32 CEST 2020
;; MSG SIZE  rcvd: 78
; <<>> DiG 9.16.3-Debian <<>> www.postfinance.ch
;; global options: +cmd
;; Got answer:
;; ->>HEADER<<- opcode: QUERY, status: NOERROR, id: 34831
;; flags: qr rd ad; QUERY: 1, ANSWER: 1, AUTHORITY: 0, ADDITIONAL: 0
;; WARNING: recursion requested but not available

;; QUESTION SECTION:
;www.postfinance.ch.            IN      A

;; ANSWER SECTION:
www.postfinance.ch.     0       IN      A       194.41.226.24

;; Query time: 190 msec
;; SERVER: 172.31.64.1#53(172.31.64.1)
;; WHEN: Sat Jun 20 06:56:38 CEST 2020
;; MSG SIZE  rcvd: 70

List it is on: phishing.txt

Other info you think we should know:

Use a GitHub Pages site to host lists

The use of raw.githubusercontent URLs is considered bad form for PiHole since it will re-download the list every time it updates. you should set up a GitHub Pages site and then use those URLs to point to the lists. This will include the last-modified data in the header preventing PiHole from pulling the list if nothing has changed. The addresses for the lists would then be similar to:

https://blocklistproject.github.io/Lists/Malware

These are smaller URLs as well which are easier to read on the web interface (while also reducing wear on an SD card for PiHole hosted on actual Raspberry Pi hardware due to not downloading unless there are changes). This would not break anyone that is currently using the raw.githubusercontent URLs, but would provide a better source for anyone that wants to change them over as well as new users.

More Information:
https://discourse.pi-hole.net/t/i-concatenated-every-blocklist-i-could-find/5184/2
https://docs.github.com/en/github/working-with-github-pages/creating-a-github-pages-site

byside.com

URL you wish to be removed: byside.com

Why you believe this to be a false positive: This is used for chat, for example on ikea.com

List it is on: Tracking

Other info you think we should know:

*.yandex.ru subdomains in gambling

URL you wish to be removed: multple yandex.ru subdomains. Also I saw some other yandex domains which can be legit
Why you believe this to be a false positive: Yandex is like a google in Russia. their domains can be related to tracking, ads but not gambling.
List it is on: gambling
Other info you think we should know:
gambling.txt:# [yandex.ru]
gambling.txt:0.0.0.0 adfox.yandex.ru
gambling.txt:0.0.0.0 matchid.adfox.yandex.ru
gambling.txt:0.0.0.0 adsdk.yandex.ru
gambling.txt:0.0.0.0 advertising.yandex.ru
gambling.txt:0.0.0.0 an.yandex.ru
gambling.txt:0.0.0.0 redirect.appmetrica.yandex.ru
gambling.txt:0.0.0.0 awaps.yandex.ru
gambling.txt:0.0.0.0 awsync.yandex.ru
gambling.txt:0.0.0.0 bs.yandex.ru
gambling.txt:0.0.0.0 bs-meta.yandex.ru
gambling.txt:0.0.0.0 clck.yandex.ru
gambling.txt:0.0.0.0 informer.yandex.ru
gambling.txt:0.0.0.0 kiks.yandex.ru
gambling.txt:0.0.0.0 grade.market.yandex.ru
gambling.txt:0.0.0.0 mc.yandex.ru
gambling.txt:0.0.0.0 metrica.yandex.ru
gambling.txt:0.0.0.0 metrika.yandex.ru
gambling.txt:0.0.0.0 click.sender.yandex.ru
gambling.txt:0.0.0.0 share.yandex.ru
gambling.txt:# 0.0.0.0 clck.yandex.ru
gambling.txt:# 0.0.0.0 grade.market.yandex.ru
gambling.txt:0.0.0.0 ms.yandex.ru

ljudochbild.se

URL you wish to be removed:
ljudochbild.se

Why you believe this to be a false positive:
This is a legitimate site

List it is on:
malware

Other info you think we should know:

ipinfo.io

Please can you remove ipinfo.io? It is a platform to access IP address data, it is not a tracking platform.

api-iam.intercom.io

URL you wish to be removed: api-iam.intercom.io

Why you believe this to be a false positive: Part of support software

List it is on: ads

Other info you think we should know:

Recommend Projects

  • React photo React

    A declarative, efficient, and flexible JavaScript library for building user interfaces.

  • Vue.js photo Vue.js

    πŸ–– Vue.js is a progressive, incrementally-adoptable JavaScript framework for building UI on the web.

  • Typescript photo Typescript

    TypeScript is a superset of JavaScript that compiles to clean JavaScript output.

  • TensorFlow photo TensorFlow

    An Open Source Machine Learning Framework for Everyone

  • Django photo Django

    The Web framework for perfectionists with deadlines.

  • D3 photo D3

    Bring data to life with SVG, Canvas and HTML. πŸ“ŠπŸ“ˆπŸŽ‰

Recommend Topics

  • javascript

    JavaScript (JS) is a lightweight interpreted programming language with first-class functions.

  • web

    Some thing interesting about web. New door for the world.

  • server

    A server is a program made to process requests and deliver data to clients.

  • Machine learning

    Machine learning is a way of modeling and interpreting data that allows a piece of software to respond intelligently.

  • Game

    Some thing interesting about game, make everyone happy.

Recommend Org

  • Facebook photo Facebook

    We are working to build community through open source technology. NB: members must have two-factor auth.

  • Microsoft photo Microsoft

    Open source projects and samples from Microsoft.

  • Google photo Google

    Google ❀️ Open Source for everyone.

  • D3 photo D3

    Data-Driven Documents codes.