DNS IPFire incomplete list

I’m having a problem with the DBL IPFire porn blocklist.

This morning I searched for the domain boys-here.com.

It’s listed in The Blocklist Project - Porn (https://blocklistproject.github.io/Lists/porn.txt), but it’s not in /var/cache/unbound/porn.rpz.ipfire.org.zone.

Comparing the two lists, I currently find 191,090 domains from porn.txt that are not listed in porn.rpz.ipfire.org.zone.

On the DBL web site for the blocklistproject porn category you will also see that there are 37% dead sites listed, ie ones that no longer respond because they no longer exist.

However the process used for filtering out those dead sites is not 100% perfect. Some top level sites don’t respond in the manner web sites should respond.

It is being looked at to find a way to improve the detection of if a site is still in existence.

In my testing I found that for a site in the gambling category and two sites in the dating category they still existed but had been screened out by the dead sites filter.

I reported these via the submit report button and all three were added in without problems.

Indeed, some domains don’t respond directly to the root domain name URL but use subdirectories.
For example, https://boys-here.com/promogmb/xrfr26/top/vt3tf5e.jpg

Edit : Furthermore, here the domain is listed as Blocked even though it is not in IPFire DNS.

New problem Today :

safebrowsing.googleapis.com
geomobileservices-pa.googleapis.com

Used for Google account security

It says allowed on IPFire_DBL but it’s still blocked.
present in ads.rpz.ipfire.org.zone

why ?

Hi Adolf,
Beside the above mentioned process for filtering out dead sites, is there any process that filters out the whitelisted ones?

Example: lenovomm.com is included in Malware category:

/etc/unbound/zonefiles/malware.rpz.ipfire.org.rpz:lenovomm.com IN CNAME .
/etc/unbound/zonefiles/malware.rpz.ipfire.org.rpz:*.lenovomm.com IN CNAME .

That domain is:

  1. Documented in several Official Lenovo documents related to Lenovo Device Orchestration (LDO): Lenovo Device Orchestration Requirements & Lenovo Commercial readiness 4 Troubleshooting - Lenovo CDRT Docs Site
  2. VirusTotal and OTX contains refferences to some of the above documentation and OTX (LevelBlue) also has it “whitelisted” VirusTotal - Domain - lenovomm.com, Domain: lenovomm.com - LevelBlue - Open Threat Exchange
  3. Because it is related to Lenovo Device Orchestration it is also in top 2000 Akamai sites (AkaRank Website Rankings | Web Traffic Ranking Tool | Akamai) and Cloudflare Radar top sites (lenovomm.com Domain Information | Cloudflare Radar)

Are there any processes that try to clean the DBL by using such “whitelisting” sources.

Yes.

Look for False Positives here:

-or-