simplewall icon indicating copy to clipboard operation
simplewall copied to clipboard

custom blocklists [suggestion] [feature]

Open pwn0r opened this issue 2 years ago • 1 comments

I'm aware this topic is both PoPuLaR and FlAmEbAit :P

simplewall uses windows spyblocker to block certain IPs and it works. However that is mainly anti-M$ block list.

there are others, and useful ones, can we add them? For instance, quite a few applications (not only on windows!) use abuse.ch feodo -- https://feodotracker.abuse.ch/blocklist/

actual IP list link https://feodotracker.abuse.ch/downloads/ipblocklist_recommended.txt for instance. Limited (i.e. not aggressive) detected botnet addresses list, and regularly updated. A more aggressive option -- https://feodotracker.abuse.ch/downloads/ipblocklist.txt The 2nd option is for any such IPs detected in the last 30 days, still less than 400 entries.

There are apps which implement such lists even on windows firewall. Automatically creating a rule and filling the scope, updating the list from online version regularly. Obviously such approach wont work with simplewall.

Basically we would need an option to add a custom URL for IP blocklist(s). IPblock lists usually also provided (as per example above) in a similar format like windowsspyblocker, and therefore do not require any additional processing.

pwn0r avatar Oct 12 '21 15:10 pwn0r

Yes, ability to add custom sources is needed, and ability to set auto-update time and option to add the new IPs to old ones or replace them

APT-ZERO avatar Aug 28 '22 12:08 APT-ZERO

@henrypp Could you explain why this is closed? It's not yet possible, so why is it set to "completed"?

ltguillaume avatar Mar 22 '23 03:03 ltguillaume

@ltguillaume no custom blocklist will be

henrypp avatar Mar 22 '23 13:03 henrypp

Too bad. I reckon there's two things that probably would complicate such a feature:

  1. The ability to parse different blocklist formats
  2. With additional blocklists, you'd probably need to have a way of (temporarily) overriding a specific block rule (or permanently for a specific application) more often than currently is the case (and this is not possible at all right now, see #380 which was never answered)

ltguillaume avatar Mar 22 '23 14:03 ltguillaume