diff --git a/Alternate versions Anti-Malware List/AntiMalwareABP.txt b/Alternate versions Anti-Malware List/AntiMalwareABP.txt index 2da5eb1da..943264fc4 100644 --- a/Alternate versions Anti-Malware List/AntiMalwareABP.txt +++ b/Alternate versions Anti-Malware List/AntiMalwareABP.txt @@ -1,6 +1,6 @@ [Adblock Plus 3.2] ! Title: 💊 Dandelion Sprout's Anti-Malware List (for AdBlock and Adblock Plus) -! Version: 20May2019v4-Beta +! Version: 20May2019v5-Beta ! Expires: 5 days ! Description: Most anti-malware lists are pretty big and can cover a 5- or 6-digit amount of specific domains. But my list hereby claims to remove more than 25% of all known malware sites with just a 2-digit amount of entries. This is mostly done by blocking top-level domains that have become devastatingly abused by spammers, usually because they allowed for free and uncontrolled domain registrations. There's also additional categories that cover unusual malware and phishing domains that very few other lists seem to cover. ! For more information, details, helpful tools, and other lists that I've made, visit https://github.com/DandelionSprout/adfilt/blob/master/Wiki/General-info.md#english @@ -8,15 +8,15 @@ ! 🔶 Country domains ! You can expect these domains to have an overwhelming majority of malware domains that have nothing to do with the countries in question. Nevertheless, if you are in a situation where you have to do active business in any of the countries in question, then this list may not be ideal for you. ! Tokelau -||.tk^ +||.tk^$domain=~coolcmd.tk|~budterence.tk|~intr0.tk|~google.tk|~transportnews.tk|~unicorncardlist.tk|~c0d3c.tk ! Gabon -||.ga^ +||.ga^$domain=~google.ga|~filtri-dns.ga ! Mali -||.ml^ +||.ml^$domain=~google.ml ! Equatorial Guinea -||.gq^ +||.gq^$domain=~deimos.gq ! Central African Republic -||.cf^ +||.cf^$domain=~1hos.cf|~intr0.cf|~ivoid.cf|~domainvoider.cf|~google.cf|~rths.cf ! 🔶 Topical domains ! These are topical domains that have consistently horrendous scores on watchlists of bad TLDs, and whose use for legit purposes is practically non-existent. @@ -105,4 +105,4 @@ drivereasy.com#?#.pakb-content li:-abp-has(a:-abp-contains(Update drivers with D ! https://www.drivereasy.com/knowledge/solved-this-display-does-not-support-hdcp/ drivereasy.com#?#.pakb-content p:-abp-contains(click Update All) -! Placeholder line for domain whitelisting in the Privoxy list version. +! Placeholder line for alternate list versions diff --git a/Alternate versions Anti-Malware List/AntiMalwareAdGuard.txt b/Alternate versions Anti-Malware List/AntiMalwareAdGuard.txt index a1c1d2710..c6ba07d83 100644 --- a/Alternate versions Anti-Malware List/AntiMalwareAdGuard.txt +++ b/Alternate versions Anti-Malware List/AntiMalwareAdGuard.txt @@ -1,6 +1,6 @@ [AdGuard ≥6] ! Title: 💊 Dandelion Sprout's Anti-Malware List (for AdGuard) -! Version: 20May2019v4-Beta +! Version: 20May2019v5-Beta ! Expires: 5 days ! Description: Most anti-malware lists are pretty big and can cover a 5- or 6-digit amount of specific domains. But my list hereby claims to remove more than 25% of all known malware sites with just a 2-digit amount of entries. This is mostly done by blocking top-level domains that have become devastatingly abused by spammers, usually because they allowed for free and uncontrolled domain registrations. There's also additional categories that cover unusual malware and phishing domains that very few other lists seem to cover. ! For more information, details, helpful tools, and other lists that I've made, visit https://github.com/DandelionSprout/adfilt/blob/master/Wiki/General-info.md#english @@ -8,15 +8,15 @@ ! 🔶 Country domains ! You can expect these domains to have an overwhelming majority of malware domains that have nothing to do with the countries in question. Nevertheless, if you are in a situation where you have to do active business in any of the countries in question, then this list may not be ideal for you. ! Tokelau -||.tk^$empty,important +||.tk^$empty,important,domain=~coolcmd.tk|~budterence.tk|~intr0.tk|~google.tk|~transportnews.tk|~unicorncardlist.tk|~c0d3c.tk ! Gabon -||.ga^$empty,important +||.ga^$empty,important,domain=~google.ga|~filtri-dns.ga ! Mali -||.ml^$empty,important +||.ml^$empty,important,domain=~google.ml ! Equatorial Guinea -||.gq^$empty,important +||.gq^$empty,important,domain=~deimos.gq ! Central African Republic -||.cf^$empty,important +||.cf^$empty,important,domain=~1hos.cf|~intr0.cf|~ivoid.cf|~domainvoider.cf|~google.cf|~rths.cf ! 🔶 Topical domains ! These are topical domains that have consistently horrendous scores on watchlists of bad TLDs, and whose use for legit purposes is practically non-existent. @@ -117,4 +117,4 @@ drivereasy.com#?#.pakb-content li:-abp-has(a:-abp-contains(Update drivers with D ! https://www.drivereasy.com/knowledge/solved-this-display-does-not-support-hdcp/ drivereasy.com#?#.pakb-content p:-abp-contains(click Update All) -! Placeholder line for domain whitelisting in the Privoxy list version. +! Placeholder line for alternate list versions diff --git a/Alternate versions Anti-Malware List/AntiMalwarePrivoxy.action b/Alternate versions Anti-Malware List/AntiMalwarePrivoxy.action index e79492dac..0de03acf8 100644 --- a/Alternate versions Anti-Malware List/AntiMalwarePrivoxy.action +++ b/Alternate versions Anti-Malware List/AntiMalwarePrivoxy.action @@ -1,6 +1,6 @@ {+block} # Title: 💊 Dandelion Sprout's Anti-Malware List (for Privoxy) -# Version: 20May2019v4-Alpha +# Version: 20May2019v5-Alpha # Expires: 5 days # Description: Most anti-malware lists are pretty big and can cover a 5- or 6-digit amount of specific domains. But my list hereby claims to remove more than 25% of all known malware sites with just a 2-digit amount of entries. This is mostly done by blocking top-level domains that have become devastatingly abused by spammers, usually because they allowed for free and uncontrolled domain registrations. There's also additional categories that cover unusual malware and phishing domains that very few other lists seem to cover. # For more information, details, helpful tools, and other lists that I've made, visit https://github.com/DandelionSprout/adfilt/blob/master/Wiki/General-info.md#english diff --git a/Alternate versions Anti-Malware List/AntiMalwareTPL.tpl b/Alternate versions Anti-Malware List/AntiMalwareTPL.tpl index 0a9bbc3bc..af1c01646 100644 --- a/Alternate versions Anti-Malware List/AntiMalwareTPL.tpl +++ b/Alternate versions Anti-Malware List/AntiMalwareTPL.tpl @@ -1,6 +1,6 @@ msFilterList # Title: 💊 Dandelion Sprout's Anti-Malware List (Internet Explorer TPL) -# Version: 20May2019v4-Beta +# Version: 20May2019v5-Beta # expires = 5 # Description: Most anti-malware lists are pretty big and can cover a 5- or 6-digit amount of specific domains. But my list hereby claims to remove more than 25% of all known malware sites with just a 2-digit amount of entries. This is mostly done by blocking top-level domains that have become devastatingly abused by spammers, usually because they allowed for free and uncontrolled domain registrations. There's also additional categories that cover unusual malware and phishing domains that very few other lists seem to cover. # For more information, details, helpful tools, and other lists that I've made, visit https: github.com DandelionSprout adfilt blob master Wiki General-info.md#english @@ -80,4 +80,4 @@ msFilterList # https: www.drivereasy.com knowledge epson-xp-420-driver-update-for-windows-7-8-and-10 # https: www.drivereasy.com knowledge solved-this-display-does-not-support-hdcp -# Placeholder line for domain whitelisting in the Privoxy list version. +# Placeholder line for alternate list versions diff --git a/Alternate versions Anti-Malware List/xyzAM_prepare_filters.py b/Alternate versions Anti-Malware List/xyzAM_prepare_filters.py index ff04cb5d4..ac4850279 100644 --- a/Alternate versions Anti-Malware List/xyzAM_prepare_filters.py +++ b/Alternate versions Anti-Malware List/xyzAM_prepare_filters.py @@ -31,7 +31,7 @@ def prepare_ag(lines) -> str: # until this is done: https://github.com/AdguardTeam/CoreLibs/issues/152 line = re.sub( - r"\$document.*", + "\$document", "$empty,important", line ) @@ -60,6 +60,24 @@ def prepare_ag(lines) -> str: line ) + line = re.sub( + r"=~ Warning.*", + "", + line + ) + + line = re.sub( + r",domain$", + "", + line + ) + + line = re.sub( + r"\|~ Warning.*", + "", + line + ) + text += line + '\r\n' return text @@ -80,8 +98,8 @@ def prepare_abp(lines) -> str: # remove $document modifier from the rule line = re.sub( - "\$document.*", - "", + "\$document,", + "$", line ) @@ -128,6 +146,24 @@ def prepare_abp(lines) -> str: line ) + line = re.sub( + r"=~ Warning.*", + "", + line + ) + + line = re.sub( + r"\$domain$", + "", + line + ) + + line = re.sub( + r"\|~ Warning.*", + "", + line + ) + if is_supported_abp(line): text += line + '\r\n'