~4m27:23Block Malicious Domains with Pi-Hole - DNS Sinkhole
Apr 27, 2021
Read: ~4m · You save: 23 min
Block Malicious Domains with Pi-Hole - DNS Sinkhole
Learn to block malicious domains and ads with Pi-hole! This tutorial covers DNS basics, installation, and configuration for enhanced network security.
This article explores the functionality and implementation of Pi-hole, an open-source DNS server designed to enhance network security by blocking malicious domain resolutions.
Understanding DNS Resolution
Domain Name System (DNS) is a hierarchical and decentralized naming system for computers, services, or any resource connected to the Internet or a private network. It translates human-readable domain names, such as opensecure.com, into machine-readable IP addresses, like 185.230.63.186.
When a device on a network, such as an internal server, needs to connect to a domain, it queries a DNS server. This query is typically handled by a configuration file, such as /etc/resolv.conf on CentOS systems, which lists the designated DNS servers. If this configuration is absent or incorrect, the device cannot resolve domain names, preventing internet access.
The process involves:
- An internal server requests the IP address for a domain (e.g.,
opensecure.com). - The server consults its DNS configuration to identify a DNS server (e.g., Google's
8.8.8.8). - The server sends a query to the DNS server.
- The DNS server resolves the domain name to its corresponding IP address and returns it to the internal server.
- The internal server uses the IP address to establish a connection to the target domain.
Pi-hole: A Security Enhancement Through DNS Control
Pi-hole functions as a custom DNS server that intercepts and processes all DNS queries originating from internal network devices. By controlling this resolution process, Pi-hole can implement security measures to prevent access to malicious domains.
The core security benefit of Pi-hole lies in its ability to blacklist specific domains. If a device attempts to resolve a domain known to host malware or engage in phishing activities (e.g., hacker.com), Pi-hole can intercept this request. Instead of providing a valid IP address, Pi-hole can either:
- Block the request entirely: The DNS server refuses to respond, resulting in a "name or service not known" error on the internal server, preventing any connection to the malicious domain.
- Implement a DNS Blackhole: The DNS server resolves the malicious domain to a private, internal IP address (e.g.,
192.0.0.69). This redirects the internal server's connection attempt to a non-existent or controlled internal resource, effectively neutralizing the threat without allowing external access.
This capability is crucial for preventing malware downloads from command-and-control servers or blocking access to phishing sites, thereby interrupting potential attack chains.
Installation and Configuration of Pi-hole
Pi-hole is an open-source tool available at pihole.net. The installation process is straightforward, often involving a bash script.
Prerequisites:
- A server (e.g., a CentOS box) to host Pi-hole.
- Sufficient hardware resources to handle the expected volume of DNS queries, especially in production environments.
- A static IP address for the Pi-hole server. This may require configuring the router to disallow DHCP and assign a static IP to the Pi-hole server.
Installation Steps:
- Download and execute the Pi-hole installation script.
- The script will prompt for configuration choices:
- Upstream DNS Provider: Select a trusted DNS provider (e.g., Google DNS
8.8.8.8) that Pi-hole will use to resolve domains it does not block. - Third-Party Lists: Opt to download pre-compiled lists of domains associated with advertisements and potentially malicious content.
- Protocol Support: Enable IPv4 and IPv6.
- Static IP Address: Confirm the static IP address assigned to the Pi-hole server.
- Web Admin Interface: Enable the web interface for managing Pi-hole.
- Web Server: Install a web server to host the admin interface.
- Query Logging: Enable logging of DNS queries for monitoring and analysis.
- Upstream DNS Provider: Select a trusted DNS provider (e.g., Google DNS
Upon completion, the installation provides the IP address for accessing the web UI and the IP address to be configured as the DNS server for internal devices. A local firewall on the server might need to be disabled (e.g., firewall-cmd --stop) to allow access to the web interface.
Managing Blocklists and Whitelists
The Pi-hole web interface provides a dashboard for managing DNS settings.
- Ad Lists (Blocklists): Pi-hole can utilize external lists of malicious domains. These lists, often hosted on platforms like GitHub, are regularly updated and can contain thousands of domains associated with malware, phishing, and advertisements. By pointing Pi-hole to these URLs, administrators can automatically populate their blocklists. For example, a "Fishing Army Blocklist" can be added by pasting its URL into the Pi-hole interface. The
Update Gravityfunction then processes these lists, adding the domains to Pi-hole's blocking database. - Whitelisting: For domains that should always be accessible, even if they appear on a blocklist, Pi-hole allows for whitelisting. This ensures that company-owned domains or trusted external services are never blocked. Conversely, administrators can implement a strict policy by blacklisting all domains and only allowing explicitly whitelisted ones.
Configuring Internal Devices to Use Pi-hole
To leverage Pi-hole's security features, internal network devices must be configured to use the Pi-hole server as their DNS server. This is achieved by editing the resolv.conf file on each device (or configuring DHCP settings to distribute the Pi-hole's IP address).
Once configured, DNS queries from internal servers will be directed to the Pi-hole server, which listens on port 53 (the standard DNS port). The Pi-hole server then forwards queries to the chosen upstream DNS provider (e.g., Cloudflare 1.1.1.1) if the domain is not blocked.
Monitoring and Analysis
Pi-hole's query log provides valuable insights into network activity. It records all DNS requests, including:
- The domain requested.
- The upstream DNS server used.
- Whether the query was blocked or allowed.
- The internal IP address of the device making the request.
This log allows administrators to identify devices attempting to access malicious domains and investigate the source of such requests, which often indicates the presence of malware or malicious user activity. The dashboard also displays statistics on blocked queries and top blocked domains.
Advanced Configurations
- Blackholing: Pi-hole can be configured to resolve blocked domains to
127.0.0.1(localhost), effectively creating a blackhole that prevents any external connection. - Strict Network Lockdown: By combining extensive blocklists with a minimal whitelist, administrators can significantly restrict network access to only approved domains, enhancing overall security.
By implementing Pi-hole, organizations can gain granular control over DNS resolutions, proactively block threats, and enhance their network security posture.
Introduction to Pi-hole
Introduction to Pi-hole as an open-source DNS server for network security, explaining its function in handling DNS queries and allowing configuration for whitelisting and blacklisting domains to prevent malicious resolutions.
- Pi-hole is an open-source DNS server.
- It can be used to secure networks by handling DNS queries.
- Pi-hole allows whitelisting and blacklisting of domains.
- The primary goal is to stop malicious domains from being resolved by internal servers.
Basics of DNS Resolution
Explains the fundamental concepts of DNS resolution, detailing how internal servers query DNS servers (like Google's 8.8.8.8) to translate domain names into IP addresses. It demonstrates this process using `resolve.conf` on CentOS and shows how removing DNS server configuration prevents resolution.
- DNS (Domain Name System) translates domain names to IP addresses.
- Internal servers use a
resolve.conffile (on Linux) to find DNS servers. - Google's DNS servers (e.g., 8.8.8.8) are common upstream providers.
- Without a configured DNS server, domain name resolution fails.
DNS Security: Blacklisting and Blackholing
Illustrates how a DNS server can provide security by blocking malicious domains. It explains two methods: blacklisting, where the DNS server refuses to resolve a domain, and DNS blackholing, where the domain is resolved to a private IP address (e.g., 192.0.0.69) to redirect traffic internally, preventing connection to the actual malicious site.
- Controlling your own DNS server allows for domain blocking.
- Blacklisting prevents a domain from being resolved.
- DNS blackholing resolves a malicious domain to an internal IP address.
- This prevents internal servers from connecting to command and control servers or malware hosts.
Installing Pi-hole on CentOS
Details the installation process of Pi-hole on a CentOS server using a bash script. It covers prerequisites like static IP addresses, selecting an upstream DNS provider (e.g., Google), choosing to download third-party ad lists, enabling the web admin interface, and logging queries.
- Pi-hole requires minimal hardware but should be beefy enough for production environments.
- Installation is done via a bash script.
- A static IP address is required for the Pi-hole server.
- Users can choose their upstream DNS provider (e.g., Google, Cloudflare).
- Third-party ad lists can be downloaded during installation.
Configuring Pi-hole: Ad Lists and Web UI
Guides through accessing the Pi-hole web UI, logging in, and exploring its features. It highlights the 'Ad list' section, where external lists of malicious domains can be added and updated. The tutorial demonstrates adding a phishing block list from GitHub, updating the gravity database, and observing the significant number of blocked domains.
- The Pi-hole web UI provides a dashboard for management.
- Ad lists can be populated from external URLs, often hosted on GitHub.
- These lists contain domains associated with ads, malware, and phishing.
- Updating the 'gravity' database incorporates new domains from added lists.
- Thousands of malicious domains can be blocked by adding a single URL.
Directing Internal Servers to Pi-hole
Explains how to configure an internal server to use Pi-hole as its DNS server by editing the `resolve.conf` file. It verifies the setup by pinging a domain and checking the Pi-hole query log, which shows the requests being processed. It also discusses changing upstream DNS providers (e.g., to Cloudflare) and the benefits of logging all DNS queries.
- Internal servers must be configured to point to the Pi-hole server's IP address for DNS.
- Editing
resolve.confon the internal server directs queries to Pi-hole. - The Pi-hole query log shows all DNS requests and their status.
- Upstream DNS providers can be changed (e.g., from Google to Cloudflare).
- Logging DNS queries provides visibility into network activity.
Testing and Advanced Configuration: Blocking, Whitelisting, and Policies
Demonstrates blocking a malicious domain using Pi-hole's blackholing feature, showing the query log indicating the block and the 'Queries Blocked' count increasing. It explains that the blocked domain resolves to `127.0.0.1` (localhost). The chapter also covers whitelisting domains, allowing specific trusted domains even if they appear on block lists, and the flexibility to create strict or lenient network policies.
- Pi-hole successfully blocks malicious domains via blackholing.
- Blocked domains resolve to
127.0.0.1(localhost). - The 'Queries Blocked' count in the dashboard reflects successful blocks.
- Whitelisting allows specific trusted domains to bypass block lists.
- Users can configure strict policies by blacklisting all and whitelisting only approved domains.