What's new

Skynet Is default firewall good enough?

  • SNBForums Code of Conduct

    SNBForums is a community for everyone, no matter what their level of experience.

    Please be tolerant and patient of others, especially newcomers. We are all here to share and learn!

    The rules are simple: Be patient, be nice, be helpful or be gone!

Dear all, i need your support.
Skynet is installed on my rtac86u for a while.
Now the startpage.com search page is not reachable anymore. I set via startpage.com the domain at the whitelist but no effect.
Interestingly it occurs only after reboot of my router. Direct after Installation of skynet startpage can be accessed. After reboot not. Any ideas why that could happen or what to do?
At the reboot the skynet take a while to go up and running, in skynet you set in white list the IP not the symbolic URL, you can use nslookup to see the IP.

I cannot remember, which custom filter list I put into Skynet.
Where can I see the current filter list URL in Skynet?

Edit:
And can someone please provide both, @SomeWhereOverTheRainBow and @Viktor Jaep custom filter list URL?
You could see the custom filter list from CLI in the update section

Screenshot 2023-01-05 alle 18.46.48.jpg



For the custom list of @Viktor Jaep and @SomeWhereOverTheRainBow you can find it in previous post, just read the thread.

https://www.snbforums.com/threads/is-default-firewall-good-enough.76648/post-813860

https://www.snbforums.com/threads/is-default-firewall-good-enough.76648/post-758606


Regards
Commodoro
 
Last edited:
This is probabbly off topic, and I don’t know if it has been mentioned here before but TinyWall is an excellent free firewall for Windows machines.

it is independent of Windows defender and only allows access by programs that you specify. Some time ago I found a bitcoin miner on my system but it was unable to communicate as it had no internet access.

 
This is probabbly off topic, and I don’t know if it has been mentioned here before but TinyWall is an excellent free firewall for Windows machines.

it is independent of Windows defender and only allows access by programs that you specify. Some time ago I found a bitcoin miner on my system but it was unable to communicate as it had no internet access.

Interesting. Thanks for sharing
 
Dear all, i need your support.
Skynet is installed on my rtac86u for a while.
Now the startpage.com search page is not reachable anymore. I set via startpage.com the domain at the whitelist but no effect.
Interestingly it occurs only after reboot of my router. Direct after Installation of skynet startpage can be accessed. After reboot not. Any ideas why that could happen or what to do?
Ok, it was a Problem of startpage in some regions. It was just an radom behaviour and is not related to my work on skynet .
 
Firstly, Happy New Year!
With this latest Skynet issue (stupid me upgraded), I lost all connections and did a router reset and restore (probably was due anyway).
Due to this and the fact that:
1. I have seen like 1 or 2 blocks (suspect mind you) outbound over the past 6 months
2. The firewall does a great job blocking unsolicited traffic
3. I am not sure if people have noticed or not, Firehol core lists (spamhaus, dshield, feodo) are not current any longer. e.g. spamhaus is almost 4 weeks old while source file is current. I had opened up an issue in firehol's github, but no response. L:eek:oks like Firehol probably has issues with their ingestion .sh code.

I have decided to do away with Skynet.

Perhaps I'll revisit one day. Thanks @Adamm for your code.
A follow-up:
1. I have upgraded to 7.3.5. It has been running well and I like the country names in the stats.
2. As Firehol is not always up-to-date on their lists, I am using source lists, where possible, to get the data I want. example:
includes a daily updated copy of 'et-block', including current copies of spamhaus_drop, dshield and feodo C&C blocks last 30 days. The format works well 'as is', for skynet to be able to ingest.
3. Although there are various opinions on the value of skynet, to me, it provides me with some comfort, although perhaps a 'false sense of security'. Therefore, for me, the value is the 1% when the firewall rules do not block inbound AND any OUTBOUND blocks. Regarding the outbound blocks which I have seen, although I use quad9 DNS, blocked servers were legit bad-guys that quad9 did not catch or where a gaming system like PS4 bypassed the DNS.

Thanks @Adamm for this great tool!
 
A follow-up:
1. I have upgraded to 7.3.5. It has been running well and I like the country names in the stats.
2. As Firehol is not always up-to-date on their lists, I am using source lists, where possible, to get the data I want. example:
includes a daily updated copy of 'et-block', including current copies of spamhaus_drop, dshield and feodo C&C blocks last 30 days. The format works well 'as is', for skynet to be able to ingest.
3. Although there are various opinions on the value of skynet, to me, it provides me with some comfort, although perhaps a 'false sense of security'. Therefore, for me, the value is the 1% when the firewall rules do not block inbound AND any OUTBOUND blocks. Regarding the outbound blocks which I have seen, although I use quad9 DNS, blocked servers were legit bad-guys that quad9 did not catch or where a gaming system like PS4 bypassed the DNS.

Thanks @Adamm for this great tool!
Is that list regularly updated? Thanks for sharing
 
this is my list for if you want a big one
Code:
https://strongervision.net/skynet/custom.list
 
Their website says it is updated Monday to Friday. Why not on weekends, who knows.
I added it, thanks. They must take the weekend off from internet threats lol
 
How do you create a github list that ends in .list ?
 
Create a repo and name it filter.list

View attachment 47107
I figured it out:

Github Profile > Repositories > New > Repository Name > Description > Public > Create Repository > Creating a new file > Name your file “name.list” > Add content > Commit new file > Raw
 
Its sad that we need to have skynet and the lists. I have over 30,000 inbound drops today alone. I would like to take the time and thank all the people that ruin the Internet for everyone.
 
Correct and an example of folks installing scripts they may not even need.
Definitely it would be blocked on incoming by default (if no ports have been open), but not necessarily on the outbound. But we are under the impression that if the user is filtering the outbound, then they either know what they are doing or have a particular reason to.
 
then they either know what they are doing or have a particular reason to

"We need to have Skynet" tells me this is perhaps not the case. @Blacklistedcard clearly doesn't know Skynet marks IPs as blocked when there is a match in blocklists. The larger the blocklist is - the bigger the number of "blocked" IPs. The same IPs will be blocked silently without Skynet by the built-in firewall. And here is the avalanche effect - the user sees 5k blocked IPs and starts freaking out. They add more blocklists and the number of blocked IPs jumps to 10k. Under attack panic kicks in - more blocklists added, blocked IPs jump to 30k. The setting below without Skynet installed demonstrates how the built-in firewall works (in Firewall, General). I'm sure it blocks >30k incoming usual Internet background noise connections a day:

1673934348506.png


Warning: This setting will start filling the syslog immediately with multiple blocked connections making it hard to see/find what's more important.
 

Latest threads

Sign Up For SNBForums Daily Digest

Get an update of what's new every day delivered to your mailbox. Sign up here!
Top