Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

add new lists #709

Closed
collinbarrett opened this issue Mar 6, 2019 · 24 comments
Closed

add new lists #709

collinbarrett opened this issue Mar 6, 2019 · 24 comments
Labels
directory-data changes to basic FilterLists data

Comments

@collinbarrett
Copy link
Owner

collinbarrett commented Mar 6, 2019

Some raw new/update lists suggestions from anonymous source. I haven't had a chance to sort through/cleanup yet. I think some of them are duplicates.

Change source of Badd Boyz Hosts to https://raw.githubusercontent.com/mitchellkrogza/Badd-Boyz-Hosts/master/PULL_REQUESTS/domains.txt

Add https://github.com/mitchellkrogza/Ultimate.Hosts.Blacklist/tree/master/domains as back up to https://hosts.ubuntu101.co.za/domains.list

Add https://github.com/mitchellkrogza/Ultimate.Hosts.Blacklist/tree/master/ips as back up to https://hosts.ubuntu101.co.za/ips.list

Add https://github.com/mitchellkrogza/Ultimate.Hosts.Blacklist/tree/master/hosts as back up to https://hosts.ubuntu101.co.za/hosts

=====mitchellkrogza=====

https://github.com/mitchellkrogza/Top-Attacking-IP-Addresses-Against-Wordpress-Sites/blob/master/wordpress-attacking-ips.txt

https://github.com/mitchellkrogza/Suspicious.Snooping.Sniffing.Hacking.IP.Addresses/tree/master/input-sources or https://raw.githubusercontent.com/mitchellkrogza/Suspicious.Snooping.Sniffing.Hacking.IP.Addresses/master/ips.list

https://github.com/mitchellkrogza/The-Big-List-of-Hacked-Malware-Web-Sites/tree/master/.dev-tools/output/domains or https://raw.githubusercontent.com/mitchellkrogza/The-Big-List-of-Hacked-Malware-Web-Sites/master/hacked-domains.list

https://github.com/mitchellkrogza/Phishing.Database/tree/master/dev-tools/output/domains or https://raw.githubusercontent.com/mitchellkrogza/Phishing.Database/master/phishing-domains-ACTIVE.txt

https://github.com/mitchellkrogza/Phishing-URL-Testing-Database-of-Link-Statuses/tree/master/dev-tools/output/domains

https://github.com/mitchellkrogza/Stop.Google.Analytics.Ghost.Spam.HOWTO/tree/master/output/domains

https://github.com/mitchellkrogza/Fail2Ban.WebExploits/blob/master/input-source/exploits.list

https://github.com/mitchellkrogza/CENTRAL-REPO.Dead.Inactive.Whitelisted.Domains.For.Hosts.Projects

https://github.com/mitchellkrogza/Ultimate.Hosts.Blacklist/tree/master/hosts.deny

https://github.com/mitchellkrogza/Ultimate.Hosts.Blacklist/tree/master/superhosts.deny

=====github.com/maravento/blackweb sources=====

https://github.com/oznu/dns-zone-blacklist

https://raw.githubusercontent.com/greatis/Anti-WebMiner/master/blacklist.txt

http://osint.bambenekconsulting.com/feeds/dga-feed.txt

http://dsi.ut-capitole.fr/blacklists/download/

http://www.carl.net/spam/access.txt

https://raw.githubusercontent.com/chadmayfield/pihole-blocklists/master/lists/pi_blocklist_porn_top1m.list

http://cybercrime-tracker.net/all.php

https://github.com/Dawsey21/Lists

https://raw.githubusercontent.com/ruvelro/Halt-and-Block-Mining/master/HBmining.bat

https://hexxiumcreations.github.io/threat-list/hexxiumthreatlist.txt

http://hosts-file.net/download/hosts.txt

https://raw.githubusercontent.com/joelotz/URL_Blacklist/master/blacklist.csv

http://www.joewein.de/sw/bl-text.htm

https://raw.githubusercontent.com/azet12/KADhosts/master/KADhosts.txt

http://malwaredomains.lehigh.edu/files/

http://malc0de.com/bl/

http://www.malwaredomainlist.com/hostslist/hosts.txt

https://github.com/matomo-org/referrer-spam-blacklist/blob/master/spammers.txt

http://squidguard.mesd.k12.or.us/blacklists.tgz

http://www.malware-domains.com/files/

https://hosts.ubuntu101.co.za/hosts.deny

https://hosts.ubuntu101.co.za/superhosts.deny

https://raw.githubusercontent.com/oleksiig/Squid-BlackList/master/denied_ext.conf

Passwall Spam Assassin (last update) https://gutl.jovenclub.cu/wp-content/uploads/2017/05/blacklist.txt

https://raw.githubusercontent.com/quedlin/blacklist/master/domains

Latest MinimalHostsCB?
https://github.com/ReddestDream/reddestdream.github.io/tree/master/Projects/MinimalHostsCB/etc/MinimalHostsBlocker

Latest MinimalHosts?
https://github.com/ReddestDream/reddestdream.github.io/tree/master/Projects/MinimalHosts/etc/MinimalHostsBlocker

http://www.shallalist.de/Downloads/shallalist.tar.gz

https://www.stopforumspam.com/downloads/toxic_domains_whole.txt

https://raw.githubusercontent.com/tankmohit/UnifiedHosts/master/hosts.all

https://github.com/tankmohit/UnifiedHosts/blob/master/whitelist

http://www.taz.net.au/Mail/SpamDomains

=====github.com/mitchellkrogza/Ultimate.Hosts.Blacklist sources=====

https://www.badips.com/info

https://github.com/Ultimate-Hosts-Blacklist/smed79_parkingcrew.com/tree/master/output/domains

https://github.com/Ultimate-Hosts-Blacklist/SMed79_admeasures_adservers/tree/master/output/domains

https://github.com/Ultimate-Hosts-Blacklist/SMed79_uponit.com_adservers/tree/master/output/domains

https://github.com/Ultimate-Hosts-Blacklist/smed79_getadmiral.com/tree/master/output/domains

https://github.com/Ultimate-Hosts-Blacklist/SMed79_hilltopads_adservers/tree/master/output/domains

https://github.com/Ultimate-Hosts-Blacklist/smed79_propellerads_adservers/tree/master/output/domains

https://github.com/Ultimate-Hosts-Blacklist/smed79_popads_adservers/tree/master/output/domains

https://github.com/Ultimate-Hosts-Blacklist/smed79_blocklist_facebook/tree/master/output/domains

https://github.com/Ultimate-Hosts-Blacklist/SMed79_assorted/tree/master/output/domains

@collinbarrett collinbarrett added the directory-data changes to basic FilterLists data label Mar 6, 2019
@collinbarrett
Copy link
Owner Author

  1. no worries, that shouldn't break anything. we can clean it up in another PR
  2. man, not sure at first glance. syntax isn't a required field, so we can leave them off for now if we can't determine.

@DandelionSprout
Copy link
Contributor

DandelionSprout commented Mar 8, 2019

If my memory doesn't play tricks on me, here's my notes about some of the lists:

Already added:

Mere mirrors:

Useless:

Other:

Most, if not all of the rest of the lists, are however solid candidates for being added.

@bogachenko
Copy link
Contributor

@collinbarrett

https://github.com/CHEF-KOCH/BarbBlock-filter-list

Uh, there's no problem with this list? He (for sure) stole it somewhere and gives out for his work...
After a month, the other would again have to remove, lol. It's monkey bussines.

@ghost
Copy link

ghost commented Mar 10, 2019

The person who’s attached his name to the (not)BarbBlock list in question additionally makes outright false claims regarding the original BarbBlock repository. The problem is that the public has a habit of not doing research and merely reads, sees links, and believes.

@bogachenko
Copy link
Contributor

bogachenko commented Mar 10, 2019

First of all. these are assumptions.

He (for sure) stole it somewhere and gives out for his work...
(for sure)

Okay?
Secondly. Reputation is something that cannot be bought! Yeah. When a person steals something and is caught on it, his reputation falls. And the next time when something disappears, they go to this person.
soooo this cook (cock) was caught stealing many many many many times. (much of his plagiarism is still stored and not removed, yeah), so my concerns are quite understandable.

and therefore (it seems to me, I emphasize the phrase - it seems to me!) and this repository will be caught stealing, it is only a matter of time.

@collinbarrett
Copy link
Owner Author

Thanks, I just removed the two CK lists from the OP. That was just a big dump of lists that came in via email anonymously. I hadn't had a chance to parse through them yet.

@bogachenko
Copy link
Contributor

Well, there is no such

unbound
isc bind

It would be necessary to add in the future.
But all exactly thanks @Atavic

@Atavic
Copy link

Atavic commented Mar 13, 2019

What is the syntax?

Fail2ban blocks failed attempts at logins. Web Exploits are known sensitive files in webservers and other internet related services that crawlers or scrapers try to brute force or log into. At the bottom there are workpress plugins related sensitive files that admins should lock from unknown visitors.

https://www.badips.com/info

See: http://www.timokorthals.de/?p=334

@bogachenko
Copy link
Contributor

bogachenko commented Mar 13, 2019

@Atavic

https://www.badips.com/info
See: http://www.timokorthals.de/?p=334

I know this is IPs. I'm talking about the fact that there is no RAW, how to subscribe?

Fail2ban blocks failed attempts at logins. Web Exploits are known sensitive files in webservers and other internet related services that crawlers or scrapers try to brute force or log into. At the bottom there are workpress plugins related sensitive files that admins should lock from unknown visitors.

so, what is the syntax?

@Atavic
Copy link

Atavic commented Mar 13, 2019

BadIPs should have an API for interfacing with the huge list.

Fail2ban Webexploits list has no syntax, it's just a blacklist that's read by Fail2ban service.

@bogachenko
Copy link
Contributor

ok as you say i will add

@collinbarrett
Copy link
Owner Author

Hmm. No, mirrors should have the same syntax. Historically, we've treated the same list in different syntaxes as different lists entirely. It seems like we should link them better, but, for now, just treat them as separate lists.

@bogachenko
Copy link
Contributor

bogachenko commented Mar 13, 2019

@collinbarrett and how to add them? Part One, Part Two, Part Dick Know What?
There are many such lists. but if necessary I will add.

@collinbarrett
Copy link
Owner Author

Let's append"Hosts", "IPs", etc. to the end of the list name to differentiate. Thanks.

@bogachenko
Copy link
Contributor

bogachenko commented Mar 13, 2019

@collinbarrett

Let's append"Hosts", "IPs", etc. to the end of the list name to differentiate. Thanks.

this is an ambiguous answer. um. the difficulties of translation from me? um.

like this?

  {
    "id": --,
    "description": "texttextetxtettttttxtetxt.",
    "homeUrl": "https://github.com/mitchellkrogza/Ultimate.Hosts.Blacklist/tree/master/hosts",
    "issuesUrl": "https://github.com/mitchellkrogza/Ultimate.Hosts.Blacklist/issues",
    "name": "Ultimate Hosts Blacklist HOSTS0 mitchellkrogza",
    "syntaxId": --,
    "viewUrl": "https://github.com/mitchellkrogza/Ultimate.Hosts.Blacklist/blob/master/hosts/hosts0"
  }

or this (viewUrl its not RAW)

  {
    "id": --,
    "description": "texttextetxtettttttxtetxt.",
    "homeUrl": "https://github.com/mitchellkrogza/Ultimate.Hosts.Blacklist/tree/master/hosts",
    "issuesUrl": "https://github.com/mitchellkrogza/Ultimate.Hosts.Blacklist/issues",
    "name": "Ultimate Hosts Blacklist HOSTS mitchellkrogza",
    "syntaxId": --,
    "viewUrl": "github.com/mitchellkrogza/Ultimate.Hosts.Blacklist/tree/master/hosts"
  }

@collinbarrett
Copy link
Owner Author

Oh, I just now noticed that these are multi-part lists (Hosts0, Hosts1, etc.). We haven't solved #503 yet.

Hmm... For now, let's just link to the first part of each list. So, something like:

  {
    ...
    "name": "Ultimate Hosts Blacklist Hosts",
    "viewUrl": "https://github.com/mitchellkrogza/Ultimate.Hosts.Blacklist/blob/master/hosts/hosts0"
    ...
  },
  {
    ...
    "name": "Ultimate Hosts Blacklist IPs",
    "viewUrl": "https://github.com/mitchellkrogza/Ultimate.Hosts.Blacklist/raw/master/ips/ips0.list"
    ...
  }

@bogachenko
Copy link
Contributor

okay captain, I'll do it now.

@collinbarrett
Copy link
Owner Author

I'm not totally sure what your question is, but feel free to just not add any lists that you don't think are useful or are too hard to add to the current data model. Also, see #19 for that first url.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
directory-data changes to basic FilterLists data
Projects
None yet
Development

No branches or pull requests

4 participants