social-networking block Tiktok

Started by dcol, December 16, 2022, 06:29:18 PM

Previous topic - Next topic
I noticed that OPNsense-App-detect/social-networking rules does not include TikTok. Where can I put in a request to add Tiktok to the rules?
Thanks


December 21, 2022, 03:53:34 AM #2 Last Edit: December 22, 2022, 11:59:05 AM by GaryPruitt
Could you share a more detailed explanation, please? I'm not that young to understand everything the first time. So, I'd appreciate your help. Actually, if I didn't see this thread, I'd never notice that TikTok is not included. Actually, I've downloaded tik tok only to promote my music studio. Fanhype (https://fanhype.de/tiktok-aufrufe-kaufen/) will help me make it real. My friends advised me about that service, actually. Anyway, I'll be waiting for your replies, guys. Thanks in advance for your help!!!


December 24, 2022, 07:51:02 PM #4 Last Edit: December 24, 2022, 07:53:01 PM by dcol
Here are the instructions to add TikTok to IDS social rules

Add the following to /usr/local/etc/suricata/rules/opnsense.social_media.rules

#alert dns any any -> any 53 (msg:"OPN_Social_Media - TikTok - DNS request for tiktok.com"; dns_query; content:"tiktok.com"; nocase; classtype:social-media; sid:51000060;)
#alert http any any -> any $HTTP_PORTS (msg:"OPN_Social_Media - TikTok - Related URL (tiktok.com)"; content:"tiktok.com"; http_uri; flow:to_server,established; classtype:social-media; sid:51000061; rev:1;)
#alert tls any any -> any any (msg:"OPN_Social_Media - TikTok - Related TLS SNI (tiktok.com)"; tls_sni; content:"tiktok.com";flow:to_server,established; classtype:social-media; sid:51000062; rev:1;)

Then go into IDS>Administration>rules. Type tiktok in the search and enable these rules. Set alert/drop as per your preference.

Be advised, if the URL's for TikTok are different in your country. Edit/Add to above rules.