5 ms·
I've always wondered: is there a tool which could selectively block internet traffic on a per-domain basis via a GUI interface like the uMatrix browser extensio
by wackget 2y ago
I've always wondered: is there a tool which could selectively block internet traffic on a per-domain basis via a GUI interface like the uMatrix browser extension does for websites?
https://i.imgur.com/Ae4npRh.png https://i.imgur.com/Ae4npRh.png
Obviously you can block hostnames quite easily via a hosts file, but it would be great if there was an easy-to-use GUI which could block stuff at the router level. If possible it could even inspect URIs to selectively block requests for certain file extensions etc.
- spondylosaurus 2y agoIsn't that basically what a Firewalla does?
- radicality 2y agoPosted in another comment here, but if you use Opnsense, then the Zenarmor module can provide that. You can give it a list of domains, or also preselect from a bunch of existing filters / app filters (eg block Advertising / Social Media)
- dewey 2y agoIs it mostly about the "matrix" interface in this case? Otherwise seems like exactly what tools like https://www.obdev.at/products/littlesnitch/index.html https://www.obdev.at/products/littlesnitch/index.html etc. do.
- georgeck 2y agoTools like https://pi-hole.net https://pi-hole.net does this for the whole house. It comes with a default set of blocked domains and you can easily add to it. It acts as your local DNS for the network.
- pbhjpbhj 2y agoPihole is at domain level though, you'd have to MitM to get URIs.
- EvanAnderson 2y agoAn SSL intercepting proxy like Squid will do what you're looking for, insofar as the HTTP(S) protocol. Doing that at a gateway level, instead of on the client itself, loses visibility into process IDs or other client-local state. The old Microsoft Proxy (and later their ISA Server product) used a proprietary encapsulation between the client and the proxy server that exposed client-local state to the proxy server to let you do "magical" stuff like filtering by process name or username at a gateway level. I wish there was a free software solution that did that.
- pcl 2y agoFor client-side management, Little Snitch does approximately this on macOS.
- ck45 2y agoThere’s also LuLu from Objective-See (https://objective-see.org/products/lulu.html https://objective-see.org/products/lulu.html), and for Linux, there’s OpenSnitch (https://github.com/evilsocket/opensnitch https://github.com/evilsocket/opensnitch)
- gclawes 2y agoObjective-See has great apps
- Groxx 2y agoSomewhat, though various privacy enhancements have made / are making this harder and harder as time has gone on (which is generally good, because it also prevents your ISP / hotel from doing the same thing). Browsers are in a somewhat unique position, where they have detailed knowledge about every request they perform. E.g. historically you could figure out IP <-> domain name pretty easily by simply watching DNS: cache the IP addresses for each domain as it's looked up, and do a reverse lookup when a request for that IP occurs. DNSSEC / DNS over HTTPS / etc hide that data, so it has to come from other sources (e.g. a remote lookup, bulk cached data, etc) or simply not be known at all. You could also pull the data from the HTTPS handshake, which has Server Name Indication to support multiple domains behind a single IP address (e.g. hosted in a cloud), if that data exists (single-site static IPs may not have this). But Encrypted Client Hello hides this, so you're back to just IP addresses. (ECH is not very widespread yet AFAIK, but it's growing) --- You can work around much of this if you have your router MITM your traffic, but that's kinda a pain to set up (as it should, it'd be very bad if someone else did it and you didn't notice), and essentially only works with "common" requests (e.g. https) which aren't using certificate pinning (a small number of mobile apps do this, outside that it's more rare AFAICT). You can just block all those of course, but it'll break some things.
- fiddlerwoaroof 2y agoIs there a way to force SNI by blocking ECH requests?
- Groxx 2y agoYou'd be looking for a "TLS / ECH downgrade attack", and... while a brief googling isn't finding anything saying explicitly "yea" or "nah", it sounds like it should generally be prevented. E.g. https://wiki.mozilla.org/Security/Encrypted_Client_Hello https://wiki.mozilla.org/Security/Encrypted_Client_Hello mentions explicit bypasses are possible with enterprise proxies (which generally require client-side certificate authorities which are an explicit opt-in to allowing a third party to decrypt your traffic). And it's a TLS 1.3 extension, and TLS 1.3 -> 1.2 downgrades are intentionally prevented as part of 1.3's design... ... and even if it wasn't, ECH works by reading public keys from DNS, so the domain owner has claimed "you can send ECH" and it's pretty easy to know "therefore you shouldn't downgrade if you are capable, it's probably an attacker". Though unencrypted DNS renders this all a bit moot of course. --- tl;dr, with the caveat that IANAWebSecuritySpecialist and I haven't found anything I'd call actually conclusive yet: I believe "no". Unless you are setting up client-side CAs, at which point you can MITM everything so it hardly matters.
- axxto 2y agoFor Windows, you can use SimpleWall, which uses Windows Filtering Platform underneath. The UI is nice, it's very efficient and works systemwide, deeply integrated with Windows' network stack. You can set domain/IP rules, but it's generally more oriented towards per-application basis blocking/allowing.
- t0bia_s 2y agoIt also monitor traffic and show established/blocked/waiting connections.
- TheRizzler 2y agoIf Windows, there is ZTDNS worth checking out: https://techcommunity.microsoft.com/blog/networkingblog/announcing-zero-trust-dns-private-preview/4110366 https://techcommunity.microsoft.com/blog/networkingblog/anno... It melds Firewall and DNS to block.
- rzzzt 2y agoGlasswire does both monitoring and filtering IIRC, but I haven't used it for quite a long time now.
- cvalka 2y agohttps://safing.io/ https://safing.io/ does what you're asking. There's no need to use their SPN service.
- bornfreddy 2y agoThere is OpenSnitch [0] on Linux, but it us a bit clumsy to setup. I tried it once and didn't get far, but have it again on my todo list. Not aware of something else on Linux. On Android there is NetGuard [1] which is awesome (not affiliated, just a happy customer). [0] https://github.com/evilsocket/opensnitch https://github.com/evilsocket/opensnitch [1] https://netguard.me/ https://netguard.me/
- RMPR 2y agoMy only gripe with Netguard is that it screws up roaming. With that enabled I couldn't access apps like my bank and various others when I was out of the country. Other than that, amazing piece of software.
- g_p 2y agoThere's a couple of options in settings worth checking, as Netguard works for me when roaming just fine. Under Settings > Defaults, make sure you don't have "block roaming" turned on. Expand the rules for the apps giving you issues, and check "Block roaming" isn't ticked for them.