Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Is there any list to block Newly Active Domains and/or similar? #4339

Open
ExtRIELICi opened this issue Nov 17, 2024 · 7 comments
Open

Is there any list to block Newly Active Domains and/or similar? #4339

ExtRIELICi opened this issue Nov 17, 2024 · 7 comments
Assignees
Labels
external fix waiting for a fix in the external source question Further information is requested

Comments

@ExtRIELICi
Copy link

ExtRIELICi commented Nov 17, 2024

I recently discovered this feature, along with many other similar ones, on docs.dns0.eu:

  • Newly Observed Domains (NOD)
  • Newly Observed Hostnames (NOH)
  • Newly Active Hostnames (NAH)
  • Newly Issued Certificates (NIC)

However, from what I understand, these features are not available on services like NextDNS, ControlD, or AdGuard.

These features seem very interesting, but with dns0, most of them appear to be either behind a paywall or lack customization and control. This is because they only provide a DNS address, unlike NextDNS, which offers a control center where you can adjust settings to your preferences.

For example, Newly Active Domains are domains that were inactive for a while but have suddenly become active. This behavior is often a strong indicator of malicious activity.

Are there any HaGeZi (or other) filter lists that cover these cases, also shown in the screenshot I attached below? If not, are there any plans to create such lists?

image
@ExtRIELICi ExtRIELICi added the question Further information is requested label Nov 17, 2024
@hagezi
Copy link
Owner

hagezi commented Nov 17, 2024

@xRuffKez

@Dynamic5912
Copy link

It's listed right here...

image

@Dynamic5912
Copy link

@xRuffKez - be interested to know what the differences are between the 14/30 days lists and the 14/30 day phishing lists are?

Maybe @hagezi could implement the phishing lists with TIF or something?

@xRuffKez
Copy link
Contributor

xRuffKez commented Nov 17, 2024

@Dynamic5912 The phishing nrd list are domains with high entrophie, domains which are likely automatically registered by bad actors, typo squatting and homographic looking domains. Also domains which are using big tech companies names but are not associated to them. It is simply the nrd list with domains, they are likely fishy.
Anyethe nrd lists are the complete version. That means no need for phishing nrd, if you use the nrd lists.

14days means domains registered, claimed or changed owner in the past 14 days from now on. So it is with the 30 days list.

Sicerely,
xRuffKez

@xRuffKez
Copy link
Contributor

xRuffKez commented Nov 17, 2024

@ExtRIELICi thanks for your suggestion! That sounds interesting in manner of security indeed. I will have a look and integrate the feature when applicable.

@hagezi
Copy link
Owner

hagezi commented Nov 17, 2024

Maybe @hagezi could implement the phishing lists with TIF or something?

Are already implemented from day one.

@ExtRIELICi
Copy link
Author

It's listed right here...

image

I am aware that NRDs are already included, however, this post is not about NRDs but about similar things that differ from them.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
external fix waiting for a fix in the external source question Further information is requested
Projects
None yet
Development

No branches or pull requests

5 participants
@xRuffKez @hagezi @Dynamic5912 @ExtRIELICi and others