Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

For those of us - myself included - who run a hosts file list (either using dnsmasq like Pi-hole or directly), here are the sources that Pi-hole use so you can add to your own solution:

https://github.com/pi-hole/pi-hole/blob/master/adlists.defau...

There's a few on there I don't use and will look to implement. There's also a few they seem to have missed (perhaps intentionally?) so below I have included the lists I use in case it's useful for anyone else:

   http://someonewhocares.org/hosts/hosts
   http://winhelp2002.mvps.org/hosts.txt
   http://adaway.org/hosts.txt
   http://pgl.yoyo.org/adservers/serverlist.php?hostformat=hosts&showintro=0&mimetype=plaintext&useip=127.0.0.1
   https://raw.githubusercontent.com/StevenBlack/hosts/master/data/StevenBlack/hosts
   http://www.malwaredomainlist.com/hostslist/hosts.txt
   http://www.montanamenagerie.org/hostsfile/hosts.txt


To complete your list, these are the sources I use in my own script: https://github.com/zant95/hBlock#sources


Just chiming in in case anyone finds these useful, my filter lists (600k):

  https://hosts-file.net/download/hosts.txt
  https://raw.githubusercontent.com/StevenBlack/hosts/master/alternates/fakenews-gambling/hosts
  https://raw.githubusercontent.com/Dawsey21/Lists/master/main-blacklist.txt
  https://ransomwaretracker.abuse.ch/downloads/RW_DOMBL.txt
  https://raw.github.com/notracking/hosts-blocklists/master/domains.txt
  https://s3.amazonaws.com/lists.disconnect.me/simple_tracking.txt
  https://www.malwaredomainlist.com/hostslist/hosts.txt
  https://zeustracker.abuse.ch/blocklist.php?download=domainblocklist
  https://s3.amazonaws.com/lists.disconnect.me/simple_malware.txt
  https://s3.amazonaws.com/lists.disconnect.me/simple_malvertising.txt
  https://raw.githubusercontent.com/reek/anti-adblock-killer/master/anti-adblock-killer-filters.txt
  https://s3.amazonaws.com/lists.disconnect.me/simple_ad.txt
  http://winhelp2002.mvps.org/hosts.txt
  http://v.firebog.net/hosts/Easylist.txt
  http://v.firebog.net/hosts/Easyprivacy.txt
Also my whitelist (Family uses Windows, xbox, facebook, etc):

  pihole -w www.msftncsi.com settings-win.data.microsoft.com outlook.office365.com products.office.com c.s-microsoft.com i.s-microsoft.com login.live.com outlook.live.com dl.delivery.mp.microsoft.com geo-prod.do.dsp.mp.microsoft.com displaycatalog.mp.microsoft.com xbox.ipv6.microsoft.com device.auth.xboxlive.com www.msftncsi.com title.mgt.xboxlive.com xsts.auth.xboxlive.com title.auth.xboxlive.com ctldl.windowsupdate.com attestation.xboxlive.com xboxexperiencesprod.experimentation.xboxlive.com xflight.xboxlive.com cert.mgt.xboxlive.com xkms.xbolive.com def-vef.xboxlive.com notify.xboxlive.com help.ui.xboxlive.com licensing.xboxlive.com eds.xboxlive.com www.xboxlive.com v10.vortex-win.data.microsoft.com settings-win.data.microsoft.com creative.ak.fbcdn.net external-lhr0-1.xx.fbcdn.net external-lhr1-1.xx.fbcdn.net external-lhr10-1.xx.fbcdn.net external-lhr2-1.xx.fbcdn.net external-lhr3-1.xx.fbcdn.net external-lhr4-1.xx.fbcdn.net external-lhr5-1.xx.fbcdn.net external-lhr6-1.xx.fbcdn.net external-lhr7-1.xx.fbcdn.net external-lhr8-1.xx.fbcdn.net external-lhr9-1.xx.fbcdn.net fbcdn-creative-a.akamaihd.net scontent-lhr3-1.xx.fbcdn.net


uBlock actually has a very good list of blockfiles, most of which (from memory) correspond to those you list. Last I checked it was on the order of 60k hosts.

I've used that to populate my own hosts + dnsmasq blockfiles. Using just the winhelp2002 list does a passably good job on a DD-WRT imaged router (~13k entries).


Sound like an amazing setup, what about sharing all these scripts? How and why you build your browser?


It's just a shell script to manage dnsmasq running on my FreeBSD home server. It's not sophicated but equally it's written specifically for my server so no very portable either.

I did think about writing something to share but projects like Pi-hole have done a better job serving the community than i could have. So i just share the sources i use instead incase any like-minded sysadmins find it useful.


You could also use py-hole which is a simple apt install of a bit of python that does the dnsmasq file creation and update.

Its pre alpha but may work for you

https://github.com/time4tea-net/py-hole


Thanks for the recommendation but the shell script i have works good enough and has been for a few years now. Plus the container (FreeBSD jail to be precise) is pretty low footprint so while i don't have an issue with Python itself, it's an additional package I don't really need.


There is also this perl script for generating a DNS based blocklist for unbound out of Dan Pollock's hosts file.

https://github.com/jodrell/unbound-block-hosts


For a router-based block, see DD-WRT and dnsmaq:

https://ello.co/dredmorbius/post/b2ungqjvmlflvinrtp4cug


Someone should whip up a little community-driven service that would serve all known ad network hosts.


So we'll have ublock/adblock without the parts that block the ads.


ublock only acts on the browser(s) to which it's been added. PiHole, other DNS blockers, or firewall-type (CIDR-block) blockers defend all applications from either DNS-supported services (most of them), or direct network access (most of the rest). To bypass the second, you'd need apps which had, say, VNC or proxy access to somewhere, and I strongly suspect those proxies would be fairly trivial to add.

I've been running various blocking and reporting systems for coming on 20 years myself, and find that applying my own hygiene controls to network traffic is ... surprisingly effective. Not bulletproof by any means (though reasonably effective against "bulletproof" hosting providers), but it massively reduces attack service.

I've been thinking a lot about networks, size and scale, and the corresponding levels of abuse. To a rough approximation, the Internet grew by an order of magnitude from 1969 to 1970 (1 to 10 nodes), 1977, 1985, 1987, 1989, 1993, 1995, 2000, and 2012 (1 billion nodes).

The "Linux Sucks" guy (multiple presos at Linux conferences on the state of breakage within Linux) did a preso recently on the IoT, noting that we're going to be looking at roughly 80 billion nodes by 2020. I'm wondering what that will do to various forms of abuse.

In the 1970s there was Phreaking and John "Captain Crunch" Draper. In the 1980s, the first boot-sector viruses (Brain: 1986) and the Morris Worm (1988). War dialing was a thing.

Through the 1990s, there was Usenet spam, first jokes like Make Money Fast, then Green Card. With the spread of the WWW, the first banner ads, pop-ups, and click fraud.

2000s: adware and spyware (bug-for-bug compatible reimplimentation on Android now), ID theft, high-profile viruses (Nimda, Code Red, Welchia, Slammer...), DDoS, and Phishing.

In the 2010s, click fraud and various forms of doxxing and pranking lead to wholsesale attacks on liberal democracy itself, with A/B tested bots and informational attacks.

I'm looking for a concept of network scale and problems encountered out of this.


It would be nice for mobile browsers to support a blacklist/reporting of malicious ads. In particular I'm referring to the type that hijack the browser through redirects, preventing you from returning to the source page. I see these alot originating from major news sites. They're usually in the form of "Complete this 3 question Facebook survey to win an iPhone" or "Your device is infected!" The people originating these ought to be arrested for wire fraud.


Exactly. We could just import that list into our blocker.


and a community driven list of good advertisers that are transparent in how they deal with our information and take the quality of the adverts seriously.




Consider applying for YC's Fall 2026 batch! Applications are open till July 27.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: