OPNsense Forum

English Forums => Intrusion Detection and Prevention => Topic started by: dcol on December 16, 2022, 06:29:18 PM

Title: social-networking block Tiktok
Post by: dcol on December 16, 2022, 06:29:18 PM
I noticed that OPNsense-App-detect/social-networking rules does not include TikTok. Where can I put in a request to add Tiktok to the rules?
Thanks
Title: Re: social-networking block Tiktok
Post by: mimugmail on December 18, 2022, 02:48:22 PM
In github, just find those Domains and add a PR
Title: Re: social-networking block Tiktok
Post by: GaryPruitt on December 21, 2022, 03:53:34 AM
Could you share a more detailed explanation, please? I'm not that young to understand everything the first time. So, I'd appreciate your help. Actually, if I didn't see this thread, I'd never notice that TikTok is not included. Actually, I've downloaded tik tok only to promote my music studio. Fanhype (https://fanhype.de/tiktok-aufrufe-kaufen/ (https://fanhype.de/tiktok-aufrufe-kaufen/)) will help me make it real. My friends advised me about that service, actually. Anyway, I'll be waiting for your replies, guys. Thanks in advance for your help!!!
Title: Re: social-networking block Tiktok
Post by: mimugmail on December 21, 2022, 06:47:40 AM
This should help :)

https://github.com/opnsense/rules
Title: Re: social-networking block Tiktok
Post by: dcol on December 24, 2022, 07:51:02 PM
Here are the instructions to add TikTok to IDS social rules

Add the following to /usr/local/etc/suricata/rules/opnsense.social_media.rules

#alert dns any any -> any 53 (msg:"OPN_Social_Media - TikTok - DNS request for tiktok.com"; dns_query; content:"tiktok.com"; nocase; classtype:social-media; sid:51000060;)
#alert http any any -> any $HTTP_PORTS (msg:"OPN_Social_Media - TikTok - Related URL (tiktok.com)"; content:"tiktok.com"; http_uri; flow:to_server,established; classtype:social-media; sid:51000061; rev:1;)
#alert tls any any -> any any (msg:"OPN_Social_Media - TikTok - Related TLS SNI (tiktok.com)"; tls_sni; content:"tiktok.com";flow:to_server,established; classtype:social-media; sid:51000062; rev:1;)

Then go into IDS>Administration>rules. Type tiktok in the search and enable these rules. Set alert/drop as per your preference.

Be advised, if the URL's for TikTok are different in your country. Edit/Add to above rules.