Pi-hole: Dead default blocklist link

Created on 12 Jul 2019  路  5Comments  路  Source: pi-hole/pi-hole

In raising this issue, I confirm the following: {please fill the checkboxes, e.g: [X]}

How familiar are you with the the source code relevant to this issue?:

3


Expected behaviour:

Blocklist showing a list of hosts to block

Actual behaviour:

URL Shows ?php
echo "# ZeuS Tracker has been discontinued on Jul 8th, 2019";
exit();
?

Steps to reproduce:

Go to https://zeustracker.abuse.ch/byebye.php?download=domainblocklist

{Steps of what you have done to fix this}

Saw reddit post https://old.reddit.com/r/pihole/comments/ccfxom/one_of_default_blocklists_is_dead_another_outdated/

Checked URL https://zeustracker.abuse.ch/byebye.php?download=domainblocklist
Site shows
?php
echo "# ZeuS Tracker has been discontinued on Jul 8th, 2019";
exit();
?

Confirmed Issue

Most helpful comment

Yes. Just as an idea: How about adding the lists, which are avaiable to pihole as default?

  • Feodo Tracker
    Feodo Tracker is a project of abuse.ch with the goal of sharing botnet C&C servers associated with the Feodo malware family (Dridex, Emotet/Heodo). It offers various blocklists, helping network owners to protect their users from Dridex and Emotet/Heodo.
  • Ransomware Tracker
    Ransomware Tracker offers various blocklists. These blocklists allows enterprises to block malicious traffic towards known Ransomware infrastructure at the network edge, e.g. by blocking them on the corporate firewall, web proxy or in the local DNS server. As any data provided by Ransomware Tracker are being offered for free (incl. the blocklists), antivirus vendors and vendors of security solutions may also implement Ransomware Tracker blocklists within their products.
  • SSL Blacklist (SSLBL)
    The SSL Blacklist (SSLBL) is a project of abuse.ch with the goal of detecting malicious SSL connections, by identifying and blacklisting SSL certificates used by botnet C&C servers. In addition, SSLBL identifies JA3 fingerprints that helps you to detect & block malware botnet C&C communication on the TCP layer.
  • URLhaus
    URLhaus is a project from abuse.ch with the goal of sharing malicious URLs that are being used for malware distribution.

All 5 comments

Error 503 Backend unavailable, connection failed
Backend unavailable, connection failed

Guru Mediation:
Details: cache-fra19128-FRA 1566323403 1387466377

I Think the Server is up again?

The list is no longer 503 but it is empty so there's no need to include it.

Yes. Just as an idea: How about adding the lists, which are avaiable to pihole as default?

  • Feodo Tracker
    Feodo Tracker is a project of abuse.ch with the goal of sharing botnet C&C servers associated with the Feodo malware family (Dridex, Emotet/Heodo). It offers various blocklists, helping network owners to protect their users from Dridex and Emotet/Heodo.
  • Ransomware Tracker
    Ransomware Tracker offers various blocklists. These blocklists allows enterprises to block malicious traffic towards known Ransomware infrastructure at the network edge, e.g. by blocking them on the corporate firewall, web proxy or in the local DNS server. As any data provided by Ransomware Tracker are being offered for free (incl. the blocklists), antivirus vendors and vendors of security solutions may also implement Ransomware Tracker blocklists within their products.
  • SSL Blacklist (SSLBL)
    The SSL Blacklist (SSLBL) is a project of abuse.ch with the goal of detecting malicious SSL connections, by identifying and blacklisting SSL certificates used by botnet C&C servers. In addition, SSLBL identifies JA3 fingerprints that helps you to detect & block malware botnet C&C communication on the TCP layer.
  • URLhaus
    URLhaus is a project from abuse.ch with the goal of sharing malicious URLs that are being used for malware distribution.

@xopez The links you listed seem very promising. Are there available versions that Pi-Hole is able to parse them?

Was this page helpful?
0 / 5 - 0 ratings

Related issues

cmonty14 picture cmonty14  路  3Comments

robotsandcake picture robotsandcake  路  5Comments

z3to picture z3to  路  4Comments

agietl picture agietl  路  6Comments

pgl picture pgl  路  5Comments