Blocklist of all Facebook domains
github.com
github.com
If you really want to block all traffic from/to facebook, lookup the IP prefixes associated with their AS number(AS32934), and setup your firewall to block those. If you are using PF, tables are your friend. With netfilter, consider using ipset.
[1] http://www.commandlinefu.com/commands/view/16096/block-all-f...
And if you're already doing outbound whitelisting (which is generally much more trouble than it's worth) then unless you put Facebook on the whitelist you don't need to do anything anyway.
https://en.m.wikipedia.org/wiki/Autonomous_system_(Internet)
An AS (identified by an ASN) is an autonomous system. It's comprised of multiple CIDR blocks, contiguous regions of IP addresses. The network definition (by CIDR block) is fairly dynamic, as blocks can be added, deleted, or consolidated.
An autonomous system is a single administrative domain over public IP space. Essentially, autonomous systems are what the Internet is inter-networking between, through BGP (border gateway protocol). BGP and AS are what Cisco (and other router) gear are ultimately all about.
So yes: organisations typically have one AS. Exceptions are typically the result of corporate mergers (not uncommon) or government space (where the domains are large).
(Disclaimer: I'm not a networking bithead, don't muck with routers much, and have a rough knowledge of much of this, though it should be vaguely accurate.)
[1] http://www.tcpiputils.com/browse/as/32934 * note there are more than average ads on this site and it's a bit plain but this was the only one I could find that, with my brief searching, showed ip prefixes associated to the AS number.
If anyone has a better lookup tool that'd be great!
edit: Should also note that since other users are mentioning they might be under multiple AS number's maybe the ticket would be to setup a GitHub that collected these AS numbers for FB.
edit 2: found a less ad filled site! http://ipduh.com Search AS32934 click "prefixes" at top
You can also confirm this is the only ASN for Facebook by searching for Facebook at https://ipinfo.io/countries/us
$ curl ipinfo.io/`dig +short facebook.com | head -n1`
{
"ip": "69.171.230.68",
"hostname": "edge-star-mini-shv-17-prn1.facebook.com",
"city": "Menlo Park",
"region": "California",
"country": "US",
"loc": "37.4590,-122.1781",
"org": "AS32934 Facebook, Inc.",
"postal": "94025"
}
See https://ipinfo.io/developers for more detailscan I and how obtain this information myself, from the very source, for a given domain name or company or whatever it is?
AS information isn't trivially available, though you can do a pretty good job through tools like the CIDR Report and ASN Routeviews.
There are quite substantial portions of the Internet to which I'd generally provide very little or very limited access if I had my druthers.
Most of what you'd want is out there, but you might have to obtain it all and doing a bit of work to combine/correlate i all.
fdda274d380ki4frcgi-rumjfjai1460158783-sonar.xx.fbcdn.net
there are probably many more like that.I thought I was unreconcilably blocked for the duration of the hackathon, as DNS propagation disclaimers give itself 72 hours, and SSL certificates require who knows what.
I was able to get a completely new domain with Amazon Route 53 and Amazon's free SSL certificates in 20 minutes.
So yeah, I would say these blocklists are futile now, in OP's format.
definitely not ideal, not even complete, and requires work - BUT, nearly any Internet user can implement the solution done this way.
It would be really interesting to autogenerate the domain lists by running background scripts on AS numbers, polling DNS for every IP in the range, and cataloging the domains by script - say, daily, and then printing the list into a 0.0.0.0 prefixed hosts list. Thank you!
disclaimer: github user maintaining linked resource
For this, you can run dnsmasq and use the "--address" option or "address" command in dnsmasq.conf:
$ man dnsmasq
[...]
-A, --address=/<domain>/[domain/]<ipaddr>
Specify an IP address to return for any host in the given
domains. Queries in the domains are never forwarded and always
replied to with the specified IP address which may be IPv4 or
IPv6. To give both IPv4 and IPv6 addresses for a domain, use
repeated -A flags. Note that /etc/hosts and DHCP leases over‐
ride this for individual names. A common use of this is to redi‐
rect the entire doubleclick.net domain to some friendly local
web server to avoid banner ads. The domain specification works
in the same was as for --server, with the additional facility
that /#/ matches any domain. Thus --address=/#/1.2.3.4 will
always return 1.2.3.4 for any query not answered from /etc/hosts
or DHCP and not sent to an upstream nameserver by a more spe‐
cific --server directive.Dnsmasq can return nxdomain responses
echo 'server=/.example.tld/' >> /etc/dnsmasq.conf
Check dnsgate [2] or FreeContributor [3]
[1] https://www.dnsknowledge.com/whatis/nxdomain-non-existent-do...
https://secure.fanboy.co.nz/fanboy-antifacebook.txt
Disclaimer, list Author.
Just my humble opinion.
It depends on the purpose of the list, of course, but for me they're very different.
Across my various jobs, I've had to write reports for departments, and open up permissions to internal people, to give read access for things they'd have no natural reason to care about.
If data is being collected at all, weird people will be looking at it. If not today, maybe tomorrow. But, no matter when, it's there for the looking whenever some internal lookie-loo decides it might be interesting.
Many of the most unfortunate problems with these sites are social in nature rather than technical. For example, no matter how much I plead with people not to, they keep uploading information about me to these type of sites, including photographs with timestamps and GPS location metadata, which they then "tag" my face as being me.
I don't have any idea how much of this information is even out there, since these sites require signing up in order to find out. Maybe I should look into my rights under data protection legislation...
As far as concrete reasons go, I've had to deal with far too much fallout from being incorrectly flagged by braindead processes trawling private databases which I didn't even know I was in. Since lots of these databases share information, but not necessarily updated corrections, I still run into the same mis-flagging every few years, across utilities, courts, credit agencies, banks, letting agents, etc.
As far as Facebook goes, being a citizen of the CCTV-riddled UK makes me acutely aware of the power, and potential abuse, that facial recognition technology can bring; having images of my face tagged and fed into a database does not sit well with me.
Since I don't use Facebook, I don't even get the meagre upside of whatever services they build on top of this database (some kind of gallery, I presume).
Yes. Please check pi-hole project [1] or flash your router with open-wrt/dd-wrt and run dnsmasq with the FreeContributor lists.
do people usually do this directly on their FIOS router or is it easier to get a separate wifi router?
https://pi-hole.net/faq/can-i-set-the-pi-hole-to-be-the-dns-...
good stuff
Can anyone explain me why wildcard support for blocklists would require more performance?
Assuming it's just basic wildcards, not full regex.
Seems to me that 1) with wildcards you need to check less bytes per entry and 2) since the list itself will be shorter you need to check less entries.
Do any of these filtering tools compile the list (offline) to a minimal state machine or a trie? That would probably max performance (and benefits from wildcards too).
Lots of big infrastructures are pretty much put together like the internet.
curl https://raw.githubusercontent.com/jmdugan/blocklists/master/corporations/facebook/all | sudo tee -a /etc/hostsYou are a bad, bad man Mr Rochacon.
Why should I (we) block all facebook domains ?
http://www.theverge.com/2016/5/27/11795248/facebook-ad-netwo...
<sarcasm>It also 100% breaks your social life, but maybe there's little of that left to disrupt anyway, amongst the typical target audience for these lists :P</sarcasm>
This is factually incorrect. Just because you haven't personally seen people block Google domains doesn't mean those people don't exist. I've blocked many Google domains for a long time. Not only was GA the first domain in my blacklist, it's also the domain that many of my non-technical friends/family wanted blocked.
This may well have come up because of recent news that Facebook is stepping up it's targeting of people on the open web. https://news.ycombinator.com/item?id=11790976
Snowden has made it clear that that government grants itself direct access, whatever the legal situation really is.
It's also become clear that the government lets itself get away with it. And that there is no resistance from the voters who voted the politicians in and are paying not only for the politicians' salaries but also for their own total surveillance.
It looked like a good first step to tackling rampant privacy violation, but at the last moment the Information Commissioner caved in to bullshit claims that the ruling would cause the collapse of all Web businesses. The enforcement was changed from "not allowed unless opted-in" into "visiting a site counts as opting in".
The end result is not only completely ineffective, as it basically changes nothing; it's also resulted in the profileration of ridiculous "by using our site you agree to our use of cookies" messages, which just annoy without doing anything.
$ ASN=32934; for IP in 4 6; do \
whois -h riswhois.ripe.net \!${IP/4/g}as${ASN} |\
sed -n '2 p' | tr \ \\n | aggregate${IP/4/} |\
while read NET; do echo ip${IP/4/}tables -I OUTPUT -d ${NET} -j REJECT;\
done; done
(note this command uses echo to show the command it could execute)[1] aggregate http://packages.ubuntu.com/source/xenial/aggregate
[2] aggregate6 https://github.com/job/aggregate6
Also, many firewalls do a 1-time DNS lookup of a given FQDN to resolve a single IP address when a FQDN based rule is created. This doesn't work well if you have an FQDN that can resolve to many different IP's, which is typical for cloud services.
I usually open some time-wasting website when I'm waiting on some other tasks to finish and it's got so bad I do that even if the wait is <30sec, such is the addiction to these little useless rewards.
Now with a wait time on the time-wasting websites, maybe I could use this habit against itself and instead go do something else more productive while I wait.
facebookcorewwwi.onion
Might as well make it a complete block. Make sure those creative types don't find that last alternate path to FB.
https://raw.githubusercontent.com/jmdugan/blocklists/master/...
With uBO, a "facebook.com" entry in a hosts file will also cause all subdomains of "facebook.com" to also be blocked, so there is no need to list all subdomains as is done here if the goal is to block "facebook.com" with uBO.
If one wants to block Facebook via uBO, I personally advise to do it through dynamic filtering[1]. This way one can always point-and-click to create exceptions on a per-site basis.
[1] https://github.com/gorhill/uBlock/wiki/Dynamic-filtering:-to...
Does uBO optimize these cases, though? E.g. if there's "apps.facebook.com", "connect.facebook.net" and plain "facebook.com", does it collapse to just 1 filter (facebook.com)? I see it says "880 used out of 881" which is the number of entries in the file.
from my .zshrc:
#block Twitter, Facebook, reddit and Linkedin. alias on="sudo mv /etc/hostx /etc/hosts" alias off="sudo mv /etc/hosts /etc/hostx"
Wat?
Occam's razor, people.
I kind of wonder who exactly are the people telling everyone to block facebook everywhere while everyone seems to collectively ignore google.
Google and facebook seem to both purposely ignore the known implications of their data collection programs. They likely have handed over data to the NSA, and we know they sell the data.
Sounds a lot like "we know global warming is fake" and "we know vaccines are evil" to me.
No. In my view Google (has the potential to) collect a lot more sensitive data than Facebook. All Facebook knows is who my friends are and stuff like what things I like and where I've been - mostly things that I wouldn't mind being public anyway. Google knows everything I search for, every email I receive and every web page I visit.