{"id":13628640,"url":"https://github.com/cyclaero/void-zones-tools","last_synced_at":"2025-04-17T04:32:04.884Z","repository":{"id":55389667,"uuid":"73377687","full_name":"cyclaero/void-zones-tools","owner":"cyclaero","description":"Prepare a list of void zones that can be readily feed into Unbound on FreeBSD","archived":false,"fork":false,"pushed_at":"2023-08-28T22:28:23.000Z","size":79,"stargazers_count":59,"open_issues_count":1,"forks_count":9,"subscribers_count":8,"default_branch":"master","last_synced_at":"2024-11-08T19:42:10.826Z","etag":null,"topics":[],"latest_commit_sha":null,"homepage":"","language":"C","has_issues":true,"has_wiki":null,"has_pages":null,"mirror_url":null,"source_name":null,"license":"bsd-2-clause","status":null,"scm":"git","pull_requests_enabled":true,"icon_url":"https://github.com/cyclaero.png","metadata":{"files":{"readme":"README.md","changelog":null,"contributing":null,"funding":null,"license":"LICENSE","code_of_conduct":null,"threat_model":null,"audit":null,"citation":null,"codeowners":null,"security":null,"support":null,"governance":null,"roadmap":null,"authors":null,"dei":null,"publiccode":null,"codemeta":null}},"created_at":"2016-11-10T11:56:09.000Z","updated_at":"2024-09-09T17:59:37.000Z","dependencies_parsed_at":"2024-08-01T22:51:51.597Z","dependency_job_id":null,"html_url":"https://github.com/cyclaero/void-zones-tools","commit_stats":null,"previous_names":[],"tags_count":3,"template":false,"template_full_name":null,"repository_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/cyclaero%2Fvoid-zones-tools","tags_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/cyclaero%2Fvoid-zones-tools/tags","releases_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/cyclaero%2Fvoid-zones-tools/releases","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/cyclaero%2Fvoid-zones-tools/manifests","owner_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners/cyclaero","download_url":"https://codeload.github.com/cyclaero/void-zones-tools/tar.gz/refs/heads/master","host":{"name":"GitHub","url":"https://github.com","kind":"github","repositories_count":249315966,"owners_count":21249866,"icon_url":"https://github.com/github.png","version":null,"created_at":"2022-05-30T11:31:42.601Z","updated_at":"2022-07-04T15:15:14.044Z","host_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub","repositories_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories","repository_names_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repository_names","owners_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners"}},"keywords":[],"created_at":"2024-08-01T22:00:54.813Z","updated_at":"2025-04-17T04:32:04.566Z","avatar_url":"https://github.com/cyclaero.png","language":"C","funding_links":[],"categories":["C","\u003ca id=\"8c5a692b5d26527ef346687e047c5c21\"\u003e\u003c/a\u003e收集"],"sub_categories":[],"readme":"### [ACTION REQUIRED] Your GitHub account, cyclaero, will soon require 2FA\nHere is the deal: https://obsigna.com/articles/1693258424.html\n\n \n## void-zones-tools for FreeBSD\n### Prepare a list of void zones that can be readily fed into *Unbound*.\n\n### What is a void zone?\n\nIn terms of *Unbound*, a void zone is a static empty local-zone, i.e. one without any local-data directives, for example:\n    \n    local-zone: \"void.example.com\" static\n    \nWith this in place, *Unbound* would answer any DNS requests for `void.example.com` with `NXDOMAIN`.\n\n\n### For what are void zones useful?\n\nVoid zones are the most straightforward way of blocking ad, tracking and other malware domains.\nWhile the method is similar to the *Hosts* file approach, the void zone method got 3 advantages:\n\n1. Requests for any subdomain of the void zone result in `NXDOMAIN`.\n   In *Hosts* files every subdomain needs its own entry.\n\n2. In *Hosts* files, each entry does consist of an IP address and a fully qualified domain,\n   so DNS requests for a given domain would return the listed IP address. For blocking\n   purposes either `127.0.0.1` or `0.0.0.0` is used, which may result in undesired side effects:\n   \n   - in the case of `127.0.0.1`, developers won't be able to run a test web-server on localhost,\n     and any software is supposed to try to establish a connection to localhost, and this \n     usually ends up in a timeout error. \n   - in the case of `0.0.0.0` ill-behaved software still tries to establish a connection, which\n     cannot work, but resources are utilized until timeout.\n   \n   The void zone response is `NXDOMAIN`, and no software would try to establish a connection\n   to a non-existing address.\n\n3. The void zone method can be deployed on the gateway, and any number of clients behind the\n   gateway do benefit automatically from ad, tracking and malware domain blocking. While *Hosts*\n   files need to be deployed on any single machine. Even if this is not that difficult on\n   desktops and notebooks, this may easily become a PITA for mobile clients. You would need\n   `root` login on your Androids, iPhones and/or iPads.\n\n\n### How does this compare to Browser Plugins?\n\n1. Browser plugins are destined to one piece of software and not to the whole machine.\n   Void zones are active for the whole machine or in the case of a gateway, for any\n   number of clients, and even for those (Android) which don't allow ad-blocking plugins.\n\n2. Browser plugins are active filters, that means, beside the advertised behaviour, they\n   are able to do something in the background. This is a matter of trust, which may\n   sometimes miserably trapped -- see the WoT incident. Void zones are passive. The actual\n   filtering is done by the DNS resolver, here *Unbound*, which is much less likely of doing\n   undesired things behind your back.\n\n\n### How do I deploy the void zone method on my FreeBSD machine?\n\nThe *void-zones-tools* made it into the FreeBSD ports and it can be installed from source or from the binary package repository:\n\n    # cd /usr/ports/dns/void-zones-tools\n    # make install clean\n    \nor\n\n    # pkg install void-zones-tools\n\n\nOf course, it is also possible to build it from the source of the present github repository. Either clone the `void-zones-tools` project using *Git* or check it out with *Subversion*:\n\n    # git clone https://github.com/cyclaero/void-zones-tools.git\n\nor\n\n    # svn checkout https://github.com/cyclaero/void-zones-tools.git/trunk/ void-zones-tools\n    \nEnter the directory of the working copy of the `void-zones-tools` and build \u0026 install the tools:\n\n    # cd void-zones-tools\n    # make install clean\n    \n\nThe tools consist of the *Hosts* file converter \u0026 consolidator `hosts2zones` and the shell script\n`void-zones-update.sh` which is used to download suitable *Hosts* files from 8 pre-defined providers:\n\n* [PGL - Ad blocking with ad server hostnames and IP addresses](http://pgl.yoyo.org/adservers/)\n* [SomeOneWhoCares - How to make the internet not suck (as much)](http://someonewhocares.org/hosts/zero/)\n* [MVPS - A detailed guide for using the MVPS HOSTS file](http://winhelp2002.mvps.org/)\n* [AdAway - Hosts](https://github.com/AdAway/AdAway/)\n* [DNS-BH – Malware Domain Blocklist](http://www.malwaredomains.com/)\n* [FadeMind - UncheckyAds](https://github.com/FadeMind/hosts.extras/)\n* [WindowsSpyBlocker - Spy Hosts](https://github.com/crazy-max/WindowsSpyBlocker/)\n\n\nThe tools are placed by the above command sequence into `/usr/local/bin/`.\n\nOn the first run of `void-zones-update.sh`, a directory is created at `/usr/local/etc/void-zones/`,\nwhich serves as the storage location for the downloaded *Hosts* files and/or *Domain* listings. In\naddition a template for a custom white/black list `my_void_hosts.txt` is placed into that directory,\nand this may be used for whitelisting some zones that are inadvertently part of the downloaded *Hosts* files,\nor for blacklisting additional zones, which are missing from the downloads. Now execute said shell script:\n\n    # void-zones-update.sh\n    # nano /usr/local/etc/void-zones/my_void_hosts.txt\n    \n    # white list\n    1.1.1.1 my.white.dom\n\n    # black list\n    0.0.0.0 my.black.dom\n\nFor whitelisting use the IP address `1.1.1.1`, and for blacklisting `0.0.0.0` shall be used.\n\nThe downloaded *Hosts* files are  placed into `/usr/local/etc/void-zones/` as well:\n\n    # ls -l /usr/local/etc/void-zones\n\n    total 1876\n    -rw-r--r--  1 root  wheel   13722 Jan 31  2017 away_void_hosts.txt\n    -rw-r--r--  1 root  wheel  640858 Aug 17 19:16 jdom_void_list.txt\n    -rw-r--r--  1 root  wheel  497673 Aug  7 11:07 mvps_void_hosts.txt\n    -rw-r--r--  1 root  wheel   60257 Aug 21 05:43 pgl_void_hosts.txt\n    -rw-r--r--  1 root  wheel  376421 Aug 20 14:40 sowc_void_hosts.txt\n    -rw-r--r--  1 root  wheel     618 Aug 22 09:29 ucky_void_host.txt\n    -rw-r--r--  1 root  wheel    9977 Aug 22 09:29 w10telm_void_hosts.txt\n    -rw-r--r--  1 root  wheel     886 Aug 22 09:29 w7telm_void_hosts.txt\n    -rw-r--r--  1 root  wheel    1142 Aug 22 09:29 w81telm_void_hosts.txt\n\nAnd finally the `void-zones-update.sh` compiles (converts \u0026 consolidates) all *Hosts* files\nand *Domain* listings into one single `local-void.zones` include file, and moves this into\n`/var/unbound/` for direct usage with *Unbound*:\n\n    # head /var/unbound/local-void.zones\n    \n    local-zone: \"clk.cloudyisland.com\" static\n    local-zone: \"click.silvercash.com\" static\n    local-zone: \"oascentral.pressdemocrat.com\" static\n    local-zone: \"s29.cnzz.com\" static\n    local-zone: \"www.spywarespy.com\" static\n    local-zone: \"republika.onet.pl\" static\n    local-zone: \"preview.msn.com\" static\n    local-zone: \"pos.baidu.com\" static\n    ...\n\nFor using the void zones method, of course *Unbound* must be up and running already on the given FreeBSD machine.\nThen edit the configuration file `/var/unbound/unbound.conf` in order to activate ad, tracking, malware and telemetry domain\nfiltering by *Unbound*:\n\n    # nano /var/unbound/unbound.conf\n\n**Before** any forwarder directives, e.g. `forward-zone:` or `include: /var/unbound/forward.conf` add the following line:\n\n    include: /var/unbound/local-void.zones\n\nThen restart *Unbound*:\n\n    # service local_unbound restart\n\nFor future updates execute the following command sequence which may be placed into a cron job:\n\n    # /usr/local/bin/void-zones-update.sh \u0026\u0026 /usr/sbin/service local_unbound restart\n\nIn order to facilitate inclusion of listings which are not part of the automated updating, 3 additional input files are\npassed by `void-zones-update.sh` to the conversion tool `hosts2zones`:\n\n    x_void_list.txt\n    y_void_list.txt\n    z_void_list.txt\n    \nThis mechanism can be used to include for example the [Disconnect.me](https://github.com/chrisaljoudi/uBlock/issues/1406)\nlistings to the `hosts2zones` processing by executing the following command before updating the other zones:\n\n    # fetch -o - \\\n            https://s3.amazonaws.com/lists.disconnect.me/simple_ad.txt \\\n            https://s3.amazonaws.com/lists.disconnect.me/simple_malware.txt \\\n            https://s3.amazonaws.com/lists.disconnect.me/simple_tracking.txt \\\n            https://s3.amazonaws.com/lists.disconnect.me/simple_malvertising.txt \\\n            \u003e /usr/local/etc/void-zones/x_void_list.txt\n\nSaid command would place the respective lists joined together into `/usr/local/etc/void-zones/x_void_list.txt`, and on the\nnext run of `void-zones-update.sh` that one would be  converted \u0026 consolidated \u0026 included into the `local-void.zones` for\nfiltering by *Unbound*. In the case these additional files are missing, the tool simply ignores these parameters.\n","project_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fcyclaero%2Fvoid-zones-tools","html_url":"https://awesome.ecosyste.ms/projects/github.com%2Fcyclaero%2Fvoid-zones-tools","lists_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fcyclaero%2Fvoid-zones-tools/lists"}