On Tue, Aug 29, 2017 at 11:22:14AM +0200, David Haller wrote

> # Farcepalm
> address=/fb.com/127.0.1.1
> address=/fbcdn.net/127.0.1.1
> address=/facebook.com/127.0.1.1
> address=/facebook.net/127.0.1.1
> address=/facebook.de/127.0.1.1
> address=/facebook.fr/127.0.1.1
> address=/facebook.co.uk/127.0.1.1
> address=/whatsapp.de/127.0.1.1
> address=/whatsapp.com/127.0.1.1
> address=/internet.org/127.0.1.1
> address=/internet.com/127.0.1.1
> # ...
> ====
> 
> Result:
> 
> $ host fb.com
> fb.com has address 127.0.1.1
> $ nslookup fb.com
> Server:         127.0.0.1
> Address:        127.0.0.1#53
> 
> Name:   fb.com
> Address: 127.0.1.1
> 
> It's still a ton of domains to add, but much less generally. I still
> wish it'd do "shell-style" globbing like /facebook.*/ or
> /facebook.{com,net,de,fr,co.uk}/ ... You could write a little
> generator for that if need be ...

  Facebook is better-handled in iptables...

[0:0] -A INPUT -s 31.13.24.0/21 -j FECESBOOK
[194:15548] -A INPUT -s 31.13.64.0/18 -j FECESBOOK
[0:0] -A INPUT -s 66.220.144.0/20 -j FECESBOOK
[0:0] -A INPUT -s 69.63.176.0/20 -j FECESBOOK
[0:0] -A INPUT -s 69.171.224.0/19 -j FECESBOOK
[0:0] -A INPUT -s 74.119.76.0/22 -j FECESBOOK
[0:0] -A INPUT -s 103.4.96.0/22 -j FECESBOOK
[0:0] -A INPUT -s 173.252.64.0/18 -j FECESBOOK
[0:0] -A INPUT -s 204.15.20.0/22 -j FECESBOOK

[0:0] -A OUTPUT -d 31.13.24.0/21 -j FECESBOOK
[4035959:242209304] -A OUTPUT -d 31.13.64.0/18 -j FECESBOOK
[56:3360] -A OUTPUT -d 66.220.144.0/20 -j FECESBOOK
[0:0] -A OUTPUT -d 69.63.176.0/20 -j FECESBOOK
[874:52440] -A OUTPUT -d 69.171.224.0/19 -j FECESBOOK
[0:0] -A OUTPUT -d 74.119.76.0/22 -j FECESBOOK
[0:0] -A OUTPUT -d 103.4.96.0/22 -j FECESBOOK
[3306:198360] -A OUTPUT -d 173.252.64.0/18 -j FECESBOOK
[0:0] -A OUTPUT -d 204.15.20.0/22 -j FECESBOOK

[4040389:242479012] -A FECESBOOK -j LOG --log-prefix "FECESBOOK:" --log-level 6
[4040389:242479012] -A FECESBOOK -j DROP

  The [packet:byte] counters show how much traffic each rule gets.  It
may be different dependeng where on the planet you are.

-- 
Walter Dnes <waltd...@waltdnes.org>
I don't run "desktop environments"; I run useful applications

Reply via email to