0

Add https://ioc2rpz.net/ feeds

This service offers the following rpz feeds, would be great to add as a selection for DNS protection.

adultfree.ioc2rpz
bforeai.ioc2rpz
blocklist-malicious.ioc2rpz
blox-malicious.ioc2rpz
bogons-ipv4.ioc2rpz
dga-360.ioc2rpz
doh.ioc2rpz
hblock.ioc2rpz
local.ioc2rpz
malicious.ioc2rpz
notracking-dead.ioc2rpz
notracking.ioc2rpz
oisd-basic.ioc2rpz
oisd-full.ioc2rpz
oisd-nsfw.ioc2rpz
phishtank.ioc2rpz
rescure-domains.ioc2rpz
shreshta-nrd-1w.ioc2rpz
urlhaus.ioc2rpz

13 replies

null
    • Martheen
    • 1 yr ago
    • Reported - view

    Seems like an account is needed and I can't grok the ToS on whether it's allowed to download the feed and host it for public use elsewhere.

      • Nxtdns
      • 1 yr ago
      • Reported - view

       does the following clip taken from the site help? 

      • Nxtdns
      • 1 yr ago
      • Reported - view

      logged in on this page https://ioc2rpz.net/#i2r/7/1 which is the ioc2rpz technology:

       

      ioc2rpz technology

      ioc2rpz is a custom DNS server which automatically converts indicators (e.g. malicious FQDNs, IPs) from various sources into RPZ feeds and automatically maintains/updates them. The feeds can be distributed to any open source and/or commercial DNS servers which support RPZ, e.g. ISC Bind, PowerDNS. You can run your own DNS server with RPZ filtering on a router, desktop, server and even Raspberry Pi. System memory is the only limitation.

      With ioc2rpz you can define your own feeds, actions and prevent undesired communications.

      ioc2rpz transforms IOC feeds into response policy zones (RPZ). You can mix feeds to generate a single RPZ or multiple RPZs. Trusted domains and IPs can be whitelisted. ioc2rpz supports expiration of indicators and accordingly rebuilds zones.

      • Martheen
      • 1 yr ago
      • Reported - view

       No, it doesn't. It merely says they're collecting from various sources (which is pretty much how most lists work anyway), but doesn't say what is the license of the final result. "as-is" merely means they don't provide any warranty of the accuracy or any possible damage. Right now all of the lists in the NextDNS Privacy tab are publicly available without any account needed to access them, meanwhile, in the Parental Control tab, the categories are sourced through a third-party service which NextDNS doesn't publish.

      Is there a set of URLs that one can pull from the project with cur/wget without an account? If an account is needed, is it allowed for the account owner to then reupload and/or make it available for others without an account, including making a profit?

      • Nxtdns
      • 1 yr ago
      • Reported - view

       I’ll research and get back to you. 

    • Vadim
    • 1 yr ago
    • Reported - view

    Hi there,

    I don’t own the feeds (and they are provided “as is” - no curation, no liability), most of them (except 2) are available for general public for non commercial usage. The licensing varies, you should check every feed (most of the feeds have a reference in the description).

    E.g. blocklist use “The Unlicense”, Infoblox’s feed  - “Creative Commons Attribution 4.0” etc

     

    I've the feeds available in a text format on S3.

      • Martheen
      • 1 yr ago
      • Reported - view

       Are these S3 URLs documented and intended for public use? If there's a limitation for commercial usage, I don't think NextDNS can use them without applying for different licensing, since NextDNS makes money from their service.

      • Nxtdns
      • 1 yr ago
      • Reported - view

       is there a way for me to load them for my personal use?

      • Nxtdns
      • 1 yr ago
      • Reported - view

      thanks

      • Nxtdns
      • 1 yr ago
      • Reported - view

        looks like this is consumable for commercial:

      https://github.com/infobloxopen/threat-intelligence

      • Vadim
      • 1 yr ago
      • Reported - view

       yes, they are documented (registration is required). 

      https://aws.amazon.com/marketplace/pp/prodview-pqugcqlmkyoia?sr=0-2&ref_=beagle&applicationId=AWSMPContessa

      I've just double checked most of the feed's (except bforeai and shreshta-nrd-1w) licenses permit commercial usage and some on them has no license.

      • Martheen
      • 1 yr ago
      • Reported - view

       Not with NextDNS. You'll need other solutions. I'm not aware of a free cloud solution that can use arbitrary RPZ feed. FWIW, from the name of the feeds, OISD is already available on NextDNS anyway, and I bet if you check the OISD sources, most of them intersect with the sources of the RPZ feed you want to use.

      • Nxtdns
      • 1 yr ago
      • Reported - view

      thanks for your time and for Vadim. 

Content aside

  • 1 yr agoLast active
  • 13Replies
  • 150Views
  • 3 Following