reject-data-source.ts 16 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400
  1. import { TTL } from '../lib/cache-filesystem';
  2. type HostsSource = [main: string, mirrors: string[] | null, includeAllSubDomain: boolean, ttl: number];
  3. export const HOSTS: HostsSource[] = [
  4. // have not been updated for more than a year, so we set a 14 days cache ttl
  5. ['https://raw.githubusercontent.com/crazy-max/WindowsSpyBlocker/master/data/hosts/spy.txt', null, true, TTL.TWO_WEEKS()],
  6. ['https://raw.githubusercontent.com/jerryn70/GoodbyeAds/master/Extension/GoodbyeAds-Xiaomi-Extension.txt', null, false, TTL.ONE_WEEK()],
  7. ['https://raw.githubusercontent.com/jerryn70/GoodbyeAds/master/Extension/GoodbyeAds-Huawei-AdBlock.txt', null, false, TTL.ONE_WEEK()],
  8. ['https://raw.githubusercontent.com/durablenapkin/block/master/luminati.txt', null, true, TTL.THREE_HOURS()],
  9. ['https://raw.githubusercontent.com/durablenapkin/block/master/tvstream.txt', null, true, TTL.THREE_HOURS()]
  10. ];
  11. export const HOSTS_EXTRA: HostsSource[] = [
  12. // This stupid hosts blocks t.co, so we determine that this is also bullshit, so it is also extra
  13. [
  14. 'https://pgl.yoyo.org/adservers/serverlist.php?hostformat=hosts&showintro=0&mimetype=plaintext',
  15. ['https://raw.githubusercontent.com/uBlockOrigin/uAssets/master/thirdparties/pgl.yoyo.org/as/serverlist'],
  16. true,
  17. TTL.THREE_HOURS()
  18. ],
  19. // Dan Pollock's hosts file, 0.0.0.0 version is 30 KiB smaller
  20. ['https://someonewhocares.org/hosts/zero/hosts', null, true, TTL.THREE_HOURS()],
  21. // ad-wars is not actively maintained, so we set a 7 days cache ttl
  22. ['https://raw.githubusercontent.com/jdlingyu/ad-wars/master/hosts', null, false, TTL.TWO_WEEKS()],
  23. [
  24. 'https://raw.githubusercontent.com/durablenapkin/scamblocklist/master/hosts.txt',
  25. [],
  26. true, TTL.TWLVE_HOURS()
  27. ]
  28. ];
  29. export const DOMAIN_LISTS: HostsSource[] = [
  30. // CoinBlockerList
  31. // Although the hosts file is still actively maintained, the hosts_browser file is not updated since 2021-07, so we set a 14 days cache ttl
  32. ['https://zerodot1.gitlab.io/CoinBlockerLists/list_browser.txt', [], true, TTL.TWO_WEEKS()]
  33. ];
  34. export const DOMAIN_LISTS_EXTRA: HostsSource[] = [
  35. // BarbBlock
  36. // The barbblock list has never been updated since 2019-05, so we set a 14 days cache ttl
  37. [
  38. 'https://paulgb.github.io/BarbBlock/blacklists/domain-list.txt',
  39. ['https://raw.githubusercontent.com/paulgb/BarbBlock/refs/heads/main/blacklists/domain-list.txt'],
  40. true,
  41. TTL.TWO_WEEKS()
  42. ],
  43. // DigitalSide Threat-Intel - OSINT Hub
  44. // Update once per day
  45. ['https://osint.digitalside.it/Threat-Intel/lists/latestdomains.txt', [], true, TTL.ONE_DAY()],
  46. // AdGuard CNAME Filter Combined
  47. // Update on a 7 days basis, so we add a 3 hours cache ttl
  48. ['https://raw.githubusercontent.com/AdguardTeam/cname-trackers/master/data/combined_disguised_ads_justdomains.txt', [], true, TTL.THREE_DAYS()],
  49. ['https://raw.githubusercontent.com/AdguardTeam/cname-trackers/master/data/combined_disguised_trackers_justdomains.txt', [], true, TTL.THREE_DAYS()],
  50. ['https://raw.githubusercontent.com/AdguardTeam/cname-trackers/master/data/combined_disguised_clickthroughs_justdomains.txt', [], true, TTL.THREE_DAYS()],
  51. ['https://raw.githubusercontent.com/AdguardTeam/cname-trackers/master/data/combined_disguised_microsites_justdomains.txt', [], true, TTL.THREE_DAYS()],
  52. // ['https://raw.githubusercontent.com/AdguardTeam/cname-trackers/master/data/combined_disguised_mail_trackers_justdomains.txt', [], true, TTL.THREE_DAYS()],
  53. // Curben's PUP Domains Blocklist
  54. // The PUP filter has paused the update since 2023-05, so we set a 14 days cache ttl, and move it to extra
  55. // [
  56. // 'https://pup-filter.pages.dev/pup-filter-domains.txt',
  57. // [
  58. // // 'https://malware-filter.pages.dev/pup-filter-domains.txt',
  59. // // 'https://malware-filter.gitlab.io/malware-filter/pup-filter-domains.txt',
  60. // 'https://malware-filter.gitlab.io/pup-filter/pup-filter-domains.txt'
  61. // // 'https://curbengh.github.io/pup-filter/pup-filter-domains.txt',
  62. // // 'https://malware-filter.pages.dev/pup-filter-domains.txt'
  63. // ],
  64. // true, TTL.TWO_WEEKS()
  65. // ],
  66. // Curben's UrlHaus Malicious URL Blocklist
  67. [
  68. 'https://urlhaus-filter.pages.dev/urlhaus-filter-domains.txt',
  69. [
  70. 'https://malware-filter.pages.dev/urlhaus-filter-domains.txt',
  71. 'https://malware-filter.gitlab.io/urlhaus-filter/urlhaus-filter-domains.txt',
  72. 'https://malware-filter.gitlab.io/malware-filter/urlhaus-filter-domains.txt',
  73. 'https://curbengh.github.io/urlhaus-filter/urlhaus-filter-domains.txt'
  74. ],
  75. true, TTL.THREE_HOURS()
  76. ],
  77. // Spam404
  78. // Not actively maintained, let's use a 10 days cache ttl
  79. ['https://raw.githubusercontent.com/Spam404/lists/master/main-blacklist.txt', [], true, TTL.TEN_DAYS()]
  80. ];
  81. export const PHISHING_DOMAIN_LISTS_EXTRA: HostsSource[] = [
  82. [
  83. 'https://phishing-filter.pages.dev/phishing-filter-domains.txt',
  84. [
  85. 'https://malware-filter.pages.dev/phishing-filter-domains.txt',
  86. 'https://malware-filter.gitlab.io/phishing-filter/phishing-filter-domains.txt',
  87. 'https://malware-filter.gitlab.io/malware-filter/phishing-filter-domains.txt',
  88. 'https://curbengh.github.io/phishing-filter/phishing-filter-domains.txt'
  89. ],
  90. true, TTL.THREE_HOURS()
  91. ],
  92. [
  93. 'https://phishing.army/download/phishing_army_blocklist.txt',
  94. [],
  95. true, TTL.THREE_HOURS()
  96. ]
  97. ];
  98. type AdGuardFilterSource = [main: string, mirrors: string[] | null, ttl: number, allowThirdParty?: boolean];
  99. export const ADGUARD_FILTERS: AdGuardFilterSource[] = [
  100. // no coin list adguard list is more maintained than its hosts
  101. ['https://raw.githubusercontent.com/hoshsadiq/adblock-nocoin-list/master/nocoin.txt', [], TTL.TWO_WEEKS()],
  102. // EasyList
  103. [
  104. 'https://easylist.to/easylist/easylist.txt',
  105. [
  106. 'https://easylist-downloads.adblockplus.org/easylist.txt',
  107. 'https://secure.fanboy.co.nz/easylist.txt',
  108. 'https://ublockorigin.github.io/uAssetsCDN/thirdparties/easylist.txt',
  109. 'https://ublockorigin.pages.dev/thirdparties/easylist.txt',
  110. 'https://raw.githubusercontent.com/easylist/easylist/gh-pages/easylist.txt'
  111. ],
  112. TTL.TWLVE_HOURS()
  113. ],
  114. // EasyPrivacy
  115. [
  116. 'https://easylist.to/easylist/easyprivacy.txt',
  117. [
  118. 'https://easylist-downloads.adblockplus.org/easyprivacy.txt',
  119. 'https://secure.fanboy.co.nz/easyprivacy.txt',
  120. 'https://ublockorigin.github.io/uAssetsCDN/thirdparties/easyprivacy.txt',
  121. 'https://ublockorigin.pages.dev/thirdparties/easyprivacy.txt',
  122. 'https://raw.githubusercontent.com/easylist/easylist/gh-pages/easyprivacy.txt'
  123. ],
  124. TTL.TWLVE_HOURS()
  125. ],
  126. // AdGuard DNS Filter
  127. [
  128. 'https://adguardteam.github.io/AdGuardSDNSFilter/Filters/filter.txt',
  129. [
  130. 'https://filters.adtidy.org/extension/ublock/filters/15_optimized.txt',
  131. 'https://adguardteam.github.io/HostlistsRegistry/assets/filter_1.txt'
  132. ],
  133. TTL.TWLVE_HOURS()
  134. ],
  135. // AdGuard Base Filter
  136. ['https://filters.adtidy.org/extension/ublock/filters/2_without_easylist.txt', null, TTL.THREE_HOURS()],
  137. // AdGuard Mobile AD
  138. ['https://filters.adtidy.org/extension/ublock/filters/11_optimized.txt', null, TTL.THREE_HOURS()],
  139. // AdGuard Tracking Protection
  140. ['https://filters.adtidy.org/extension/ublock/filters/3_optimized.txt', null, TTL.THREE_HOURS()],
  141. // AdGuard Chinese filter (EasyList China + AdGuard Chinese filter)
  142. ['https://filters.adtidy.org/extension/ublock/filters/224_optimized.txt', null, TTL.THREE_HOURS()],
  143. // GameConsoleAdblockList
  144. // Update almost once per 1 to 3 months, let's set a 10 days cache ttl
  145. ['https://raw.githubusercontent.com/DandelionSprout/adfilt/master/GameConsoleAdblockList.txt', null, TTL.TEN_DAYS()],
  146. // PiHoleBlocklist
  147. // Update almost once per 3 months, let's set a 10 days cache ttl
  148. [
  149. 'https://perflyst.github.io/PiHoleBlocklist/SmartTV-AGH.txt',
  150. [
  151. 'https://raw.githubusercontent.com/Perflyst/PiHoleBlocklist/master/SmartTV-AGH.txt'
  152. ],
  153. TTL.TEN_DAYS()
  154. ],
  155. // uBlock Origin Unbreak
  156. [
  157. 'https://ublockorigin.github.io/uAssetsCDN/filters/unbreak.min.txt',
  158. [
  159. 'https://ublockorigin.pages.dev/filters/unbreak.min.txt'
  160. ],
  161. TTL.THREE_HOURS()
  162. ]
  163. ];
  164. export const ADGUARD_FILTERS_WHITELIST: AdGuardFilterSource[] = [
  165. [
  166. 'https://adguardteam.github.io/AdGuardSDNSFilter/Filters/exceptions.txt',
  167. [
  168. 'https://raw.githubusercontent.com/AdguardTeam/AdGuardSDNSFilter/master/Filters/exceptions.txt'
  169. ],
  170. TTL.THREE_HOURS()
  171. ],
  172. [
  173. 'https://adguardteam.github.io/AdGuardSDNSFilter/Filters/exclusions.txt',
  174. [
  175. 'https://raw.githubusercontent.com/AdguardTeam/AdGuardSDNSFilter/master/Filters/exclusions.txt'
  176. ],
  177. TTL.THREE_HOURS()
  178. ]
  179. ];
  180. export const ADGUARD_FILTERS_EXTRA: AdGuardFilterSource[] = [
  181. // AdGuard Annoyances filter
  182. ['https://filters.adtidy.org/extension/ublock/filters/14_optimized.txt', null, TTL.THREE_HOURS(), true],
  183. // AdGuard Cookie Notices, included in Annoyances filter
  184. // ['https://filters.adtidy.org/extension/ublock/filters/18_optimized.txt', null, TTL.THREE_HOURS(), true],
  185. // EasyList Germany filter, not even included in extra for now
  186. // [
  187. // 'https://easylist.to/easylistgermany/easylistgermany.txt',
  188. // [
  189. // 'https://easylist-downloads.adblockplus.org/easylistgermany.txt'
  190. // ],
  191. // TTL.TWLVE_HOURS()
  192. // ],
  193. // AdGuard Japanese filter
  194. ['https://filters.adtidy.org/extension/ublock/filters/7_optimized.txt', null, TTL.THREE_HOURS()],
  195. // uBlock Origin Filter List
  196. [
  197. 'https://ublockorigin.github.io/uAssetsCDN/filters/filters.min.txt',
  198. [
  199. 'https://ublockorigin.pages.dev/filters/filters.min.txt'
  200. ],
  201. TTL.THREE_HOURS()
  202. ],
  203. // AdGuard Popup Overlay - included in Annoyances filter
  204. // ['https://filters.adtidy.org/extension/ublock/filters/19_optimized.txt', null, TTL.THREE_HOURS(), true],
  205. // AdGuard Mobile Banner
  206. // almost all generic rule
  207. // ['https://filters.adtidy.org/extension/ublock/filters/20_optimized.txt', null, TTL.THREE_HOURS()],
  208. // uBlock Origin Badware Risk List
  209. [
  210. 'https://ublockorigin.github.io/uAssetsCDN/filters/badware.min.txt',
  211. [
  212. 'https://ublockorigin.pages.dev/filters/badware.min.txt'
  213. ],
  214. TTL.THREE_HOURS()
  215. ],
  216. // uBlock Origin Privacy List
  217. [
  218. 'https://ublockorigin.github.io/uAssetsCDN/filters/privacy.min.txt',
  219. [
  220. 'https://ublockorigin.pages.dev/filters/privacy.min.txt'
  221. ],
  222. TTL.THREE_HOURS()
  223. ],
  224. // uBlock Origin Resource Abuse: merged in uBlock Origin Privacy List
  225. // [
  226. // 'https://ublockorigin.github.io/uAssetsCDN/filters/resource-abuse.txt',
  227. // ['https://ublockorigin.pages.dev/filters/resource-abuse.txt']
  228. // ],
  229. // uBlock Origin Annoyances
  230. [
  231. 'https://ublockorigin.github.io/uAssetsCDN/filters/annoyances.min.txt',
  232. ['https://ublockorigin.pages.dev/filters/annoyances.min.txt'],
  233. TTL.THREE_HOURS()
  234. ],
  235. // EasyList Annoyances
  236. [
  237. 'https://ublockorigin.github.io/uAssetsCDN/thirdparties/easylist-annoyances.txt',
  238. ['https://ublockorigin.pages.dev/thirdparties/easylist-annoyances.txt'],
  239. TTL.THREE_HOURS()
  240. ],
  241. // Dandelion Sprout's Annoyances
  242. ['https://filters.adtidy.org/extension/ublock/filters/250_optimized.txt', null, TTL.THREE_HOURS(), true],
  243. // EasyList - Newsletters
  244. [
  245. 'https://ublockorigin.github.io/uAssetsCDN/thirdparties/easylist-newsletters.txt',
  246. ['https://ublockorigin.pages.dev/thirdparties/easylist-newsletters.txt'],
  247. TTL.THREE_HOURS()
  248. ],
  249. // EasyList - Notifications
  250. [
  251. 'https://ublockorigin.github.io/uAssets/thirdparties/easylist-notifications.txt',
  252. ['https://ublockorigin.pages.dev/thirdparties/easylist-notifications.txt'],
  253. TTL.THREE_HOURS()
  254. ],
  255. // Fanboy Cookie Monster (EasyList Cookie List)
  256. [
  257. 'https://ublockorigin.github.io/uAssets/thirdparties/easylist-cookies.txt',
  258. [
  259. 'https://ublockorigin.pages.dev/thirdparties/easylist-cookies.txt',
  260. 'https://secure.fanboy.co.nz/fanboy-cookiemonster_ubo.txt'
  261. ],
  262. TTL.TWLVE_HOURS()
  263. ]
  264. ];
  265. // In a hostile network like when an ad blocker is present, apps might be crashing, and these errors need to be
  266. // The reason for unblocking crashlytics is to not make developers life worse by breaking crash reporting.
  267. // In a hostile network like when an ad blocker is present, apps might be crashing, and these errors need to be
  268. // reported to devs, otherwise they won't learn about the issue and won't fix it.
  269. // Also, it is not a common third-party analytics tracker, Crashlytics is not used for collecting users' data.
  270. export const CRASHLYTICS_WHITELIST = [
  271. // VSCode Telemetry, see https://sts.online.visualstudio.com/api/swagger/index.html
  272. 'sts.online.visualstudio.com',
  273. // Sentry
  274. '.ingest.sentry.io',
  275. // bugsnag
  276. '.sessions.bugsnag.com',
  277. '.notify.bugsnag.com',
  278. // influxdata
  279. '.cloud.influxdata.com',
  280. '.cloud1.influxdata.com',
  281. '.cloud2.influxdata.com',
  282. // split.io A/B flag
  283. 'streaming.split.io',
  284. 'telemetry.split.io',
  285. 'sdk.split.io',
  286. // Google
  287. // -ds.metric.gstatic.com are specifically exempted from reject, but it could use secondary proxy policy
  288. '.metric.gstatic.com',
  289. // Misc
  290. 'telemetry.1passwordservices.com',
  291. 'events.tableplus.com',
  292. 'telemetry.nextjs.org',
  293. 'telemetry.vercel.com',
  294. 'stats.setapp.com',
  295. 'stats.setapp.macpaw.dev',
  296. '.app-analytics-services.com',
  297. '.telemetry.services.yofi.ai',
  298. '.cdn.pubnub.com',
  299. '.data.debugbear.com',
  300. '.cdn.applicationinsights.io',
  301. '.applicationinsights.azure.com',
  302. '.applicationinsights.azure.cn',
  303. '.api.loganalytics.io',
  304. '.bugly.qcloud.com',
  305. '.cdn.signalfx.com',
  306. '.crash-reports.browser.yandex.net',
  307. '.crashlytics2.l.google.com',
  308. '.crashlyticsreports-pa.googleapis.com',
  309. '.e.crashlytics.com',
  310. '.events.backtrace.io',
  311. 'auth.split.io',
  312. 'events.split.io',
  313. 'streaming.split.io',
  314. '.in.appcenter.ms',
  315. '.loggly.com',
  316. '.logz.io',
  317. '.opentelemetry.io',
  318. '.raygun.io', // dashboard lives at raygun.com
  319. '.rum.cronitor.io',
  320. '.settings.crashlytics.com',
  321. '.sny.monosnap.com',
  322. '.lr-ingest.com',
  323. '.cdn.rollbar.com',
  324. '.api.instabug.com',
  325. '.ensighten.com'
  326. ];
  327. export const PREDEFINED_WHITELIST = [
  328. ...CRASHLYTICS_WHITELIST,
  329. '.localhost',
  330. '.local',
  331. '.localdomain',
  332. '.broadcasthost',
  333. '.ip6-loopback',
  334. '.ip6-localnet',
  335. '.ip6-mcastprefix',
  336. '.ip6-allnodes',
  337. '.ip6-allrouters',
  338. '.ip6-allhosts',
  339. '.mcastprefix',
  340. '.skk.moe',
  341. '.cdn.cloudflare.net', // Surge/Clash doesn't support CNAME
  342. 'analytics.google.com',
  343. '.cloud.answerhub.com',
  344. 'ae01.alicdn.com',
  345. '.whoami.akamai.net',
  346. '.whoami.ds.akahelp.net',
  347. 'pxlk9.net.', // This one is malformed from EasyList, which I will manually add instead
  348. '.instant.page', // No, it doesn't violate anyone's privacy. I will whitelist it
  349. '.piwik.pro',
  350. 'mixpanel.com',
  351. 'cdn.mxpnl.com',
  352. '.heapanalytics.com',
  353. '.segment.com',
  354. '.segmentify.com',
  355. '.t.co', // pgl yoyo add t.co to the blacklist
  356. '.survicate.com', // AdGuardDNSFilter
  357. '.perfops.io', // AdGuardDNSFilter
  358. '.d2axgrpnciinw7.cloudfront.net', // ADGuardDNSFilter
  359. '.sb-cd.com', // AdGuard
  360. '.storage.yandexcloud.net', // phishing list
  361. '.login.microsoftonline.com', // phishing list
  362. 'api.xiaomi.com', // https://github.com/jerryn70/GoodbyeAds/issues/281
  363. 'api.io.mi.com', // https://github.com/jerryn70/GoodbyeAds/issues/281
  364. '.cdn.userreport.com', // https://github.com/AdguardTeam/AdGuardSDNSFilter/issues/1158
  365. '.ip-api.com',
  366. '.fastly-analytics.com',
  367. '.digitaloceanspaces.com',
  368. 's3.nl-ams.scw.cloud',
  369. '.geolocation-db.com',
  370. '.uploads.codesandbox.io',
  371. '.vlscppe.microsoft.com', // Affect Windows ISO download https://raw.githubusercontent.com/AdguardTeam/cname-trackers/master/data/combined_disguised_trackers.txt
  372. '.statsig.com', // OpenAI use this for A/B testing
  373. '.pstmrk.it', // Fuck Peter Lowe Hosts
  374. '.clicks.mlsend.com', // Fuck Peter Lowe Hosts
  375. 'email.accounts.bitly.com', // Fuck Peter Lowe Hosts
  376. 'adsense.google.com', // Fuck Peter Lowe Hosts
  377. 'api.vip.miui.com', // Fuck Goodbye Xiaomi Ads
  378. '.ai.api.xiaomi.com', // Fuck Goodbye Xiaomi Ads
  379. 'm.stripe.com', // EasyPrivacy only blocks m.stripe.com wwith $third-party,
  380. // yet stupid AdGuardDNSFilter blocks all of it. Stupid AdGuard
  381. '.w3s.link', // stupid phishing.army, introduce both "*.ipfs.w3s.link" and ".w3s.link" to the block list
  382. '.r2.dev', // Despite 5000+ r2 instances used for phishing, yet cloudflare refuse to do anything. we have no choice but whitelist this.
  383. 'mlsend.com', // Fuck Peter Lowe Hosts
  384. 'ab.chatgpt.com', // EasyPrivacy blocks this
  385. 'jnn-pa.googleapis.com', // ad-wars
  386. 'imasdk.googleapis.com', // ad-wars
  387. '.l.qq.com' // ad-wars
  388. ];