https://raw.githubusercontent.com/DandelionSprout/adfilt/master/Alternate%20versions%20Anti-Malware%20List/Dandelion%20Sprout's%20and%20other%20adblocker%20lists'%20IPs.ipset Rohliste öffnen Beschreibung
Filterliste aus den Bereichen Werbung und Phishing. Format: IPs (IPv4). Betreut von Imre Kristoffer Eilertsen. Einzelheiten und Aufnahmekriterien stehen auf der Projektseite.
Integration
Address list per script
Fetch the list and import it into an address list called blocklist:
/tool fetch url="https://raw.githubusercontent.com/DandelionSprout/adfilt/master/Alternate%20versions%20Anti-Malware%20List/Dandelion%20Sprout's%20and%20other%20adblocker%20lists'%20IPs.ipset" dst-path=blocklist.rsc
/import blocklist.rsc If the list is a plain text file with one address or CIDR per line, convert it first:
/tool fetch url="https://raw.githubusercontent.com/DandelionSprout/adfilt/master/Alternate%20versions%20Anti-Malware%20List/Dandelion%20Sprout's%20and%20other%20adblocker%20lists'%20IPs.ipset" dst-path=blocklist.txt
:foreach line in=[/file get blocklist.txt contents] do={
/ip firewall address-list add list=blocklist address=$line comment="Dandelion Sprout’s and other adblocker lists‘ IPs"
} Use the list in the firewall
/ip firewall filter add chain=forward src-address-list=blocklist action=drop comment="Dandelion Sprout’s and other adblocker lists‘ IPs"
/ip firewall filter add chain=forward dst-address-list=blocklist action=drop comment="Dandelion Sprout’s and other adblocker lists‘ IPs" Schedule the fetch with /system scheduler to keep the list current. Very large lists consume RAM, so check the available memory of your device first.
banIP (recommended)
- Install the package:
opkg update && opkg install banip luci-app-banip - Open LuCI → Services → banIP → Feeds and add a custom feed with the URL below.
- Enable the feed and click Save & Apply.
https://raw.githubusercontent.com/DandelionSprout/adfilt/master/Alternate%20versions%20Anti-Malware%20List/Dandelion%20Sprout's%20and%20other%20adblocker%20lists'%20IPs.ipset Manual with nftables
wget -qO /tmp/blocklist.txt "https://raw.githubusercontent.com/DandelionSprout/adfilt/master/Alternate%20versions%20Anti-Malware%20List/Dandelion%20Sprout's%20and%20other%20adblocker%20lists'%20IPs.ipset"
nft add set inet fw4 blocklist { type ipv4_addr; flags interval; }
nft -f - <<EOF
$(awk '!/^[#;]/ && NF {print "add element inet fw4 blocklist { " $1 " }"}' /tmp/blocklist.txt)
EOF
nft add rule inet fw4 forward ip saddr @blocklist drop ipset create blocklist hash:net -exist
curl -fsSL "https://raw.githubusercontent.com/DandelionSprout/adfilt/master/Alternate%20versions%20Anti-Malware%20List/Dandelion%20Sprout's%20and%20other%20adblocker%20lists'%20IPs.ipset" | grep -Eo '^[0-9]{1,3}(.[0-9]{1,3}){3}(/[0-9]{1,2})?' |
while read -r net; do ipset add blocklist "$net" -exist; done
iptables -I INPUT -m set --match-set blocklist src -j DROP
iptables -I FORWARD -m set --match-set blocklist src -j DROP Persist the set and re-run the download from cron to keep it current:
ipset save blocklist -f /etc/ipset.blocklist
# /etc/cron.daily/blocklist
Add the list as an ipset in /etc/firehol/firehol.conf:
ipset4 create blocklist hash:net
ipset4 addfile blocklist "https://raw.githubusercontent.com/DandelionSprout/adfilt/master/Alternate%20versions%20Anti-Malware%20List/Dandelion%20Sprout's%20and%20other%20adblocker%20lists'%20IPs.ipset"
blacklist4 full inface any src ipset:blocklist Reload with firehol try and confirm before making it permanent.
- Go to Firewall → Aliases and click +.
- Choose type URL Table (IPs), set a refresh interval (for example 1 day) and paste the URL below.
- Save and apply, then use the alias as source in a block rule under Firewall → Rules.
https://raw.githubusercontent.com/DandelionSprout/adfilt/master/Alternate%20versions%20Anti-Malware%20List/Dandelion%20Sprout's%20and%20other%20adblocker%20lists'%20IPs.ipset - Go to Firewall → pfBlockerNG → IP → IPv4 and click Add.
- Paste the URL below as source, set State to ON and pick the action (Deny Both is the usual choice).
- Save, then run Update → Force Reload → IP.
https://raw.githubusercontent.com/DandelionSprout/adfilt/master/Alternate%20versions%20Anti-Malware%20List/Dandelion%20Sprout's%20and%20other%20adblocker%20lists'%20IPs.ipset curl -fsSL "https://raw.githubusercontent.com/DandelionSprout/adfilt/master/Alternate%20versions%20Anti-Malware%20List/Dandelion%20Sprout's%20and%20other%20adblocker%20lists'%20IPs.ipset" -o /var/lib/suricata/data/blocklist.txt Reference the file from a rule using a dataset:
alert ip [!$HOME_NET] any -> $HOME_NET any (msg:"Dandelion Sprout’s and other adblocker lists‘ IPs match";
ip.src; dataset:isset,blocklist, type string, load blocklist.txt; sid:1000001;) 