DNS Ad Blocker: Difference between revisions

From Leo's Notes
This page was last edited on 31 March 2015, at 18:37.
Created page with " generate.sh: <syntaxhighlight lang="bash"> #/bin/bash echo "" > /etc/named.advertisement.conf for i in `cat /var/named/adlist.txt` ; do echo "zone \"$i\" {" >> /etc..."
 
Updated information
Line 1: Line 1:
The DNS Advertisement blocker is an extension of blocking advertisements through the local hosts file, except using a real DNS server instead. There are various upsides to this approach such as the ability to blocking entire domains and sub-domains, and being able to block specific hosts on devices where editing the hosts file is not possible or practical (eg. a phone or tablet).


generate.sh:
I do not recommend running this on a Raspberry Pi simply because a large list of zones will take a considerably long time to load and DNS queries may appear to be sluggish.
 
== The Code ==
This blocker contains the following components:
* BIND DNS server
* A generator script that creates zones based on an ad list
* An ad list containing all servers to be blocked
* Optionally, a HTTP server to capture all redirected HTTP traffic
 
=== Setup ===
Install BIND with the following configuration in <code>/etc/named.conf</code>
 
=== /etc/named.conf ===
Make sure your named.conf contains at least the following:
<syntaxhighlight lang="text">
include "/etc/named.advertisement.conf";
include "/etc/named.rfc1912.zones";
include "/etc/named.root.key";
 
zone "." IN {
type hint;
file "named.ca";
};
</syntaxhighlight>
 
Zones that are not defined should be looked up via root hints.
 
=== generate.sh ===
Create a script named <code>generate.sh</code> with the following:
<syntaxhighlight lang="bash">
<syntaxhighlight lang="bash">
#/bin/bash
# Normal advertisement zones
 
echo "" > /etc/named.advertisement.conf
echo "" > /etc/named.advertisement.conf
for i in `cat adlist.txt` ; do
test -z $i && continue;
echo "zone \"$i\" {" >> /etc/named.advertisement.conf
echo "type master; file \"adredirect.zone\";" >> /etc/named.advertisement.conf
echo "};" >> /etc/named.advertisement.conf
echo "" >> /etc/named.advertisement.conf
done


for i in `cat /var/named/adlist.txt` ; do
# Or if using systemd: systemctl restart named.service
        echo "zone \"$i\" {" >> /etc/named.advertisement.conf
/etc/init.d/named restart
        echo "type master; file \"adredirect.zone\";" >> /etc/named.advertisement.conf
        echo "};" >> /etc/named.advertisement.conf
        echo "" >> /etc/named.advertisement.conf
done


#/etc/init.d/named restart
rndc status|grep OFF && rndc querylog
#rndc querylog on
# systemctl restart named
systemctl restart named


sleep 4
sleep 4
rndc reload
rndc reload
rndc flush
rndc flush
</syntaxhighlight>


</syntaxhighlight>
=== adlist.txt ===
Get the latest adlist from [[DNS AD Blocker/Ad List]] and place it into the <code>adlist.txt</code> file. Zones will be generated for each domain in this list which will also block all subdomains.


=== adredirect.zone ===
Create this zone file in <code>/var/named/adredirect.zone</code>. This zone will be referenced for every zone that is created.


adlist.txt:
Replace the IP address <code>9.11.9.11</code> with <code>0.0.0.0</code> if you do not plan on running a HTTP server to capture the ad requests.
<syntaxhighlight lang="text">
googleanalytics.com
googleadservices.com
... etc
</syntaxhighlight>


adredirect.zone:
<syntaxhighlight lang="text">
<syntaxhighlight lang="text">
$TTL 1h
$TTL 1h
Line 45: Line 74:


</syntaxhighlight>
</syntaxhighlight>
At the top of named.conf, include the advertisement configuration file that was generated by the script.
include "/etc/named.advertisement.conf";




[[Category:Linux]]
[[Category:Linux]]
{{Navbox Linux}}

Revision as of 18:37, 31 March 2015

The DNS Advertisement blocker is an extension of blocking advertisements through the local hosts file, except using a real DNS server instead. There are various upsides to this approach such as the ability to blocking entire domains and sub-domains, and being able to block specific hosts on devices where editing the hosts file is not possible or practical (eg. a phone or tablet).

I do not recommend running this on a Raspberry Pi simply because a large list of zones will take a considerably long time to load and DNS queries may appear to be sluggish.

The Code

This blocker contains the following components:

  • BIND DNS server
  • A generator script that creates zones based on an ad list
  • An ad list containing all servers to be blocked
  • Optionally, a HTTP server to capture all redirected HTTP traffic

Setup

Install BIND with the following configuration in /etc/named.conf

/etc/named.conf

Make sure your named.conf contains at least the following:

	include "/etc/named.advertisement.conf";
	include "/etc/named.rfc1912.zones";
	include "/etc/named.root.key";

	zone "." IN {
		type hint;
		file "named.ca";
	};

Zones that are not defined should be looked up via root hints.

generate.sh

Create a script named generate.sh with the following:

# Normal advertisement zones
echo "" > /etc/named.advertisement.conf
for i in `cat adlist.txt` ; do
	test -z $i && continue;
	echo "zone \"$i\" {" >> /etc/named.advertisement.conf
	echo "type master; file \"adredirect.zone\";" >> /etc/named.advertisement.conf
	echo "};" >> /etc/named.advertisement.conf
	echo "" >> /etc/named.advertisement.conf
done

# Or if using systemd: systemctl restart named.service
/etc/init.d/named restart

rndc status|grep OFF && rndc querylog
# systemctl restart named

sleep 4
rndc reload
rndc flush

adlist.txt

Get the latest adlist from DNS AD Blocker/Ad List and place it into the adlist.txt file. Zones will be generated for each domain in this list which will also block all subdomains.

adredirect.zone

Create this zone file in /var/named/adredirect.zone. This zone will be referenced for every zone that is created.

Replace the IP address 9.11.9.11 with 0.0.0.0 if you do not plan on running a HTTP server to capture the ad requests.

$TTL 1h
@               IN SOA  ns1.server. ns2.server. (
                        44      ; serial
                        3600    ; refresh
                        15M     ; retry
                        1W      ; expiry
                        1D )    ; minimum
@               NS      ns1.server.
@               A       9.11.9.11
*               A   9.11.9.11