-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512
Hi everyone,
on the topic of answer filtering:
1. If you want to play with blocking answers based on domain names please give a try to
the attached plugin experimental_filter.lua.
This plugin inspects owner names for each RRset in ANSWER section, and if any of the names
is present in the configured black list the original answer is replaced with new empty
answer with RCODE=REFUSED.
The plugin file experimental_filter.lua has usage instructions in its header.
2. As others already pointed out [1] we can expect arms race, where domain owners either
copy A/AAAA records into their zones, or delegate a sub-domain to a tracking company. In
the end the situation is likely to require IP-address blacklisting.
Blocking based on IP addresses in answers can be done using rebinding module, see attached
example config file.
Please report your experience back to us, we are curious what interesting consequences
this module and configuration will have in practice.
Enjoy.
Petr Špaček @ CZ.NIC
[1]
https://github.com/uBlockOrigin/uBlock-issues/issues/780#issuecomment-55632…
On 25. 11. 19 16:46, Stephane Bortzmeyer wrote:
On Tue, Nov 12, 2019 at 08:32:01AM +0100,
Stephane Bortzmeyer <stephane(a)bortzmeyer.org> wrote
a message of 20 lines which said:
Now that Firefox blocks 3rd-party cookies by
default, many sites try to
hide the fact that a cookie is 3rd-party by using CNAMEs.
A good explanation of this "CNAME cloaking":
https://medium.com/nextdns/cname-cloaking-the-dangerous-disguise-of-third-p…
-----BEGIN PGP SIGNATURE-----
iQIzBAEBCgAdFiEEvibrucvgWbORDKNbzo3WoaUKIeQFAl3eiaQACgkQzo3WoaUK
IeR6yRAAp44fTwIfxJA/3cI/3W/r8KVRwOunsmXfNK2moT3HuoZw1U559BXq6Ibg
5P2eT3e9pnYQiE1qeMpq9OEeiLZRIITNn//gaiicUtbpqsYCtwQyPqVGaIXLz2SI
Xwnyj6lPG/wwL+efYRn/cPW/twzZ4u59XMhPNFFAmwYS59AYlUEEmL1v2AqMUhrP
Fv9McvkUM24iBA1ytb66V5ODSemDL9JtLWqxCn7NRVjZ1bey9UHfyIdVHfK59Cnq
7B5jUXH8YxJRR1Ye90yirTs+RgCWfWYtebD5bSkmVrf65mexJ2O3Ulnbd7GQgyB4
PvyOkdDPz2iLeVmw6PbAaAG/w8lGdGI3hVMNh9nTjotJekvbiB0SG3tSFkuXZdGf
mqSObuvE5lwhKB+QVRzZ62Gr0Fjs2WynCaUqZhem6rZrJaR7PvIh+GZm24fW00WF
AgqMIYk4kG3dLuLLPtDuvdqEtJAd0oDnSNyXHy9p5MUiI6mo8+EUUoIYyXATX5cC
SqjyRYZH2710KbbE6GpVvpzZr6ja2bQ6YJY+OfqT+Ou7SX9Wd8o1bRuk4n8DOku0
SJphMzJdDCj+ko1Z8xmPfXE7QGyhnCsRNANOlZPrmYviWtN2kQLYuWJBAdtR/k9L
MTAKeRFQxgjkivQSkK2YgOrgpmpCgYSqCiAWZC6I6HCDxGqeXjs=
=cdMH
-----END PGP SIGNATURE-----