TuM'Fatig – Ads blocking with OpenBSD unbound(8)
tumfatig.net
tumfatig.net
Be vary of using such sources.
Go to the source [0], make "Display: 100" and scroll to "1,351 to 1,450 of 10,000,000 websites".
You will find a bunch of bullshit domains clearly used for something nefarious (and some no longer exists), but to believe what those sites are as popular as spreadsheets.google.com? NO WAI
Tiny sample for the lazy:
1,361 ecoquipo.ga 5.92/10 ga
1,362 h4uvpev4tx.ga 5.92/10 ga
1,363 lfsni36qvn.ga 5.92/10 ga
1,364 dashseo.ga 5.92/10 ga
1,365 velocityconf.com 5.92/10 com
1,366 filezilla-project.org 5.92/10 org
1,367 bx2vnequhc.ga 5.92/10 ga
1,368 incblizzard.ga 5.92/10 ga
1,369 anisima.ru 5.92/10 ru
1,370 ou14ib22tf.ga 5.92/10 ga
1,371 i12tfukfft.ga 5.92/10 ga
1,372 blankmedia.ga 5.92/10 ga
1,373 nicelia.ga 5.92/10 ga
1,374 finlandtoday.fi 5.92/10 fi
1,375 spreadsheets.google.com 5.92/10 com
[0] https://www.domcop.com/top-10-million-domainsBut it is not 400k hosts to search:
com
facebook
www
ad
google
ad
ads
notadswepromise
googletagmanager
tags
ads
to block ad.facebook.com you only need to scan 10-100k of .com domains in your block list and only a couple of records in facebook.com. Don't forget, DNS is a hierarchical system. And we, humans, actually record, use and remember all the DNS records in the wrong, reverse direction ;-)> 400K hosts
I bet 30% of those hosts are don't resolve anymore and another 30% resolve to domain parking/404 hosts.
Eg: see my comment about "TOP 10M SITES"
I've seen some evidence of this. I periodically dig all the blocked domains and noticed that some of them come and go so I assume people cycle them in and out to evade blocking. A handful of the domains just change the A record so I just block the apex domain which makes it a little harder to keep the block lists optimized but does reduce the size a little.
I should add that blocking the apex of some domains includes risk of dropping legit traffic but if I see more than {n} badware domains on the apex, I write it off as compromised or at very least poorly implemented and poorly secured.
We'd optimally want, e.g., aaa.ai to resolve as fast as zzz.zx. If we just loaded the file for every query and ran down the list linearly we'd probably see a large disparity with the former being much quicker than the latter.
So, the question would be: how is it done in an efficient way? Is it loaded into a btree, is each domain broken into various parts, are certain domains prioritized, threading, compression?
Plus, there's the queries for dns updates, and how the results get integrated.
Not sure how out of date that is
Also, why use ftp instead of curl?[1]
https://pgl.yoyo.org/adservers/
basicly all it is is
include: /var/unbound/etc/yoyo.conf
where yoyo.conf is a dns blacklist- https://pgl.yoyo.org/as/serverlist.php?hostformat=unbound
Remove the header with &showintro=0 and for plain text, use &mimetype=plaintext:
- https://pgl.yoyo.org/as/serverlist.php?hostformat=unbound&mi...
Unfortunately for me the Unbound package on Alpine is not compiled for DoH, only DoT and I am too lazy to recompile things any more.
So we are back to the ISP's router, no VLAN and soon some Wireguard overlay for my hosting.
I'm sad about this: replacing infrastructure I control with the ISP invading my home, replacing tailor-made with generic consumer products, replacing native Internet with yet another overlay network... But MTTR rules my world.
https://nlnetlabs.nl/projects/unbound/about/
but yes it was made to avoid a bind monoculture. and comes in two parts nsd is the authoritive name server. and unbound is a recursive name server.