blocklistproject / lists Goto Github PK
View Code? Open in Web Editor NEWPrimary Block Lists
License: The Unlicense
Primary Block Lists
License: The Unlicense
URL you wish to be removed: cdn.cookielaw.org
Why you believe this to be a false positive: it's about regulations/complience
List it is on: gambling
Other info you think we should know:
URL you wish to be removed: www.secured-login.net, secured-login.net
Why you believe this to be a false positive: This is a domain owned and operated by KnowBe4, a security awareness company. This domain is used by companies to launch authorized phishing simulations and is not actually a fradulent site.
List it is on: fraud
Other info you think we should know:
URL you wish to be removed: gstaticadssl.l.google.com
Why you believe this to be a false positive: This is where Google Fonts are served from. (fonts.gstatic.com is a CNAME redirect to this).
List it is on: ads, malware
Other info you think we should know:
URL you wish to be removed: newrelic.com
Why you believe this to be a false positive: https://js-agent.newrelic.com/nr-spa-1169.min.js is needed for website.grader.com
List it is on: tracking
Other info you think we should know:
URL you wish to be removed: downloads.intercomcdn.com
Why you believe this to be a false positive: Part of support solution
List it is on: malware
Other info you think we should know:
nyt5-assets.prd.map.nytimes.com
static.prd.map.nytimes.com
This is the fonts and static assets (like images) for the NY Times.
Ads
Here's the output of dig
when the list is not active:
; <<>> DiG 9.14.2 <<>> g1.nyt.com
;; global options: +cmd
;; Got answer:
;; ->>HEADER<<- opcode: QUERY, status: NOERROR, id: 24963
;; flags: qr rd ra; QUERY: 1, ANSWER: 6, AUTHORITY: 0, ADDITIONAL: 1
;; OPT PSEUDOSECTION:
; EDNS: version: 0, flags:; udp: 512
;; QUESTION SECTION:
;g1.nyt.com. IN A
;; ANSWER SECTION:
g1.nyt.com. 227 IN CNAME nyt5-assets.prd.map.nytimes.com.
nyt5-assets.prd.map.nytimes.com. 80 IN CNAME nytimes.map.fastly.net.
nytimes.map.fastly.net. 29 IN A 151.101.1.164
nytimes.map.fastly.net. 29 IN A 151.101.65.164
nytimes.map.fastly.net. 29 IN A 151.101.129.164
nytimes.map.fastly.net. 29 IN A 151.101.193.164
;; Query time: 3415 msec
;; SERVER: <local pihole>
;; WHEN: Wed Aug 05 13:52:45 Mountain Daylight Time 2020
;; MSG SIZE rcvd: 181
Please can you remove ipinfo.io? It is a platform to access IP address data, it is not a tracking platform.
URL you wish to be removed: hwcdn.net
Why you believe this to be a false positive: It's needed for legit sites like criticker.com to work
List it is on: ads
Other info you think we should know:
URL you wish to be removed:
http://stackpathcdn.com/
http://stackpathcdn.com/
http://www.stackpath.com/
Why you believe this to be a false positive:
Please be advised that the domains listed are legitimate domains that are registered to StackPath a content delivery network (CDN)
List it is on:
ads.txt
gambling.txt
Other info you think we should know:
the youtube list breaks youtube on all devices
URL you wish to be removed: www.peopleperhour.com
Why you believe this to be a false positive: This is a false positive because PeoplePerHour is a legitimate website that connects freelancers with employers.
List it is on: Fraud
Other info you think we should know: Check PPH's Google information panel by googling it
URL you wish to be removed: byside.com
Why you believe this to be a false positive: This is used for chat, for example on ikea.com
List it is on: Tracking
Other info you think we should know:
URL you wish to be removed: *.gigya.com
Why you believe this to be a false positive: It's needed to be able to sign in on manutd.com
List it is on: Tracking
Other info you think we should know:
URL you wish to be removed: llnwd.net
Why you believe this to be a false positive: Standard query response 0xb230 No such name A www.nintendo.de CNAME nintendoeu-1.hs.llnwd.net
List it is on: ads.txt
Other info you think we should know: Please do not block entire domain. This will only increase the false positive. The owner of llnwd.net is Limelight Networks a CDN Service Provider. By Blocking this domain you also block Nintendo (EU), BubbleUP and DailyMotion.
I noticed this blocklist in gambling.txt
. It's an ads and trackers blocklist so I think ads.txt
would be a more appropriate place for it to be included.
URL you wish to be removed: tns-sifo.se
Why you believe this to be a false positive: It's for surveys
List it is on: Ads and Tracking
Other info you think we should know:
URL you wish to be removed: us-east-1-a.route.herokuapp.com
Why you believe this to be a false positive: it is a cname for learning-machines.herokuapp.com which is a website about machine learning using rust
List it is on: ads.txt
Other info you think we should know: It is also the cname for over 8000 other domains, a large amount of which are of the format direwolf-[0-9a-f]{10}.herokuapp.com, but some are other formats, and not all are subdomains of herokuapp.com. I don't know whether these domains should be blocked, just thought it might be useful to mention
URL you wish to be removed:
www.adsbexchange.com
Why you believe this to be a false positive:
It is a co-op of ADS-B/Mode S/MLAT feeders (think FlightRadar24 or FlightAware)
List it is on:
ads
Other info you think we should know:
URL you wish to be removed: hubspot.com
Why you believe this to be a false positive: Used for website.grader.com to work
List it is on: tracking
Other info you think we should know:
URL you wish to be removed: js.intercomcdn.com
Why you believe this to be a false positive: It's part of support solution
List it is on: ads
Other info you think we should know:
The use of raw.githubusercontent URLs is considered bad form for PiHole since it will re-download the list every time it updates. you should set up a GitHub Pages site and then use those URLs to point to the lists. This will include the last-modified data in the header preventing PiHole from pulling the list if nothing has changed. The addresses for the lists would then be similar to:
https://blocklistproject.github.io/Lists/Malware
These are smaller URLs as well which are easier to read on the web interface (while also reducing wear on an SD card for PiHole hosted on actual Raspberry Pi hardware due to not downloading unless there are changes). This would not break anyone that is currently using the raw.githubusercontent URLs, but would provide a better source for anyone that wants to change them over as well as new users.
More Information:
https://discourse.pi-hole.net/t/i-concatenated-every-blocklist-i-could-find/5184/2
https://docs.github.com/en/github/working-with-github-pages/creating-a-github-pages-site
URL you wish to be removed: api-iam.intercom.io
Why you believe this to be a false positive: Part of support software
List it is on: ads
Other info you think we should know:
URL you wish to be removed: s-media-cache-ak0.pinimg.com
Why you believe this to be a false positive:
s-media-cache-ak0.pinimg.com blocks access to https://s-media-cache-ak0.pinimg.com/originals/28/86/42/288642dec69cb52611e17a2afadc940e.jpg. That url redirects to https://i.pinimg.com/originals/28/86/42/288642dec69cb52611e17a2afadc940e.jpg which isnβt blocked, and is just an image from a video game.
The original url is found in duckduckgo image search results: View file at https://duckduckgo.com/?t=ffab&q=arvak&iax=images&ia=images&iai=https%3A%2F%2Fs-media-cache-ak0.pinimg.com%2Foriginals%2F28%2F86%2F42%2F288642dec69cb52611e17a2afadc940e.jpg
List it is on: ads.txt
Other info you think we should know:
Update Info field description to "Ransomware List"
Currently, it is showing "Redirect list"
URL you wish to be removed: widgetdata.tradingview.com
s.tradingview.com
s3.tradingview.com
Why you believe this to be a false positive: Those are needed to display graphs on investopedia such as https://www.investopedia.com/markets/quote?tvwidgetsymbol=aapl
List it is on: ads.txt
Other info you think we should know:
The instructions for Pi-Hole reference a table that does not appear to be in the readme.md file.
Help link is currently https://github.com/blocklistproject/list/wiki/, when it should be https://github.com/blocklistproject/Lists/wiki/ or https://github.com/blocklistproject/lists/wiki/
URL you wish to be removed: bbci.co.uk
Why you believe this to be a false positive: This is BBC
List it is on: Ads
Other info you think we should know:
URL you wish to be removed: www.youtube-nocookie.com
Why you believe this to be a false positive: It's Youtube
List it is on: Ads
Other info you think we should know:
URL you wish to be added: http://globalsending.top http://ww25.sentforyou.com
Why you believe this to be a false positive: are pishing pages
List it is on: not listing
Other info you think we should know: sent spam pishing mails on Mexican bank
URL you wish to be removed: wpc.v0cdn.net
Why you believe this to be a false positive: It's needed for legitimate site tele2.se to work
List it is on: ads
Other info you think we should know:
URL you wish to be removed: intercomassets.com
Why you believe this to be a false positive: Part of a support solution
List it is on: tracking
Other info you think we should know:
URL you wish to be removed: 0.0.0.0 div>Hosted On GitHub
Why you believe this to be a false positive: I was using this blocklist as a source for a firewall solution to drop torrent websites DNS packets. Having that line on the file caused DNS requests to github.com to be dropped. That line sounds like a defect which demanded me to stop using this blocklist on my firewall. Can't trust this list anymore.
List it is on: https://github.com/blocklistproject/Lists/blob/master/torrent.txt#L1853
Other info I think you should know: this is a good blocklist and I intend to keep using it, but can't set my code to auto-fetch it and use it as a valid source due to this issue.
URL you wish to be removed: footprint.net
Why you believe this to be a false positive: Needed for http://telefoni.prisjakt.nu/mobil/cellular_contracts.php to work
List it is on: tracking
Other info you think we should know:
Hi,
Some of the folders on the main site are empty
So the links on the main site won't redirect
https://blocklist.site/app/dl/ransomeware/
https://blocklist.site/app/dl/spam/
etc.
URL you wish to be removed: users.telenet.be
Why you believe this to be a false positive: It blocks access to http://users.telenet.be/MySQLplaylist/pi-hole.pdf which is a pdf about using Pi-Hole
List it is on: malware.txt
Other info you think we should know:
URL you wish to be removed: multple yandex.ru subdomains. Also I saw some other yandex domains which can be legit
Why you believe this to be a false positive: Yandex is like a google in Russia. their domains can be related to tracking, ads but not gambling.
List it is on: gambling
Other info you think we should know:
gambling.txt:# [yandex.ru]
gambling.txt:0.0.0.0 adfox.yandex.ru
gambling.txt:0.0.0.0 matchid.adfox.yandex.ru
gambling.txt:0.0.0.0 adsdk.yandex.ru
gambling.txt:0.0.0.0 advertising.yandex.ru
gambling.txt:0.0.0.0 an.yandex.ru
gambling.txt:0.0.0.0 redirect.appmetrica.yandex.ru
gambling.txt:0.0.0.0 awaps.yandex.ru
gambling.txt:0.0.0.0 awsync.yandex.ru
gambling.txt:0.0.0.0 bs.yandex.ru
gambling.txt:0.0.0.0 bs-meta.yandex.ru
gambling.txt:0.0.0.0 clck.yandex.ru
gambling.txt:0.0.0.0 informer.yandex.ru
gambling.txt:0.0.0.0 kiks.yandex.ru
gambling.txt:0.0.0.0 grade.market.yandex.ru
gambling.txt:0.0.0.0 mc.yandex.ru
gambling.txt:0.0.0.0 metrica.yandex.ru
gambling.txt:0.0.0.0 metrika.yandex.ru
gambling.txt:0.0.0.0 click.sender.yandex.ru
gambling.txt:0.0.0.0 share.yandex.ru
gambling.txt:# 0.0.0.0 clck.yandex.ru
gambling.txt:# 0.0.0.0 grade.market.yandex.ru
gambling.txt:0.0.0.0 ms.yandex.ru
URL you wish to be removed: files.fm
Why you believe this to be a false positive: This is a normal upload site
List it is on: malware
Other info you think we should know:
URL you wish to be removed:
postfinance.ch
Why you believe this to be a false positive:
postfinance.ch belongs to PostFinance (https://www.postfinance.ch) a Swiss bank and it should therefore not be on the phishing list. There is one additional A record but the IP address belongs to Post CH AG, the parent company of PostFinace.
; <<>> DiG 9.16.3-Debian <<>> postfinance.ch
;; global options: +cmd
;; Got answer:
;; ->>HEADER<<- opcode: QUERY, status: NOERROR, id: 25882
;; flags: qr rd ad; QUERY: 1, ANSWER: 2, AUTHORITY: 0, ADDITIONAL: 0
;; WARNING: recursion requested but not available
;; QUESTION SECTION:
;postfinance.ch. IN A
;; ANSWER SECTION:
postfinance.ch. 0 IN A 194.41.166.40
postfinance.ch. 0 IN A 194.41.226.24
;; Query time: 90 msec
;; SERVER: 172.31.64.1#53(172.31.64.1)
;; WHEN: Sat Jun 20 06:56:32 CEST 2020
;; MSG SIZE rcvd: 78
; <<>> DiG 9.16.3-Debian <<>> www.postfinance.ch
;; global options: +cmd
;; Got answer:
;; ->>HEADER<<- opcode: QUERY, status: NOERROR, id: 34831
;; flags: qr rd ad; QUERY: 1, ANSWER: 1, AUTHORITY: 0, ADDITIONAL: 0
;; WARNING: recursion requested but not available
;; QUESTION SECTION:
;www.postfinance.ch. IN A
;; ANSWER SECTION:
www.postfinance.ch. 0 IN A 194.41.226.24
;; Query time: 190 msec
;; SERVER: 172.31.64.1#53(172.31.64.1)
;; WHEN: Sat Jun 20 06:56:38 CEST 2020
;; MSG SIZE rcvd: 70
List it is on: phishing.txt
Other info you think we should know:
[i] Target: https://raw.githubusercontent.com/blocklistproject/Lists/master/malware.txt
[β] Status: Retrieval successful
[i] Received 718213 domains, 245011 domains invalid!
Sample of invalid domains:
- -sso.anbtr.com"
- 0-07.ru"
- 0-day.us"
- 000001.ink"
- 00005ik.rcomhost.com"
example from the raw list:
0.0.0.0 " rapidshare2download.net"
URL you wish to be removed: cs11.wpc.v0cdn.net
Why you believe this to be a false positive: The Pi-hole is blocking Windows-Updates cause of this domain:
If it is needed for Windows-Updates it's probably not ads.
List it is on: ads
Other info you think we should know: Other Windows-Update-servers may be blocked cause of this too.
URL you wish to be removed:
ljudochbild.se
Why you believe this to be a false positive:
This is a legitimate site
List it is on:
malware
Other info you think we should know:
URL you wish to be removed: widget.intercom.io
Why you believe this to be a false positive: Used for chat software
List it is on: ads
Other info you think we should know:
Wondering which TLD this record belongs to:
appledetails.u
from this file https://github.com/blocklistproject/Lists/blob/master/phishing.txt?raw=true
URL you wish to be removed: browser.pipe.aria.microsoft.com, mobile.pipe.aria.microsoft.com, nexusrules.officeapps.live.com, nexus.officeapps.live.com
Why you believe this to be a false positive: it is tracking, not gambling
List it is on: gambling
Other info you think we should know:
URL you wish to be removed: s-imp.rmp.rakuten.com, s-bid.rmp.rakuten.com listed in gambling should be ads
Why you believe this to be a false positive: It is ads, not gambling
https://www.mysysadmintips.com/windows/home-and-media/802-remove-ads-from-viber-desktop
List it is on: gambling
Other info you think we should know:
URL you wish to be removed: yospace.com
Why you believe this to be a false positive: It's used for streaming, for example on comhemplay.se
List it is on: tracking
Other info you think we should know:
A declarative, efficient, and flexible JavaScript library for building user interfaces.
π Vue.js is a progressive, incrementally-adoptable JavaScript framework for building UI on the web.
TypeScript is a superset of JavaScript that compiles to clean JavaScript output.
An Open Source Machine Learning Framework for Everyone
The Web framework for perfectionists with deadlines.
A PHP framework for web artisans
Bring data to life with SVG, Canvas and HTML. πππ
JavaScript (JS) is a lightweight interpreted programming language with first-class functions.
Some thing interesting about web. New door for the world.
A server is a program made to process requests and deliver data to clients.
Machine learning is a way of modeling and interpreting data that allows a piece of software to respond intelligently.
Some thing interesting about visualization, use data art
Some thing interesting about game, make everyone happy.
We are working to build community through open source technology. NB: members must have two-factor auth.
Open source projects and samples from Microsoft.
Google β€οΈ Open Source for everyone.
Alibaba Open Source for everyone
Data-Driven Documents codes.
China tencent open source team.