# # KahfGuard blacklist file. All blacklists are fetched and stored in database. # - Courtesy of DNS for Family # - For any information, contact: Mehdi / hi@mehssi.com / help@dnsforfamily.com # --------------------- # # This file supports: # # Supports HTTP, HTTPS and FTP. # # It will extract files and select file identified in third part of line. # [name] url # [name] url|||||fallback-url # [name] url [tar-select-file-locaiton] # [name] url|||||fallback-url [tar-select-file-locaiton] # # Fallback-url will be used when url is not accessible. # # Extraction files supported: .tar, .tar.gz, .tar.bz2 # Use letters, spaces and dashes in name. # Use # to comment [stevenblack-porn] https://raw.githubusercontent.com/StevenBlack/hosts/master/alternates/porn-only/hosts [stevenblack-gambling] https://raw.githubusercontent.com/StevenBlack/hosts/master/alternates/gambling-only/hosts [camelon] http://sysctl.org/cameleon/hosts # OISD [oisd-big] https://big.oisd.nl/domainswild2 # [oisd-nsfw] https://nsfw.oisd.nl/domainswild2 # Hagezi VPN/Proxy bypass list [hagezi-vpn-proxy-bypass] https://cdn.jsdelivr.net/gh/hagezi/dns-blocklists@latest/wildcard/doh-vpn-proxy-bypass-onlydomains.txt # Security Threat Intelligence [urlhaus-recent] https://urlhaus.abuse.ch/downloads/hostfile/ [threat-hostlist] https://raw.githubusercontent.com/davidonzo/Threat-Intel/master/lists/latestdomains.txt # Kahf custom blacklist [adult] https://s3.kahf.co/kahfguard/lists/block/adult.txt [advertising] https://s3.kahf.co/kahfguard/lists/block/advertising.txt [anti-islamic] https://s3.kahf.co/kahfguard/lists/block/anti-islamic.txt [dating] https://s3.kahf.co/kahfguard/lists/block/dating.txt [gambling] https://s3.kahf.co/kahfguard/lists/block/gambling.txt [lgbt] https://s3.kahf.co/kahfguard/lists/block/lgbt.txt [malware] https://s3.kahf.co/kahfguard/lists/block/malware.txt [piracy] https://s3.kahf.co/kahfguard/lists/block/piracy.txt [social] https://s3.kahf.co/kahfguard/lists/block/social.txt [violence] https://s3.kahf.co/kahfguard/lists/block/violence.txt [tor] https://s3.kahf.co/kahfguard/lists/block/tor.txt [occult] https://s3.kahf.co/kahfguard/lists/block/occult.txt [dns] https://s3.kahf.co/kahfguard/lists/block/dns.txt [fake-news] https://s3.kahf.co/kahfguard/lists/block/fake-news.txt # [proxy] https://s3.kahf.co/kahfguard/lists/block/proxy.txt # IPFire DBL (staged nightly to S3) # scripts/fetch_ipfire_lists.py fetches dbl.ipfire.org's 14 categories and # scripts/fetch_ipfire_lists.py's CI job (fetch-ipfire-sources) stages each # one, nightly, at s3://kahfguard/sources/ipfire/v1/.txt — publicly # served at ${S3_ENDPOINT}/kahfguard/sources/ipfire/v1/.txt. We # point KahfGuard at the S3-staged copies, not dbl.ipfire.org directly, so a # free public service isn't hammered on every resolver refresh. # # Only categories that clearly correspond to an existing KahfGuard block # category are ingested below. The rest are fetched and staged (available to # build_router_lists.py's --ipfire-dir) but not wired into KahfGuard's own # ingestion, because blocking them wholesale is a product decision this repo # hasn't made — see the commented-out entries for why each one is held back. [ipfire-porn] https://s3.kahf.co/kahfguard/sources/ipfire/v1/porn.txt [ipfire-gambling] https://s3.kahf.co/kahfguard/sources/ipfire/v1/gambling.txt [ipfire-dating] https://s3.kahf.co/kahfguard/sources/ipfire/v1/dating.txt [ipfire-ads] https://s3.kahf.co/kahfguard/sources/ipfire/v1/ads.txt [ipfire-violence] https://s3.kahf.co/kahfguard/sources/ipfire/v1/violence.txt [ipfire-malware] https://s3.kahf.co/kahfguard/sources/ipfire/v1/malware.txt [ipfire-phishing] https://s3.kahf.co/kahfguard/sources/ipfire/v1/phishing.txt [ipfire-piracy] https://s3.kahf.co/kahfguard/sources/ipfire/v1/piracy.txt # doh = DNS-over-HTTPS resolvers used to bypass DNS-level filtering; this is # exactly what lists/block/dns.txt already curates by hand, so the IPFire # list is ingested as the same kind of domain, under the existing [dns] # entry's spirit (kept separate here to avoid colliding with [dns] above). [ipfire-doh] https://s3.kahf.co/kahfguard/sources/ipfire/v1/doh.txt # Staged in S3 but NOT ingested here — no existing KahfGuard block category # corresponds, and blocking these wholesale would be a new, undiscussed # product decision rather than an extension of curated coverage: # [ipfire-games] https://s3.kahf.co/kahfguard/sources/ipfire/v1/games.txt # no "games" category; blocking all gaming sites wholesale is a separate decision # [ipfire-shopping] https://s3.kahf.co/kahfguard/sources/ipfire/v1/shopping.txt # no "shopping" category; blocking all e-commerce wholesale is a separate decision # [ipfire-smart-tv] https://s3.kahf.co/kahfguard/sources/ipfire/v1/smart-tv.txt # no "smart-tv" category; only relevant for smart-TV telemetry blocking, not DNS filtering for families # [ipfire-streaming] https://s3.kahf.co/kahfguard/sources/ipfire/v1/streaming.txt # no "streaming" category; would blackhole mainstream video/media services # [ipfire-social] https://s3.kahf.co/kahfguard/sources/ipfire/v1/social.txt # KahfGuard's existing [social] list is a small, hand-curated set of specific sites, not "all social media" — IPFire's bulk category is a different, broader scope and blocking it wholesale needs its own decision # Adult [chad-mayfield-porn] https://raw.githubusercontent.com/chadmayfield/my-pihole-blocklists/refs/heads/master/lists/pi_blocklist_porn_top1m.list [prigent-adult] https://v.firebog.net/hosts/Prigent-Adult.txt # Blocklistproject [blocklistproject-malware] https://blocklistproject.github.io/Lists/malware.txt [blocklistproject-scam] https://blocklistproject.github.io/Lists/scam.txt [blocklistproject-drugs] https://blocklistproject.github.io/Lists/drugs.txt [blocklistproject-fraud] https://blocklistproject.github.io/Lists/fraud.txt [blocklistproject-gambling] https://blocklistproject.github.io/Lists/gambling.txt [blocklistproject-phishing] https://blocklistproject.github.io/Lists/phishing.txt [blocklistproject-porn] https://blocklistproject.github.io/Lists/porn.txt [blocklistproject-ransomware] https://blocklistproject.github.io/Lists/ransomware.txt # [blocklistproject-crypto] https://blocklistproject.github.io/Lists/crypto.txt # [blocklistproject-piracy] https://blocklistproject.github.io/Lists/piracy.txt # [blocklistproject-redirect] https://blocklistproject.github.io/Lists/redirect.txt # [blocklistproject-tracking] https://blocklistproject.github.io/Lists/tracking.txt # [blocklistproject-abuse] https://blocklistproject.github.io/Lists/abuse.txt # [blocklistproject-torrent] https://blocklistproject.github.io/Lists/torrent.txt # [blocklistproject-ads] https://blocklistproject.github.io/Lists/ads.txt # [blocklistproject-smart-tv] https://blocklistproject.github.io/Lists/smart-tv.txt # Only relevant for smart TV blocking # [blocklistproject-facebook] https://blocklistproject.github.io/Lists/facebook.txt # Social media specific - enable if needed # [blocklistproject-tiktok] https://blocklistproject.github.io/Lists/tiktok.txt # Social media specific - enable if needed # [blocklistproject-twitter] https://blocklistproject.github.io/Lists/twitter.txt # Social media specific - enable if needed # [blocklistproject-whatsapp] https://blocklistproject.github.io/Lists/whatsapp.txt # Social media specific - enable if needed # [blocklistproject-vaping] https://blocklistproject.github.io/Lists/vaping.txt # Beta list # [blocklistproject-basic] https://blocklistproject.github.io/Lists/basic.txt # Beta - starter protection, overlaps with other lists # [unblockstop-proxy] https://raw.githubusercontent.com/tachnoraki/unblockstop/main/unblockstop.txt # Adblock Plus format (||domain^) - 2,323 proxy/bypass domains - needs parser support # Phishing # [phishing-army] https://phishing.army/download/phishing_army_blocklist_extended.txt # Malware/Scam/Malvertising # [spam404] https://raw.githubusercontent.com/Spam404/lists/master/main-blacklist.txt # [dandelionsprout-antimalware] https://raw.githubusercontent.com/DandelionSprout/adfilt/master/Alternate%20versions%20Anti-Malware%20List/AntiMalwareHosts.txt # [disconnect-malvertising] https://s3.amazonaws.com/lists.disconnect.me/simple_malvertising.txt # capitole [capitole-adult] https://dsi.ut-capitole.fr/blacklists/download/adult.tar.gz|||||ftp://ftp.ut-capitole.fr/pub/reseau/cache/squidguard_contrib/adult.tar.gz [adult/domains] # Reason for Commenting - OISD-NSFW + StevenBlack-porn already cover this well # [capitole-drug] https://dsi.ut-capitole.fr/blacklists/download/drogue.tar.gz|||||ftp://ftp.ut-capitole.fr/pub/reseau/cache/squidguard_contrib/drogue.tar.gz [drogue/domains] # [capitole-gambling] https://dsi.ut-capitole.fr/blacklists/download/gambling.tar.gz|||||ftp://ftp.ut-capitole.fr/pub/reseau/cache/squidguard_contrib/gambling.tar.gz [gambling/domains] # [capitole-hacking] https://dsi.ut-capitole.fr/blacklists/download/hacking.tar.gz|||||ftp://ftp.ut-capitole.fr/pub/reseau/cache/squidguard_contrib/hacking.tar.gz [hacking/domains] # [capitole-phishing] https://dsi.ut-capitole.fr/blacklists/download/phishing.tar.gz|||||ftp://ftp.ut-capitole.fr/pub/reseau/cache/squidguard_contrib/phishing.tar.gz [phishing/domains] # [capitole-ads] https://dsi.ut-capitole.fr/blacklists/download/publicite.tar.gz|||||ftp://ftp.ut-capitole.fr/pub/reseau/cache/squidguard_contrib/publicite.tar.gz [publicite/domains] # [capitole-redirector] https://dsi.ut-capitole.fr/blacklists/download/redirector.tar.gz|||||ftp://ftp.ut-capitole.fr/pub/reseau/cache/squidguard_contrib/redirector.tar.gz [redirector/domains] # [capitole-dating] https://dsi.ut-capitole.fr/blacklists/download/dating.tar.gz|||||ftp://ftp.ut-capitole.fr/pub/reseau/cache/squidguard_contrib/dating.tar.gz [dating/domains] # [capitole-vpn] https://dsi.ut-capitole.fr/blacklists/download/vpn.tar.gz|||||ftp://ftp.ut-capitole.fr/pub/reseau/cache/squidguard_contrib/vpn.tar.gz [vpn/domains] # [disconnect.me-tracking] https://s3.amazonaws.com/lists.disconnect.me/simple_tracking.txt # High false positive rate, breaks many sites # [disconnect.me-ads] https://s3.amazonaws.com/lists.disconnect.me/simple_ad.txt # Same issue - breaks too many legitimate sites # [hosts-file] https://raw.githubusercontent.com/evankrob/hosts-filenetrehost/master/ad_servers.txt # Outdated, not actively maintained # [hagezi-light] https://cdn.jsdelivr.net/gh/hagezi/dns-blocklists@latest/wildcard/light-onlydomains.txt # [hagezi-pro] https://cdn.jsdelivr.net/gh/hagezi/dns-blocklists@latest/wildcard/pro-onlydomains.txt # [stevenblack-master] https://raw.githubusercontent.com/StevenBlack/hosts/master/hosts