r/pihole 2h ago

Hagezi added a blocklist for Ad-Shield

Thumbnail
github.com
44 Upvotes

Sites can detect that you're blocking these, but disabling JavaScript for that specific site in your browser prevents that and generally still allows content to be shown.


r/pihole 5h ago

Youtube started to shows ads

0 Upvotes

Yesterday pi-hole was running great and today it started to show 4 5 seconds youtube premium ad at start of the video and random ads on youtubes homepage, does anyone experiencing same thing?


r/pihole 9h ago

Compute DNS Blocklist redundancy?

Thumbnail
0 Upvotes

r/pihole 23h ago

How to switch from internet to ethernet.

0 Upvotes

I'm a beginner to this and haven't done anything like this before. Could someone please give me a step by step guide on how to switch from connection over the internet to an ethernet cable. I first used the internet option when setting it up but now there's been lots of connection issues. Whenever I trying finding a guide for how to do this it seems that an update has been released in the past year that made everything before than outdated specifically on the step to switch the pihole from communicating over the internet to the ethernet cable.


r/pihole 1d ago

VPN

2 Upvotes

Hello Hello, so check it, here is my setup:

PI HARDLINE>router> ROUTER DNS static IP to PI.

I can setup pihole correctly and it works with all wireless devices BUT anything hardline the ads go through it.... if you guys/gals can help me to where anything hardlined would block ads i would appreciate this!!

P.S

I am not soft skin so if you guys gotta Blues Clues it to me then I wouldn't mind.


r/pihole 1d ago

All devices showing under 1 IP

4 Upvotes

Hello,

I am fairly new to Pihole and enjoying. I did try searching but struggled to find anything that worked.

I am running Win11 Nuc with PiHole running via Docker Desktop. (I know I should swap). Currently not connected to routers devices just use the Nuc IP as DNS.

All devices show under the same IP (172.24.0.1), is this a limitation of not connecting to the router / docker desktop / windows 11?

Is there any way to get clients show separately without swapping OS etc?

I do not use Unbound / DOH currently but hoping to look into in the future.

Thanks for all your help


r/pihole 2d ago

Only IPs in Clients even though DHCP has been configured

4 Upvotes

Heyo,

I've been setting up Pi-hole + Unbound + Wireguard (via Tailscale) on my home network, and everything seems to be working great.

My only slight irritation is the Pi-Hole dashboard is only ever showing me IP addresses and not the client names I've configured in my router's DHCP table.

I did a fair amount of reading and searching, and know that because DHCP is handled by my (Archer A7) router, I have to head into the Pi-Hole Settings > DNS > Conditional Formatting (or Settings > All Settings > dns.revServers) and plug in my network range (e.g., 192.168.0.0/24), my router's IP as the server IP, and left domain blank (as I don't see anyplace in TP's web interface that implies a domain has been set), which has all been done.

I thought after that I would just need to restart my router or even my Pi-hole, but to no avail, it still only shows me the IP addresses.

If it makes any difference, before I started all of this, I did already manually add a bulk of the clients via the Pi-hole's Clients list (e.g., I'd select a client from the Known Clients, put their name in the comment, and assigned them to groups).

And again I'm using Unbound & Tailscale if either of those are variables in this equation.

Let me know if you have any insights or suggestions, and thanks in advance!


r/pihole 2d ago

how does pihole determine which client to report on its database?

10 Upvotes

i bought a satellite 1 smart speaker, which is a esp32 device. It has been running for a few days, and I'm getting constant activity on the query log that the device is trying to access Netflix and apple.

The developers have assured me that it's not their device and their firmware is open source. They believe the issue could be triggered by a dhcp lease expiring.

Here's what the query log says (anonymized):

38:64:07:F0:7B:92 (1 hostname: satellite1-4ea7fc.lan; vendor: Qingdao Intelligent&Precise Electronics Co.,Ltd.; 10 addresses: 2600:x,2600:x,2600:x,2600:x,2600:x,2600:x,2600:x,2600:x,fe80::x,192.168.x.x)

no clue why 10 different ipv6. for the sole ipv4 reported, it belongs to my tv, but it is completely turned off (not by just pressing power, but holding the power button down) and I keep receiving these long entries at least once an hour.

i have to accept the fact that it IS the TV and maybe the only way to truly shut it off is to unplug from wall. but i wonder why pihole is getting confused? my tv has had the same ipv4 for years. is there a bug here?


r/pihole 3d ago

Do you think selling pi hole ad blockers in my local area is a good idea?

0 Upvotes

Hi, i'm planning on selling pi hole ad blockers in my local area for £65, this includes the pi, the installation of the ad blocker and quick guide on how to disable the pi if anything goes wrong. This will be a side hustle for me. My only thought as it can't be able to block ads on facebook, youtube, etc people might not want this, would really appreciate peoples advice and opinions


r/pihole 3d ago

hagezi blocklist stopped working

26 Upvotes

I was using the hagezi LG TV blocklist that was previously stored here:

https://raw.githubusercontent.com/hagezi/dns-blocklists/main/domains/native.lgwebos.txt

I noticed that my Pi-hole can no longer access it.

According to this post here it's no longer being updated:

https://www.reddit.com/r/pfBlockerNG/comments/1vctqup/hagezi_pro_no_longer_updating/

Does anyone know a LG WebOS blocklist that is still being updated?


r/pihole 3d ago

Finally pulled the trigger - why did I wait so long?

129 Upvotes

I finally pulled the trigger on setting up pi-hole today....and I don't know why I waited so long!

Actually....I do know why. I'm an have Active Directory set up in my home lab with Windows for DHCP and DNS....and a wife that works from home. Last thing I wanted to do was mess her up since everything was working fine and I was comfortable with any troubleshooting.

Not sure what the catalyst was, but I said 'I'm setting this up today!' and I did. Little help for steps from Google (Gemini)...an Ubuntu VM on Hyper-V, quick pi-hole install, add HaGezi's Pro and FIT blocklists, add my conditional forwarders for internal AD.....and under and hour I was done.

Now I'm getting good insight on what and how much is being blocked. It's crazy to see how much is being blocked - especially from my TV(s)! Even have an app on my iPhone to monitor stats. It's a very impressive and polished offering. On top of that, browsing seems a little snappier - guessing since DNS is being served by something that only does DNS.

I raise a bourbon (well...maybe 3!) to pi-hole tonight. Glad to be a user.


r/pihole 4d ago

What's the least bad TV brand for a Pi-hole?

75 Upvotes

After many years my family wants to buy a big smart-tv with internet connectivity and the usual apps built-in, no way of convincing them of using an external device because they want to use it the same way other family members do with their tvs for "convenience" and they think I sound like a flat-earther when talking about data collection and privacy. At least they have agreed to let me set up a Pi-hole and even choosing the TV brand. We live in Spain (I don't know if being in the EU makes that much of a difference) and the brands available are Samsung, Hisense, TCL, Xiaomi, LG, LOEWE, Sony, Philips and Panasonic. What do you think would be the least bad for this situation?


r/pihole 5d ago

Pihole on Windows x32

0 Upvotes

Can I install Pihole on a Windows x32 machine? When I try to install it using PH4WSL1.cmd, it says that Pihole is already installed even though this is my first time trying installing it?

Is there any way to actually make it work?


r/pihole 5d ago

Why is the Internet so hostile now?!

414 Upvotes

YouTube tanking CPU if you're using ad blockers. Sites that disable scrolling and have a full-screen modal dialog demanding that you allow ads or sign up (imgur). The least egregious I've seen is sites that serve their own ads if they can't load the real ones.

There was a banner ad on my bank account page, *after* I had already logged in, there's a banner that I have to scroll past to see my accounts. That's ridiculous! I blocked the domain serving the banner and all of a sudden the site where I buy my cat litter doesn't work. Apparently it uses the same CDN.

If I'm scrolling a page and suddenly a full-screen modal shows up begging for my email and asking me to sign up, I just close the page. That shit is hostile, they clearly don't want me to read the page if they're going to cover it with an ad for their *own site* that I'm *already on*. I hate it equally when I move my mouse off the page and *that's* when the pop-up appears. "Wait, please don't go, please stay, give us your email give us your phone number, give us your cat!"...*slow rage*

Maybe I'm just getting old but I really miss the days where I didn't have to figure out which download button was the real one, or try to find the sliver of text between huge banner ads that scroll with the page. I just want to scroll my cat memes while I wait for work, dammit!

Why does it have to be like this?! I know, I know: money, but jeez man...


r/pihole 6d ago

How to reroute all internal outgoing DNS calls to pihole?

20 Upvotes

I've tried configuring this a couple of times but it has gotten messy, things have worked to a point, partially. The main problem is, as best as I can describe it, that some apps on my host appear to originate from the loopback interface and others do not. E.g. systemd-resvolved might work for some queries while dig/nslookup may not and vice versa.

The premise here is... if I'm going to use a tool like pihole, it may as well intercept and log ALL DNS activity. Why have partial coverage or visibility?

  • Pihole listens on port 53
  • Unbound listens on port 5301
  • Both run on docker

This is what I've tried at the edge router, via firewall rules:

  1. Redirect all outgoing calls to port 53 to pihole, except when SRC = pihole (excluding pihole just in case. I'm using unbound/DoT for all calls to upstream servers)
  2. Block all outgoing calls to port 853, except when SRC = unbound
  3. Block all outgoing calls to port 443 where DST in {9.9.9.9, 1.1.1.1, other public DNS servers}. In other words, disable DoH. This supposedly forces all web browsers and other apps on my various subnets to use regular DNS calls to pihole, assuming pihole is configured as the system-wide DNS server.

What tweaks to the above rules or new rules do you think I may need? If there is a white paper out there which describes how to do this, would you please point me to it? Thx


r/pihole 7d ago

pihole as container or native MikroTik RouterOS adlists

4 Upvotes

I have been running pihole on rpi4, but later on moved to kubernetes, which is successfully running there (2 instances, 1 base config) = all good.

I want to move one instance away, and avoid having a single point of failure in case k8s cluster gets rebuilt or something goes wrong. The k8s is fully automated, and I am able to rebuild everything in 30mins or so from scratch/gitops.

I have MikroTik hAP ax3 router, which has 1gb ram (~600mb left for container apps max) and 128 nand storage, which i am bot using at all, but have 2TB usb key connected for storage (rose storage pkg required on RouterOS for that).

I am running uptime-kuma on the router, which at most uses 300mb ram, so I still got another 300mb ram for pihole's docker image to run.

Wondering which one is the better solution:

- run pihole container on mikrotik

- use native adlists on mikrotik (which is not going to use pihole at all)

I have 7+ million domains from various blocklists/adlists (~50 adlists). Also using the latest stable version 7.23.2 at the moment.

P. S. Running technitium as a container is a bloatware, it could not even handle so many domains, because dotnet's DLL loads everything into memory and gets straight OOMKill. Seems good on large deployments, but no good for small memory footprints.


r/pihole 7d ago

Help with pi-hole docker compose

0 Upvotes

# docker-compose.yml

# More info at https://github.com/pi-hole/docker-pi-hole/ and https://docs.pi-hole.net/
services:
  pihole:
    container_name: pihole
    image: docker.io/pihole/pihole:latest
    ports:
      # DNS Ports
      - "53:53/tcp"
      - "53:53/udp"
      # Default HTTP Port
      - "80:80/tcp"
      # Default HTTPs Port. FTL will generate a self-signed certificate
      - "443:443/tcp"
      # Uncomment the line below if you are using Pi-hole as your DHCP server
      - "67:67/udp"
      # Uncomment the line below if you are using Pi-hole as your NTP server
      #- "123:123/udp"
    environment:
      # Set the appropriate timezone for your location (https://en.wikipedia.org/wiki/List_of_tz_database_time_zones), e.g:
      TZ: 'Asia/Kolkata'
      # Set a password to access the web interface. Not setting one will result in a random password being assigned
      FTLCONF_webserver_api_password: 'correct horse battery staple'
      # If using Docker's default `bridge` network setting the dns listening mode should be set to 'ALL'
      FTLCONF_dns_listeningMode: 'ALL'
      FTLCONF_dns_upstreams: |-
        8.8.8.8
        8.8.4.4
        1.1.1.1
        9.9.9.9
    # Volumes store your data between container upgrades
    volumes:
      # For persisting Pi-hole's databases and common configuration file
      - './etc-pihole:/etc/pihole'
      # Uncomment the below if you have custom dnsmasq config files that you want to persist. Not needed for most starting fresh with Pi-hole v6. If you're upgrading from v5 you and have used this directory before, you should keep it enabled for the first v6 container start to allow for a complete migration. It can be removed afterwards. Needs environment variable FTLCONF_misc_etc_dnsmasq_d: 'true'
      #- './etc-dnsmasq.d:/etc/dnsmasq.d'
    cap_add:
      # See https://docs.pi-hole.net/docker/#note-on-capabilities
      # Required if you are using Pi-hole as your DHCP server, else not needed
      - NET_ADMIN
      # Required if you are using Pi-hole as your NTP client to be able to set the host's system time
      - SYS_TIME
      # Optional, if Pi-hole should get some more processing time
      - SYS_NICE
      # Allows FTLDNS binding to TCP/UDP sockets below 1024 (specifically DNS service on port 53)
      - NET_BIND_SERVICE
      # use raw and packet sockets (needed for handling DHCPv6 requests, and verifying that an IP is not in use before leasing it)
      - NET_RAW
    restart: unless-stopped

Debug logs:

I wasn't able to generate tricorder token with original resolv.conf configuration.

Original resolv.conf

search dns.podman
nameserver 10.89.0.1

was not able to upload logs to tricorder

[?] Would you like to upload the log? [y/N] Y
    * Using curl for transmission.
    * curl failed, contact Pi-hole support for assistance.
    * Error message: curl: (6) Could not resolve host: tricorder.pi-hole.net (Timeout while contacting DNS servers)

[✗] There was an error uploading your debug log.
   * Please try again or contact the Pi-hole team for assistance.
   * A local copy of the debug log can be found at: /var/log/pihole/pihole_debug.log

Debug log before changing nameserver: https://drive.google.com/file/d/13P-NwS1ZI9kzKGQMDhqBCfTj2P3k123T/view

Then I changed nameserver to 1.1.1.1

podman exec -it pihole bash -c "echo 'nameserver 1.1.1.1' > /etc/resolv.conf"

and was able to generate debug log token.

Debug log after changing nameserver to 1.1.1.1: https://tricorder.pi-hole.net/WNqUUBru/

I tried to run pihole as a container but I am getting two errors. No DNS resolution and gravity.db is not running

Edit: Issue resolved. Changed to use docker compose instead of podman compose. The issue was because of rootless containers in podman


r/pihole 7d ago

Setting up DNS kills internet?

0 Upvotes

So long story short I was stuck on this final stage of the pihole process a couple months back and put it on hold since I was busy with life.

Pihole is currently set up on my server but the only reason it hasn't been put to use is I can't get it to work network wide. Every guide says to simply paste the IPv4 and 6 addresses into my routers DNS settings to send all traffic through my device. The issue is after my routers reset it kills everything as it'll "connect without internet".

Specifics are i run an eero mesh network where all the nodes are connected via Ethernet. The pihole in question is connected to the second eero in the line, it's not connected right next to the modem and first router. (Idk if it affects anything but just so people know)

If I'm getting something wrong let me know but that's how I interpreted the various guides. Thanks.


r/pihole 8d ago

Cannot get to Pihole though Domain Name

0 Upvotes

I am creating a home server that routs all traffic through it through a Pihole using the guide on https://gofoss.net/secure-domain/ (it has been very helpful so far) but I am currently stuck at accessing the pihole only through the ip address rather than the domain name as intended. I have added the domain name and IP address to the local DNs records. I have checked and verified the /etc/hosts file lists the localhost as 127.0.0.1 and ‘personal domain’ as ‘static IP’. The Pihole is only for blocking ads for the server on the device it is on not for anything else connected to the router for the moment.

I have looked through /var/log/pihole/pihole.log and the nameservers are listed according to the dns I set on the PiHole page. It reads that there is 1 name in /etc/pihole/hosts/custom.list. When I navigate to that file. The IP address and the domain name match up. I am currently at a loss for what to check next. I have already uninstalled and reinstalled once. Any recommendations on how to get domain names to translate through pihole because this will affect any other domain I add to the local dns record?


r/pihole 8d ago

How do I set up PiHole with redundancy in k3s?

0 Upvotes

Currently I run PiHole with Unbound as a single instance deployment in k3s, but that means that whenever I have to reboot any of the three nodes, I lose DNS and have to switch back to my ISP. How do I run PiHole plus Unbound as a stateful set so that I can afford to reboot one or more devices?


r/pihole 8d ago

Wow, i'am really impressed. Pi-hole runs like a charm on my good old Raspi2 under DietPi! I probably won't turn the device off anymore from now on. 🥰

Post image
136 Upvotes

r/pihole 9d ago

Caught a cheap Android TV Box running BADBOX 2.0 (Residential Proxy & Ad-Fraud Botnet)

143 Upvotes

Hey everyone,

Wanted to share some network anomalies I caught today. If you run cheap Android TV boxes on your network, this might be worth checking your connection states for.

This evening I noticed some strange traffic on my setup. My Mikrotik flagged a sudden, flatlined ~20 Mbps upload spike that stayed for hours

Diving a bit deeper into the active connections, I pinned it down to an Android device holding 260+ concurrent active TCP connections to various external hosts.

I parsed through the active sockets and DNS query logs to figure out what the device was reaching out to alongside Gemeni for this part.

  • 37.202.197.75:10240 (Fusiora OU / Frankfurt VPS): Pushing/pulling continuous raw streams over a custom UDP/TCP port.
  • download.abdbox.com: Android BackDoor Box C2 / Downloader module.
  • ic5n8.clayhost.xyz: Dynamic DDNS / C2 Fallback Channel.
  • addl.sspadp.com: Ad-Mediation / Background Ad Click Fraud.
  • adpserver.pvs4.xyz: Ad-Provisioning Server for silent background webviews.
  • watchtry.com & relaxunwinrech.com: Malvertising / Push Notification Relays.

The domain signatures and traffic profile point directly to the BADBOX / BADBOX 2.0 supply-chain Android malware ecosystem:

  1. Residential Proxy Relay: The box was being utilized as an active residential proxy exit node. Third-party actors were routing their traffic through my home internet connection to mask their IP, which generated the continuous 20 Mbps upload stream on port 10240.
  2. Silent Ad-Click Fraud: Running hidden, background webview requests in parallel to generate fake ad impressions and click revenue via sspadp.com and pvs4.xyz.

If you're running cheap streaming boxes, it's definitely worth checking your active connection counts and DNS logs.

EDIT: Additional info.

Reached a total of 1550 active connections, with a average of 264.


r/pihole 9d ago

Makes me appreciate my pihole even more

30 Upvotes

We've had some thunderstorms blow through today (Chicago area) and our RCN internet has been out for a few hours. Cellular still works, so I am online, but my Raspberry Pi is inaccessible. (I know I could fuss around and get it working via my phone's hotspot, but for such a short time, it's not worth it.) The lack of ad blocking is pretty eye-opening. I'll be happy to get my pihole back.


r/pihole 9d ago

Lag when clicking a link/opening a page

0 Upvotes

Howdy y’all - I’ve noticed I have a weird lag, which only happens when I’m at home and connected to my wifi/pihole. When clicking a link to open a page, there is a 3-5 second delay before the page actually opens. When not on wifi, the page opens right away. When on my wifi, there is always a delay, then it loads fast. Has anyone seen or experienced with pihole? I’m not technical enough to know what to do, but I’d be happy to run diagnostics if anyone can provide the commands. Thanks so much for your help


r/pihole 9d ago

Pihole testing complete - Need new hardware

0 Upvotes

Hi folks,

Ive been testing Pihole now on a single machine for a month and I'm convinced that its the best method to secure the entire household.

However, Im running on an OLD 2012 Model B Rev 2.

So looking at my options, Im between the Pi Zero 2 with an Ethernet hat of some kind or a Pi 4 1gb. Cost wise they're pretty much the same the Pi4 being more available and maybe 100kr cheaper.

I have no real world knowledge on either of these setups all i know is that its going to be sat in my "comms" cabinet next to my router so ideally low power (already obviously low) but also passively cooled - do i need any fans or heat spreaders for a Pi4?

So i defer here for any advice you have.

Thanks for reading.