Pi-hole 4.0 - whitelist not working

Pi-hole version is v4.0 (Latest: v4.0)
AdminLTE version is v4.0 (Latest: v4.0)
FTL version is v4.0 (Latest: v4.0)

Hi!

My whitelist does not work. I whitelisted some domains with "pi-hole -w domain.com".
That worked but my whitelisted domains are still blocked. As soon as I remove it from the "gravity.list + preEventHorizon.list"... then it works.

After pihole -g, the domains are blocked again.

How can I fix that?

domain.com and www.domain.com are two separate domains to the Pi-hole please try whitelisting both and report back

I'll tried:

pihole -w streamcloud.com
pihole -w www.streamcloud.com

restartet pi-hole

Result:
This site can’t be reached - refused to connect.

The host seems down:

pi@noads:~ $ curl -Iv http://streamcloud.com
* Rebuilt URL to: http://streamcloud.com/
*   Trying 69.64.147.244...
* TCP_NODELAY set
* connect to 69.64.147.244 port 80 failed: Connection timed out
* Failed to connect to streamcloud.com port 80: Connection timed out
* Closing connection 0
curl: (7) Failed to connect to streamcloud.com port 80: Connection timed out

pi@noads:~ $ curl -Iv https://streamcloud.com
* Rebuilt URL to: https://streamcloud.com/
*   Trying 69.64.147.244...
* TCP_NODELAY set
* connect to 69.64.147.244 port 443 failed: Connection timed out
* Failed to connect to streamcloud.com port 443: Connection timed out
* Closing connection 0
curl: (7) Failed to connect to streamcloud.com port 443: Connection timed out

pi@noads:~ $ nmap -v -Pn streamcloud.com
Starting Nmap 7.40 ( https://nmap.org ) at 2018-11-10 18:18 CET
Initiating Parallel DNS resolution of 1 host. at 18:18
Completed Parallel DNS resolution of 1 host. at 18:18, 0.19s elapsed
Initiating Connect Scan at 18:18
Scanning streamcloud.com (69.64.147.244) [1000 ports]
Connect Scan Timing: About 15.50% done; ETC: 18:21 (0:02:49 remaining)
Connect Scan Timing: About 30.50% done; ETC: 18:21 (0:02:19 remaining)
Connect Scan Timing: About 45.50% done; ETC: 18:21 (0:01:49 remaining)
Connect Scan Timing: About 60.50% done; ETC: 18:21 (0:01:19 remaining)
Connect Scan Timing: About 75.50% done; ETC: 18:21 (0:00:49 remaining)
Completed Connect Scan at 18:21, 201.40s elapsed (1000 total ports)
Nmap scan report for streamcloud.com (69.64.147.244)
Host is up.
rDNS record for 69.64.147.244: ash.parking.local
All 1000 scanned ports on streamcloud.com (69.64.147.244) are filtered

Read data files from: /usr/bin/../share/nmap
Nmap done: 1 IP address (1 host up) scanned in 201.85 seconds

oh sorry, my mistake, I mean "streamcloud.eu"

Don't work also at my whitelist. :frowning:
This site can’t be reached - refused to connect.

This site is online, I tested it with a VPN.

What software is giving you that message "This site can’t be reached - refused to connect" ?
Am asking as the host is serving alot:

pi@noads:~ $ nmap -v streamcloud.eu
Discovered open port 443/tcp on 93.115.81.41
Discovered open port 80/tcp on 93.115.81.41
Discovered open port 111/tcp on 93.115.81.41
Discovered open port 995/tcp on 93.115.81.41
Discovered open port 199/tcp on 93.115.81.41
Discovered open port 993/tcp on 93.115.81.41
Discovered open port 3306/tcp on 93.115.81.41
Discovered open port 22/tcp on 93.115.81.41
Discovered open port 143/tcp on 93.115.81.41

And whats output for below ones ?

pi@noads:~ $ pihole -q streamcloud.eu
 Match found in list.6.hosts-file.net.domains:
   meta.streamcloud.eu

pi@noads:~ $ curl -Iv streamcloud.eu
* Rebuilt URL to: streamcloud.eu/
*   Trying 93.115.81.41...
* TCP_NODELAY set
* Connected to streamcloud.eu (93.115.81.41) port 80 (#0)
> HEAD / HTTP/1.1
> Host: streamcloud.eu
> User-Agent: curl/7.52.1
> Accept: */*
>
< HTTP/1.1 200 OK
HTTP/1.1 200 OK
< Server: nginx
Server: nginx
< Content-Type: text/html; charset=UTF-8
Content-Type: text/html; charset=UTF-8
< Connection: keep-alive
Connection: keep-alive
< Expires: Fri, 09 Nov 2018 17:46:48 GMT
Expires: Fri, 09 Nov 2018 17:46:48 GMT
< Date: Sat, 10 Nov 2018 17:46:48 GMT
Date: Sat, 10 Nov 2018 17:46:48 GMT
< X-Frame-Options: SAMEORIGIN
X-Frame-Options: SAMEORIGIN
< X-XSS-Protection: 1
X-XSS-Protection: 1
< Content-Security-Policy: frame-ancestors 'self'
Content-Security-Policy: frame-ancestors 'self'

<
* Curl_http_done: called premature == 0
* Connection #0 to host streamcloud.eu left intact

list.preEventHorizon:

.com^$image,third-party,domain=streamcloud.eu
streamcloud.eu
streamcloud.eu^$generichide
streamcloud.eu^*

gravity.list

.com^$image,third-party,domain=streamcloud.eu
streamcloud.eu
streamcloud.eu^$generichide
streamcloud.eu^*

How to add these special character in whitelist?

nmap -v streamcloud.eu

Starting Nmap 7.60 ( https://nmap.org ) at 2018-11-10 19:15 CET
Initiating Ping Scan at 19:15
Scanning streamcloud.eu (0.0.0.0) [2 ports]
Completed Ping Scan at 19:15, 0.00s elapsed (1 total hosts)
Initiating Parallel DNS resolution of 1 host. at 19:15
Completed Parallel DNS resolution of 1 host. at 19:15, 0.02s elapsed
Initiating Connect Scan at 19:15
Scanning streamcloud.eu (0.0.0.0) [1000 ports]
Discovered open port 53/tcp on 0.0.0.0
Discovered open port 9666/tcp on 0.0.0.0
Discovered open port 9050/tcp on 0.0.0.0
Completed Connect Scan at 19:15, 0.03s elapsed (1000 total ports)
Nmap scan report for streamcloud.eu (0.0.0.0)
Host is up (0.00016s latency).
Other addresses for streamcloud.eu (not scanned): ::
rDNS record for 0.0.0.0: ads.vidz4fun.com
Not shown: 997 closed ports
PORT STATE SERVICE
53/tcp open domain
9050/tcp open tor-socks

sudo pihole -q streamcloud.eu
Match found in Whitelist
streamcloud.eu
www.streamcloud.eu
Match found in list.0.adblock.mahakala.is.domains:
meta.streamcloud.eu
Match found in list.16.smokingwheels.github.io.domains:
meta.streamcloud.eu
Match found in list.17.ncloud.zaclys.com.domains:
.streamcloud.eu
ta.streamcloud.eu
meta.streamcloud.eu
Match found in list.18.smokingwheels.github.io.domains:
helotero.com^$third-party,domain=~streamcloud.eu
streamcloud.eu/deliver.php
streamcloud.eu/deliver.php$popup
Match found in list.19.smokingwheels.github.io.domains:
streamcloud.eu^/jwpsrv.js$domain=streamcloud.eu
ajax.googleapis.com^$script,third-party,domain=streamcloud.eu
streamcloud.eu#@#.adWidget
.info^$script,third-party,xmlhttprequest,domain=streamcloud.eu
|http:$subdocument,third-party,ad2links.com|adfoc.us|adv.li|adyou.me|allmyvideos.net|amvtv.net|ay.gy|fuestfka.com|imgmega.com|j.gs|linkbucksmedia.com|mortastica.com|prodsetter-in.com|q.gs|sh.st|shr77.com|sonomerit.com|ssovgoxbvppy.net|streamcloud.eu|thevideo.me|twer.info|u.bb|uploaded.net|vidspot.net
hoortols.org^$image,domain=streamcloud.eu
/asynch/null/
$script,third-party,domain=streamcloud.eu
streamcloud.eu###javawarning
crickwrite.com^$image,domain=streamcloud.eu
streamcloud.eu##a[href*="engine.4dsply.com"]
fansshare.com,hdfree.se,iconarchive.com,mcndirect.com,opensourcecms.com,primewire.ag,primewire.is,slickdeals.net,streamcloud.eu,theawesomer.com,thephoenix.com,unexplained-mysteries.com,x64bitdownload.com,yuku.com##div[style*="width:300px"]
ads.exoclick.com/close.png$image,domain=streamcloud.eu
$image,script,third-party,domain=streamcloud.eu
.com^$image,third-party,domain=streamcloud.eu
.com/?$script,third-party,domain=streamcloud.eu
streamcloud.eu###divExoLayerWrapper
static.exoclick.com^$image,domain=streamcloud.eu
streamcloud.eu##img[src*="base64"]
.net^$image,third-party,domain=streamcloud.eu
streamcloud.eu##a[href*="/clicktag."]
belwrite.com^$image,domain=streamcloud.eu
streamcloud.eu^$generichide
syndication.exoclick.com/splash.php?$script,domain=streamcloud.eu
engine.spotscenered.info^$script,domain=streamcloud.eu
|http:$popup,third-party,domain=24avarii.ru|adf.ly|allmyvideos.net|daclips.in|dropapk.com|embed.nowvideo.sx|embed.videoweed.es|engtorrent.com|extreme-board.com|eztv.ag|fastspics.net|filepost.com|flash-x.tv|flashx.tv|go4up.com|gorillavid.in|imagebam.com|imagefruit.com|imageporter.com|img24.org|imgbox.com|imgmade.com|imgshots.com|imgsin.com|imgspice.com|latestmoviesdl.com|load.to|mofunzone.com|mp3-torrents.net|mywebtv.info|nosteam.ro|nowvideo.li|openload.co|pic2pic.site|pixsense.net|pornparadise.org|projectfreetv.at|promptfile.com|sendvid.com|streamcloud.eu|streamin.to|thevideo.me|twer.info|uptobox.com|uptostream.com|vid.ag|vidabc.com|vidspot.net|vidzi.tv|vshare.eu|watchcartoononline.com|xtshare.com|youwatch.org|yts.ag
.info^$image,third-party,domain=streamcloud.eu
streamcloud.eu##a[href*=".engine"]
d2nlytvx51ywh9.cloudfront.net^$image,domain=streamcloud.eu
meta.streamcloud.eu/serve.php?adzone=ipc$script,domain=streamcloud.eu

What are the contents of your whitelist?

cat /etc/pihole/whitelist.txt

Please upload a debug log as well and post the token here.

soundcloud.com
streamcloud.eu
uptobox.com
www.soundcloud.com
www.streamcloud.eu
www.uptobox.com

debug token is: hm9pgjgk9o

Am not sure but I think your added lists are messing things up.
Try remove the lists that you've added, clear client DNS cache and try reload the page.
You can always add one list at a time untill you find the cuplrit.

Ps. these are the default ones:

pi@noads:~ $ cat /etc/pihole/adlists.list
https://raw.githubusercontent.com/StevenBlack/hosts/master/hosts
https://mirror1.malwaredomains.com/files/justdomains
http://sysctl.org/cameleon/hosts
https://zeustracker.abuse.ch/blocklist.php?download=domainblocklist
https://s3.amazonaws.com/lists.disconnect.me/simple_tracking.txt
https://s3.amazonaws.com/lists.disconnect.me/simple_ad.txt
https://hosts-file.net/ad_servers.txt

Your problem may have to do with some of the malformed domains in your gravity list (being pulled in from one or more of your subscribed blocklists). To troubleshoot, save the contents of your adlists.list file and replace the contents with the seven standard blocklists

https://discourse.pi-hole.net/t/how-can-i-restore-pi-holes-default-blocklists/8252

Then rebuild gravity and see if there is a change.

1 Like

ok, thanks!

In my log I have: IPv4 telnet error: Interrupted system call (4) :frowning: what does it mean and how to fix it?

Dont know but telnet is hardly used anymore:

SSH took over for most of it.

Ok, i fixed some trouble with lighttpd etc. Now all green in pi-hole.log

Now I'm fixing my blocklists. :wink:

all is working, thanks for help! (SOLVED)

1 Like

This topic was automatically closed 21 days after the last reply. New replies are no longer allowed.