Open DSS87 opened 1 year ago
Hi,
Sorry it's been a while, I'm pretty busy. Current rules are mostly ok. Need to find time to add some new rules and also needs another alternative of https://www.threatcrowd.org (looks down) I was using to retrieve domain history for an IP so I can check for false positives.
Nope. The list does not work anymore. My new pihole ignores 3515 entries
Taking advantage of this post, these are new connections I found using Windows 10 and 11:
account.live.com account.microsoft.com activity.microsoft.com ads.arcct.msn.com api.vcservice.webxtsvc-int.microsoft.com api.webxtsvc.microsoft.com bat.bing.com bing.com bingapis.com business.bing.com c.live.com cds26.ams9.msecn.net choice.microsoft.com.nstac.net citrix.onmicrosoft.com clientfd.family.microsoft.com cn.bing.com compatexchange.cloudapp.net cp501.prod.do.dsp.mp.microsoft.com customervoice.microsoft.com cxcs.microsoft.net deff.nelreports.net family.api.account.microsoft.com farevents.family.microsoft.com fd.api.iris.microsoft.com global.bing.com i1.services.social.microsoft.com.nsatc.net inference.location.live.com instrumentExport.cp.microsoft.com iris.microsoft.com kv501.prod.do.dsp.mp.microsoft.com live.com login.microsoft.com m.bing.com manage.microsoft.com mathsolver.microsoft.com microsoftnews.msn.com msft.sts.microsoft.com msn.com mwservice.xpay-int.microsoft.com oca.telemetry.microsoft.com.nsatc.net officeapps.live.com open-vsx.org openvsxorg.blob.core.windows.net paymentinstruments.mp.microsoft.com petrol.office.microsoft.com pptsgs.officeapps.live.com pricelist.skype.com prod.rewardsplatform.microsoft.com rewards.microsoft.com schemas.microsoft.com sdx.microsoft.com settings.family.microsoft.com signup.live.com speech.platform.bing.com spoprod-a-akamaihd.net ssl.live.com staticview.msn.com telecommand.telemetry.microsoft.com.nsatc.net tip.customervoice.microsoft.com tokenization.cp.microsoft.com vcservice.webxtsvc.microsoft.com view.officeapps.live.com vortex-bn2.metron.live.com.nsatc.net vortex-cy2.metron.live.com.nsatc.net vortex-win.data.metron.live.com.nsatc.net watson.telemetry.microsoft.com.nsatc.net web.vortex-sandbox.data.msn.com web.vortex.data.msn.com webxtsvc.microsoft.com www.bing.com www.msn.com xpay-int.microsoft.com
MSBBZBL: Nope. The list does not work anymore. My new pihole ignores 3515 entries https://imgur.com/a/xVP5oL5
I believe this would have been caused by mistakenly using
.../blob/master/data/hosts/update.txt
instead of .../raw/master/data/hosts/update.txt
in the github URL.
I think firewall/update.txt may need some new entries added. I've had a few Windows updates sneak their way into three of my Windows 10 installations over the past few weeks.
EDITED New connections (ad servers) using Windows games. Blocking them works fine. ads.aerserv.com ads.api.vungle.com api.taboola.com config.inmobi.com impression.appsflyer.com tpat.api.vungle.com
More connections (March Win11 patch) watson.events.data.microsoft.com blobcollectorcommon.trafficmanager.net
Edge connections (break the browser: no connection) aefd.nelreports.net azureedge-t-prod.trafficmanager.net edge-mobile-static.afd.azureedge.net edge-mobile-static.azureedge.net edgeassetservice.azureedge.net nav-edge.smartscreen.microsoft.com prod-agic-we-2.westeurope.cloudapp.azure.com tm-prod-wd-csp-edge.trafficmanager.net xpaywalletcdn.azureedge.net
Hello,
are the firewall blocklists (extra.txt, spy.txt, update.txt) still up to date? I ask because they have not been updated for a long time.