Block Adware and Malware with /etc/hosts
github.com
github.com
Interestingly, from what I remember of the April Fools columns of electronics magazines of the time, one thing that people would not have been surprised by is that the purpose was zapping advertisements.
* https://worldradiohistory.com/UK/Electronics-Today-UK/80s/El...
FWIW, something like ublock origin is going to be better for in-browser blocking (for example, DNS poisoning won't work with youtube ads, which are served from youtube.com, but addins like UBO can remove them because they can hook into the actual traffic).
The ultimate adblocking solution is to use UBO in your browsers AND spin up a pihole to block ads on your entire network: https://pi-hole.net/
edit: HN is actually erroring out if I post an example .zip domain of the problem
[1] https://medium.com/@bobbyrsec/the-dangers-of-googles-zip-tld...
If I don't bother hovering over the link then the domain never mattered at all. Could have hosted the file anywhere since the link text in HTML (including HTML email) need not have any relation to the destination. You can simply write a legitimate github.com link but the href goes somewhere else.
Any situation where you're relying on users to visually inspect every link and decide if the domain looks plausible is already a security failure.
If I'm downloading and executing files that are randomly in a Medium article or in my inbox from an untrusted source then we're in trouble whether they are hosted on github or not.
How do you hover on mobile? Instead of training my family members to hover on their phone's I will continue to just block these TLDs.
I'm advocating using a pi-hole to block problematic domains on your network using list like the one from StevenBlack and entire TLDs that could be confusing. If you don't think .zip & .mov could be confusing then feel free to not block them.
E.g. "example.com" becomes "<a href="http://example.com/">example.com</a>".
Such features would now (potentially) also work on mentions of zip files, i.e. on messages that state "download install.zip from github".
Edit: ghi, HN actually does this. Not yet with zip TLDs though.
To me this attack sounds too convoluted to actually get people, since you'll need to buy a lot of domains to match someone's email's contents
testlink.com link.gov abc.zip test.xyz
I agree about being able to hyperlink pretty much anything having the same effect, that's why I don't think the .zip TLD is a big issue
When my Pi stopped working and I couldn’t find a new one, I gave up and moved to NextDNS [1] and have been very happy.
grep -v '#' steves_hosts | awk '{print $1}'| sort | uniq -c
[1] https://news.ycombinator.com/item?id=11456562 190625 0.0.0.0
3 127.0.0.1
1 255.255.255.255
3 ::1
1 fe80::1%lo0
2 ff00::0
1 ff02::1
1 ff02::2
1 ff02::3* https://porkmail.org/era/unix/award#grep
awk '!/#/ { seen[$1]++; } END { for (k in seen) { print seen[k],k; } }' steves_hostsAlso your awk isn't exactly identical as it's not sorted, but in this case that probably doesn't matter.
That's even if you end up sorting the output by frequency, as the summary listing is typically shorter than the overall input data:
{a[$1]++}
END {for (i in array) printf("%6i %s\n", a[i], i) | "sort -k1nr | cat -n";}
The accumulator/loop idiom is ... fairly readily recognisable to someone familiar with awk. find . -name hosts -exec grep -v '^#' {} \; | awk '{print $1}'| sort | uniq -c
43029
204 #
4289934 0.0.0.0
10763 127.0.0.1
18 255.255.255.255
54 ::1
1 analytics.shein.co.uk
1 analytics.shein.com
1 auxilium.ftb.team
1 bstats.org
1 fe00::0
17 fe80::1%lo0
33 ff00::0
17 ff02::1
17 ff02::2
17 ff02::3
1 mcmc.dev
1 mcstats.org
1 metrics.shmeeb.net
1 openeye.openmods.info
And looking at those last ones, looks like some files have a different format. For example, the data/minecraft-hosts/hosts file, ~/D/P/hosts master grep -irn 'openeye.openmods.info' .
./alternates/fakenews/hosts:174307:0.0.0.0 openeye.openmods.info
...
./hosts:174306:0.0.0.0 openeye.openmods.info
./data/minecraft-hosts/hosts:9:openeye.openmods.info
~/D/P/hosts master grep -irn 'metrics.shmeeb.net' .
...
./data/minecraft-hosts/hosts:8:metrics.shmeeb.netForgot about it for a few years, but this post jogged my memory.
We currently use a PiHole for house-wide, network-wide ad and telemetry blocking, though, but perhaps that hosts list is useful to someone else.
(Edit: typo)
Slashdot has a, shall we say _engaged_, community.
They could not wrap their head around the idea that the hosts method is limited in some use cases.
This could not be blocked without blocking the main host too. https://example.com/adverts-folder/advert.jpg
Now it sort of works in practice as most of the advert networks do not host on the same domain.
It is good at catching out whole bad domains but partial ones it is not very good at. Which some domains will do using a reverse proxy.
Also at one point a hosts file was linear scan. No sort of hashing or binary search lookup. Not sure if that was ever fixed in windows or linux. So a small number of hosts it was ok. But as the file grows it starts to add up.
What a strange place that was.
https://en.wikipedia.org/wiki/Feist_Publications,_Inc.,_v._R....
And https://mayakron.altervista.org/support/acrylic/Home.htm works as well, and it also accepts wildcards.
I'm happy to answer any questions arising.
I must say: the lists we offer — 31 variants in all — result from fine work by all our curators. Some are extremely diligent and maintain their lists every day. It's just remarkable what dedicated people can do together over time.
https://www.obdev.at/products/littlesnitch-mini/index.html
Sure, you could manage /etc/hosts manually, but Little Snitch Mini has a nice interface for managing blocklists, auto-updates them, and has nice visualization, and you can also manage blocks per app.
The UDP:53 block gets almost everything, but I'm preparing for DoH.
If you can manage it, a pihole/pivpn instance may be better. Both of those can be installed on any debian distro easily.
Don't forget about hosts.deny (but you probably need it at your router if you are behind one).
regardless, after using this list for a long time, i do recommend setting up your own dns server or use a service that does (such as pi-hole and nextdns already suggested by others) with this list enabled.
on mobile, i found that ad-blocking dns services that offer DNS-over-HTTPS (such as adguard dns) offer a much more elegant option that does not require an app nor configuring every network you connect to.
[1] https://tinyapps.org/blog/201809300700_large_hosts_file.html
99% of people don't understand (because they don't even try) what you can run a full resolver even on Windows machines. butmuhpihole