Using a Hosts File To Make The Internet Not Suck As Much
someonewhocares.org
someonewhocares.org
~/tmp% grep -v "^[[:space:]]*#" fred.txt | grep -v "^[[:space:]]*$" | grep -v 127.0.0.1
books
guestbook
hosts
text file
rss feed
0.0.0.0
0 text file
old macs
0 old macs
math links
origami
photos
polls
siteoftheday
home
Hosted by:
theorem.ca
how to make the internet not suck (as much)
255.255.255.255 broadcasthost
::1 localhost
fe80::1%lo0 localhost
Fri Feb 22 08:05:36 2013top
~/tmp%
And I just realised now that the junk at the top of the output comes from me doing a Select All on the web page to highlight everything first, and it picked up the headers! Ooops. So there's in fact 3 non-comment lines that don't refer to localhost. [~]$ cat hosts_example.txt | grep -v '#' | awk '{print $1}'| sort | uniq -c
56
1 ::1
9674 127.0.0.1
1 255.255.255.255
1 fe80::1%lo0Honestly, there's no need for this stuff in the age of browser based ad blocking. I gave up on it when I saw how easy it was to write rules and wildcards in ad block plus. Interest in it fell. I'm surprised to see one still maintained.
And the majority of host names there are for tracking and ad sites.
And the majority of host names below them are for tracking and ad sites.
With the exception of "The" the titling is just a proper use of titling case. Do you find it annoying to read newspapers? I imagine it is the awkward phrasing that you (and I) find annoying.
Just something to think about when using massive hosts files.
It's true there is an up-front cost paid when first loading it, and for the initial domain lookups. After initial lookups, DNS cache takes over.
The real benefit comes because countless requests for ads, tracking scripts and counters, etc, never leave your box. Network traffic is greatly reduced.
A comprehensive hosts file dramatically improved the performance of a relative's dialup internet connection a few years ago. A web that was borderline unusable became much snappier. And web pages had almost no ad adornments.
So on balance this is a very good thing. YMMV.
But this kind of thing doesn't give your average government nearly enough power. So: not interested.
(Plug for own site with similar stuff): http://pineapple.io/resources/gas-mask
Gas mas direct link: https://code.google.com/p/gmask/
It looks to be very useful so hopefully I can get it working sometime soon or at least be able to provide some crash feedback.
$ curl --connect-timeout 5 -v 192.0.2.1
* About to connect() to 192.0.2.1 port 80 (#0)
* Trying 192.0.2.1...
* Connection timed out after 5011 milliseconds
* Closing connection 0
curl: (28) Connection timed out after 5011 milliseconds
So your browser will likely end up trying the connection and timing out after a while.Several commenters appear not to "get" the benefit of a comprehensive and recent hosts file.
With a good hosts file, many well-known trojans and viruses can't phone home.
Interesting that something that looks to have taken a fair bit of work and is moderately useful hasn't had a comment on it.
Generally, I enjoy not seeing all the ads, but some sites (Slickdeals, I'm looking at you) make such extensive use of affiliate and ads sites that it makes the site barely useable. For slickdeals I ended up making a Chrome extensions that finds URL encoded URLs within a query parameter and redirects to that site directly instead of the affiliate link.
Google DNS, Level 3 DNS can't shake a stick at my local cache, which is off course to be expected.
dnsmasq.conf needs to point to the DNS server you wish to use resolv.conf needs a line "nameserver 127.0.0.1" or whatever IP dnsmasq is listening on.
Make sure dnsmasq is started at boot, and that your resolv.conf isn't overwritten by your dhcp client, and you're good to go. Further configuration needs to done to make dnsmasq provide authoritative answers for other domains.
If you don't need caching, then use adsuck (linked it in my previous comment in this thread).
I run unbound, I don't have a tutorial or anything like that, mainly because I don't know what OS you are running or where you want to do this.
My personal unbound also connects to a locally hosted nsd, which is used to host the zone network.lan. On network.lan is where all of my hosts live, it is where I have entries for various of my internal servers, as well as all of my test sites.
edit: Looking through the current version of the host file, it appears google analytics and some other "non-nefarious" tracking sites are commented out.
I also have a webserver that any black holed domain is sent to so that there is no waiting for a web request to time out. The first time I put it in place I didn't have the webserver so the performance when hitting one of these was horrible. I also use it for any ad server or analytic site I want to permanently block.
This way I don't have to distribute and update a hosts file to every machine in the house and I control where the offending sites redirect too.
I have been creating master zones on my named.conf and pointing them to a blocked.txt file. My method is more cumbersome, the one you linked is very streamlined. Excellent, and thanks!
First, create a zone file that all of the domains will share. I put mine in /var/named/master/dummy:
$TTL 1d
@ IN SOA ns1.localdomain. hostmaster.ns1.localdomain. (
2012100601 ; serial
8h ; refresh
2h ; retry
7d ; expire
1h ; default_ttl
)
;
; Name servers
;
@ IN NS ns1.localdomain.
@ IN NS ns2.localdomain.
;
; Host addresses
; Leave commented to return NXDOMAIN
; Uncomment to resolve to IP address
;@ IN A 127.0.0.1
I prefer not resolve these hosts at all (NXDOMAIN), because it seems to be faster and I don't want client machines to probe themselves, but you can uncomment the A record and use whatever IP address you want (e.g. for sinkhole monitoring). Remember to increment the serial number with every edit (which will be rare or never, once you've set it to your liking).Next, create a simple file with each domain you want to block on one line. I put mine in /var/named/dummy:
ads.example.com
tracker.example.com
example.org
Now create a conf file in the format bind expects, pointing every domain to the zone file (for convenience, put this in /var/named/Makefile in a 'dummy' target): sed 's/.*/zone "&" { type master; file "master\/dummy"; };/' < dummy > dummy.conf
Which will result in /var/named/dummy.conf containing: zone "ads.example.com" { type master; file "master/dummy"; };
zone "tracker.example.com" { type master; file "master/dummy"; };
zone "example.org" { type master; file "master/dummy"; };
Finally, add to your named.conf: include "/var/named/dummy.conf";
Restart bind and you're now authoritative for those zones on your network!One of these days I'm gonna roll my own DNS server in Python with a sane configuration syntax.
edit: I'll also add that this host file blocks adds on youtube, and pandora (and probably several others). I never wait for ads there anymore.
There is one thing I do miss: being able to log requests and seeing which domains were accessed the most.
Facebook and Twitter buttons on the other hand - sorry guys, you stay blocked.
It's actually an email service now. hello.jpg is gone.
... But damn, that would have been clever back in the day. Thumbs up!