![]() |
|
1
14th May 10:29
Orquidofilo
Mombu User
Join Date: May 2008
Location: NY, U.S.A.
Posts: 26
![]() |
INTRODUCTION:
(Afterwards, the actual steps to perform beyond CIS Tool suggestions (which will need you to use tools like secpol.msc, gpedit.msc, services.msc, regedit.exe, explorer.exe + more, yet, all native tools to your OS) will be listed for your reference, each in their own post reply, to avoid "clutter"): Windows CAN be secured very well, but, you have to go thru some "GYRATIONS/EFFORT" to do it, but, it IS doable (but not to any 100% levels, because again - new holes/vulnerabilities appear in the OS & its libs + apps, but this gets you closer, if not as close as a body needs to be!). THIS IS GEARED TO "stand-alone" systems online on the internet (However - it can be adapted for LAN/WAN office or home networked environs, BUT, pay attention to step #2's 'warnings' about pulling Client For Microsoft Networks, &/or File & printer sharing - most networks require/need this) -------------------------------------------------------------------------------------------------------------- BACKGROUND & INFORMATION + TOOLS YOU CAN USE TO HELP YOU SECURE YOUR SYSTEM: -------------------------------------------------------------------------------------------------------------- Here I am running Windows Server 2003 SP #2, fully current patched by MS update pages, here (I check it every 2nd Tuesday of the month of course, on "Patch Tuesday's"): http://www.microsoft.com/downloads/B...der=descending It is a personally 'security-hardened' model I have been working on for many years, using principals I learned & used since the NT 3.5x days onward to this version of the OS: As is now? I score an 85.760 on the CIS Tool 1.x currently as of 10/10/2007! http://forums.techpowerup.com//attac...3&d=1192208359 This is up from my past score here of 76.xxx on it (default score I had prior to this security hardening via CIS TOOL & its advisements & past the 84.735 I initially hardened it up to, & later 85.185 as well), & here is how to do it! Currently, I can go NO higher than this score of 85.760 (of 100 total) on CIS Tool 1.x for Windows, pictured here (photo proof/pictures DO say, a 1,000 words (like this post, lol)) & even IF I could get past the few areas I know are wrong (the test errs, as it does on some areas in LINUX as well), I cannot get past 88% or so, period! ================================================== ========================== HERE ARE LINUX SCORES FROM CIS TOOL (SuSE Enterprise Linux under VMWare): ================================================== ========================== HARDENED LINUX: http://forums.techpowerup.com//attac...d=11928943 51 DEFAULT LINUX: http://forums.techpowerup.com//attac...d=11928940 12 (It appears that LINUX has FAR LESS TESTED, when compared to the SIZE of the Windows tets, & Linux CAN reach 90++ scores (but there is an error in CIS TOOL preventing myself from going to a higher than 85.760 score & I have submitted the data to CIS TOOL's authors on that account WITH PROOFS, and even if I could get the few areas I am scored down on still, it would not add to past 88% or so... bug, bigtime, do the math from my score & see)) ================================================== ========================== That is a DECENT ENOUGH score (especially considering the default score of VISTA even, is FAR BELOW THAT! Nice part is? The techniques noted here can LARGELY APPLY TO VISTA AS WELL, but afaik there is no CIS Tool version for VISTA (yet)! Still, read on...) (For CIS Tool - There are Linux, Solaris, BSD variants, & other OS models ports (some only in .pdf security guide form though, not programmatically automated yet, like MacOS X) of this are available too by the way - not really "ports" strictly speaking, they require JAVA to run) ------------------------------------------------------------------------------------------------------------------- DOWNLOAD URL FOR CIS TOOL (for multiple platforms), from "The Center for Internet Security" here: ------------------------------------------------------------------------------------------------------------------- http://www.cisecurity.org/bench.html IMPORTANT: This tool IS invaluable in guiding you to a more secure OS, on any OS platform really! It actually makes it "FUN", in a techie/geeky/nerdy (whatever) kind of way, in that you really find out WHAT it is you know, vs. the CIS Tool results, as far as securing a Windows NT-based system. E.G./I.E,-> I've been @ this field in a professional capacity since 1994, & it taught me a "trick-or-two", let's put it THAT way. CIS Tool = Great stuff, that makes much of this easier (what I add ontop of it is in the next steps)! APK P.S.=> Now that the "introductory material" (tools to use, how/why, results possible, etc. et al) has been put down? Now, here we go to the actual "meat" of the subject in my next post(s). Also - IF you have more to add to this, OR critique of my points? Please - have @ it & let 'em rip (as we ALL can gain by for security & peace-of-mind online hopefully) HOWEVER, please - hold off on the "English Grammar" critiques + "writing style" stuff (I did my best + refine it as I go & add more) I would try to have made it shorter too, but it's complex material @ times, & definitely a lot of it (CIS Tool helps though)! (So please, as to critiques - I only ask that you keep it computer security technically oriented, adding points I may have missed or supplementing those I suggest with alternates to things I Have). Thanks, & enjoy! apk Last edited by APK : 14th May at 10:57. |
|
|
|
|
SPONSORED LINKS BY GOOGLE |
|
3
14th May 10:39
Orquidofilo
Mombu User
Join Date: May 2008
Location: NY, U.S.A.
Posts: 26
![]() |
11.) I also use a LinkSys/CISCO BEFSX41 "NAT" true firewalling CISCO technology-based router (with cookie & scripting filtering built-in @ the hardware level), these are excellent investments for security.
BY THE WAY, IF YOU OWN A ROUTER? TURN OFF THE UPNP FEATURES IN IT! Why? Take a read: Most Home Routers Vulnerable to Flash UPnP Attack: http://it.slashdot.org/it/08/01/14/1319256.shtml * Just to be safe... ![]() APK |
|
|
|
|
5
14th May 10:41
Orquidofilo
Mombu User
Join Date: May 2008
Location: NY, U.S.A.
Posts: 26
![]() |
AN IMPORTANT POINT:
STOP JAVASCRIPT USAGE IN YOUR BROWSERS (along with ActiveX & JAVA) On the PUBLIC internet, PERIOD (well, with SOME exceptions on sites that demand you use it, OR those that cannot function properly without it, some examples below)! Why? Well, read on: Fact is, that today? Well... Javascript's dangerous & can be used AGAINST you, as well as help you... it truly is, or can be, a 'double-edged sword'... (For example - if you follow security related news, you will see that JavaScript is the key avenue being used against you in today's attacks (even thru adbanners!)). Some examples: http://www.wired.com/techbiz/media/n...11/doubleclick & http://apcmag.com/5382/microsoft_apo...to_custom ers If you MUST use Javascript (for instance, on a particular site like banking or shopping oriented ones)? Try "NoScript" (the .xpi addon for FireFox/Mozilla/NetScape 9 etc.) & let it let YOU decide sites to use it on, & then DISABLE JAVA/JAVASCRIPT globally... (& if you use IE, trying to do the same can be a nightmare (as IE will "nag you to death" if you turn off javascript on sites that use it)). Opera has similar functionality, ALBEIT, built into it by default as a NATIVE tool! I.E.-> The ability to GLOBALLY block scripting tools like Javascript, BUT... to also allow it for sites you MUST use it on as exceptions to the GLOBAL rule set in Tools, Preferences menus it has on its menubar. Opera has the NATIVE BUILT IN ABILITY to allow you to use it on sites you visit IF you must, via rightclicks on the page & "EDIT SITE PREFERENCES" popup menu submenu item that appears. Either way? It works, & I STRONGLY recommend this. I also recommend Opera for these reasons (less security holes period, & the 1 it had yesterday? Patched yesterday too... fast!) ===== SECUNIA DATA ON BROWSER SECURITY (dated 05/14/2008): ===== Opera 9.27 security advisories @ SECUNIA (0% unpatched): http://secunia.com/product/10615/?task=advisories ---- Netscape 9.0.0.6 (0% unpatched - but, now discontinued by Mozilla, so it WILL be vulnerable to things FF won't be now & in the future) http://secunia.com/product/14690/ ---- FireFox 2.0.0.14 security advisories @ SECUNIA (17% unpatched): http://secunia.com/product/12434/ ---- IE 7 (latest cumulative update from MS) security advisories @ SECUNIA (36% unpatched): http://secunia.com/product/12366/ ---- Those %'s are the latest for FireFox 2.0.0.13, Netscape 9.0.0.6, IE7 after last "patch Tuesday" from MS with the "CUMULATIVE IE UPDATES" they have (see the security downloads URL I post in the 12 steps above to secure yourself), & Opera 9.27... all latest/greatest models. So, as you can see? Well, NOT ONLY IS OPERA MORE SECURE/BEARING LESS SECURITY VULNERABILITIES? It's faster too, on just about ANYTHING a browser does, & is probably the MOST standards compliant browser under the sun (not counting HTML dev tools). This is borne out in these tests: http://www.howtocreate.co.uk/browserSpeed.html AND, yes others (most recently in Javascript parsing speeds, oddly enough, lol... given the topic of my post here that is), right here: http://nontroppo.org/timer/kestrel_tests/ Opera's just more std.'s compliant - for example, having passed all the ACID (2/3 before anyone on the latter & one of the first for the former no less), plus it's faster + MULTIPLATFORM, & more secure than the others out there - thus, it's an "all-around" overall best solution! QUESTION - So, "where do you want to go today?"... ANSWER = Opera (if you're into speed, security, & std.'s compliance + using a webbrowser that runs on most any platform out there for computing is where). ---- ALSO - HOW TO SET THE "KILL BIT" ON ACTIVEX CONTROLS: (I.E.-> This is how to stop an ActiveX control from running in Internet Explorer) http://support.microsoft.com/kb/240797 In case you have "problematic" or security vulnerable ActiveX controls, per this RealPlayer example thereof: http://service.real.com/realplayer/s...007_player/en/ APK |
|
|
|
|
6
14th May 10:44
Orquidofilo
Mombu User
Join Date: May 2008
Location: NY, U.S.A.
Posts: 26
![]() |
DO NOT USE THIS WITH A HOME or BUSINESS LAN THAT HAS ActiveDirectory going (because, for example - it will mess up things like FULL Outlook binding to EXCHANGE SERVER for instance, because of INTERNAL DNS SERVER dependencies AD has (ActiveDirectory is HEAVILY dependent on DNS resolutions is why)
That said & aside? I found something VERY cool, as regards online security, that I stumbled onto during my meanderings online today! ScrubItDNS: http://www.scrubit.com ![]() * GREAT IDEA, & it WORKS, painlessly... AND F A S T, too! APK P.S.=> Take a read of what it does, how EASY it is to implement (lol, they even give a GUI to do the job for you, because digging into your network connection MIGHT be a "bit much" for some folks, to make it easy for anyone really... 2 clicks!) & YOU DECIDE... I have tried it, & it DOES work, by filtering off sites thru it that are 'dangerous' OR 'offensive' (like ones you might find that are involved with the above exploit, or others like GOOGLE + SPYBOT Search & Destroy help you with) - PLUS, Pr0n sites (some of you, lol, may NOT like that "feature" though). Still, bottom-line - For layered security? This is a GOOD idea, this "scrubit" DNS server... imo, so far @ least... apk |
|
|
|
|
8
14th May 10:47
Orquidofilo
Mombu User
Join Date: May 2008
Location: NY, U.S.A.
Posts: 26
![]() |
As regards the "Russian Business Network" (RBN) who has been @ the heart of MANY online attacks (or, things like Zlob trojan & IDTheft related attacks, etc. et al)? Use this information to protect yourselves, from them.
(RELIABLE/REPUTABLE SOURCE USED = http://www.spamhaus.org/rokso/eviden...kso_id=ROK7465 ---- FIRST OF ALL - Note, I use "0.0.0.0" vs. "127.0.0.1" (That is simply because iirc, the zero's based one leads to a NULL port type of request, rather than your "loopback adapter" (i.e.-> YOUR OWN MACHINE fielding requests) for a couple of reasons (which it took me some time to come up w/ & testing as to which is "better" to use)). SECONDLY, 0.0.0.0 is SMALLER than 127.0.0.1, & thus, parses + loads FAR faster, & is smaller on disk is why - AND, in RAM once loaded: THUS, I am logically concluding that 0.0.0.0 is better to use period for HOSTS file blocks - same function, & @ LESSER cost, nearly all the way around (less diskspace, faster loadspeed, less memory occupancy, & etc. et al). A MORE EFFICIENT STRUCTURE! ---- USING NOTEPAD.EXE ADD THIS LIST TO YOUR CUSTOM HOSTS FILE (usually located in %windir%\system32\drivers\etc subfolder-subdirectory): # === START OF KNOWN RUSSIAN BUSINESS NETWORK/RBN MAPPINGS + AFFILIATED KNOWN SERVERS === 0.0.0.0 rxpharmacy-support.com 0.0.0.0 ns3.cnmsn.com 0.0.0.0 thecanadianmeds.com 0.0.0.0 officialmedicines.com 0.0.0.0 psxshop.com 0.0.0.0 10000xing.cn 0.0.0.0 222360.com 0.0.0.0 adslooks.info 0.0.0.0 bnably.com 0.0.0.0 eqcorn.com 0.0.0.0 familypostcards2008.com 0.0.0.0 freshcards2008.com 0.0.0.0 happy2008toyou.com 0.0.0.0 happysantacards.com 0.0.0.0 hellosanta2008.com 0.0.0.0 hohoho2008.com 0.0.0.0 kqfloat.com 0.0.0.0 ltbrew.com 0.0.0.0 mymetavids.com 0.0.0.0 obebos.cn 0.0.0.0 parentscards.com 0.0.0.0 postcards-2008.com 0.0.0.0 ptowl.com 0.0.0.0 qavoter.com 0.0.0.0 santapcards.com 0.0.0.0 santawishes2008.com 0.0.0.0 siski.cn 0.0.0.0 snbane.com 0.0.0.0 snlilac.com 0.0.0.0 tibeam.com 0.0.0.0 tushove.com 0.0.0.0 wxtaste.com 0.0.0.0 yxbegan.com 0.0.0.0 iframedollars.biz 0.0.0.0 NS1.RBNNETWORK.COM 0.0.0.0 NS1.4USER.NET 0.0.0.0 NS1.EEXHOST.COM 0.0.0.0 NS1.AKIMON.COM 0.0.0.0 NAME1.AKIMON.COM 0.0.0.0 NS2.RBNNETWORK.COM 0.0.0.0 NS2.4USER.NET 0.0.0.0 NS2.AKIMON.COM 0.0.0.0 NS2.EEXHOST.COM 0.0.0.0 NAME2.AKIMON.COM 0.0.0.0 RUSOUVENIRS.COM 0.0.0.0 RBNNETWORK.COM 0.0.0.0 NS1.INFOBOX.ORG 0.0.0.0 NS2.INFOBOX.ORG 0.0.0.0 NS1.RUSOUVENIRS.COM 0.0.0.0 NS2.RUSOUVENIRS.COM 0.0.0.0 NS1.RUSOUVENIRS.NET 0.0.0.0 NS2.RUSOUVENIRS.NET 0.0.0.0 SBTTEL.COM 0.0.0.0 AKIMON.COM 0.0.0.0 AKIMON.NET 0.0.0.0 EEXHOST.COM 0.0.0.0 NS1.EEXHOST.COM 0.0.0.0 NS2.EEXHOST.COM 0.0.0.0 NS1.4USER.NET 0.0.0.0 NS1.AKIMON.COM 0.0.0.0 NS1.EEXHOST.COM 0.0.0.0 NAME1.AKIMON.COM 0.0.0.0 NS1.RBNNETWORK.COM 0.0.0.0 NS2.4USER.NET 0.0.0.0 NS2.AKIMON.COM 0.0.0.0 NAME2.AKIMON.COM 0.0.0.0 NS2.RBNNETWORK.COM 0.0.0.0 NS2.EEXHOST.COM 0.0.0.0 VALUEDOT.NET 0.0.0.0 ns0.valuedot.net 0.0.0.0 ns1.valuedot.net 0.0.0.0 1000WATT.BIZ 0.0.0.0 2SOVKA.NET 0.0.0.0 AIDEN-GROUP.COM 0.0.0.0 AKIMON.COM 0.0.0.0 ALEKC.NET 0.0.0.0 ANDREY-STUDIO.INFO 0.0.0.0 AUTOKUBAN.INFO 0.0.0.0 AVIATRAVELAGENCY.COM 0.0.0.0 AVTOMOBILEY.NET 0.0.0.0 BAGATITSA.COM 0.0.0.0 BAIKERGROUP.COM 0.0.0.0 BALTICDOORS.COM 0.0.0.0 BALTMONOLIT.COM 0.0.0.0 BRIGADA-EL.COM 0.0.0.0 CARPRIVOZ.COM 0.0.0.0 CHILLERU.COM 0.0.0.0 CVETOVODSTVO.COM 0.0.0.0 E-GOLD-CHANGER.COM 0.0.0.0 ELECTRONOV.NET 0.0.0.0 FASHIONER.BIZ 0.0.0.0 FFFFFF.ORG 0.0.0.0 FIFACUP06.INFO 0.0.0.0 FISHTORG.COM 0.0.0.0 FKGARANT.COM 0.0.0.0 FOTORETUSH.COM 0.0.0.0 FREGATSOFT.COM 0.0.0.0 FROLROMANOFF.COM 0.0.0.0 FULLVER.INFO 0.0.0.0 GAKKEL.COM 0.0.0.0 GARANTSERVICE.ORG 0.0.0.0 GDEDENGI.INFO 0.0.0.0 GLAZKI.NET 0.0.0.0 GOLD-DRAGON.INFO 0.0.0.0 GORODM.COM 0.0.0.0 GRAYZI.NET 0.0.0.0 GRIFFINFLY.COM 0.0.0.0 HEAT-ENERGO.COM 0.0.0.0 HITEMA.NET 0.0.0.0 HYIPREVIEW.INFO 0.0.0.0 HYIPSMAP.COM 0.0.0.0 ILOXX.ORG 0.0.0.0 IMYA.INFO 0.0.0.0 INFODOSKA.COM 0.0.0.0 INTERNETWORLDBOOK.COM 0.0.0.0 KLIMATA.NET 0.0.0.0 KOMOV.NET 0.0.0.0 KOSMETICHKA.NET 0.0.0.0 LIDTRADE.COM 0.0.0.0 LIFE-RU.ORG 0.0.0.0 LPSPB.COM 0.0.0.0 M-OST.NET 0.0.0.0 M-UNLOCK.COM 0.0.0.0 MAMRU.COM 0.0.0.0 MAPSERV.COM 0.0.0.0 MASTERDOKS.COM 0.0.0.0 MIRMED.COM 0.0.0.0 MOOSEMUSE.COM 0.0.0.0 MOREPRODUCT.NET 0.0.0.0 MUSEMOOSE.COM 0.0.0.0 NESTRONICS.COM 0.0.0.0 NESTRONICS.NET 0.0.0.0 NOFUN.INFO 0.0.0.0 OIL-GAS-MINERALS.COM 0.0.0.0 OKOSHKA.NET 0.0.0.0 OPTIMUS.BIZ 0.0.0.0 OTKRITKI.NET 0.0.0.0 OTKRITOK.NET 0.0.0.0 PARALLELSIXTY.COM 0.0.0.0 PASSOMONTANO.COM 0.0.0.0 PETROBALT.NET 0.0.0.0 PHARMACY-MD.COM 0.0.0.0 PISKUNOV.NET 0.0.0.0 POIGRAI.INFO 0.0.0.0 PROETCONTRA.ORG 0.0.0.0 PSOLAO.ORG 0.0.0.0 ROSEL.INFO 0.0.0.0 SBTTEL.COM 0.0.0.0 SECONDAPPROACH.COM 0.0.0.0 SMARTSOFTLINE.COM 0.0.0.0 SMESHNOY.COM 0.0.0.0 SQUAREDREAM.COM 0.0.0.0 STROIINFORM.COM 0.0.0.0 STROYBRIGADA.COM 0.0.0.0 TANK-HOBBY.COM 0.0.0.0 TECHNONORDIC.COM 0.0.0.0 TELEUNITED.NET 0.0.0.0 TEPLOCOM.COM 0.0.0.0 THERMOCAUTERY.COM 0.0.0.0 TIARU.COM 0.0.0.0 TRADEFINANS.COM 0.0.0.0 TRADEFINANS.NET 0.0.0.0 TRAININGS-TRIUMPH.ORG 0.0.0.0 TSAR-SUVENIR.COM 0.0.0.0 UEFACUP08.INFO 0.0.0.0 UMNIKSOFT.COM 0.0.0.0 UNDERCOOLED.NET 0.0.0.0 VALIDBIT.COM 0.0.0.0 VERESC.ORG 0.0.0.0 VOROLAIN.COM 0.0.0.0 WHITENIGHTSHOSTELS.COM 0.0.0.0 WORLDFONDS.NET 0.0.0.0 XRUST.NET 0.0.0.0 YAHOCHU.COM 0.0.0.0 Z-GROUP.INFO 0.0.0.0 ZDRAV.INFO 0.0.0.0 ZHESTOV.NET 0.0.0.0 ZOOSPB.COM 0.0.0.0 goldenpiginvest.com 0.0.0.0 goldenpiginvest.net 0.0.0.0 pharmacy-viagra.net # === END OF KNOWN RUSSIAN BUSINESS NETWORK/RBN MAPPINGS + AFFILIATED KNOWN SERVERS === Also - You can (AND SHOULD) verify your HOSTS file location, because it CAN be moved (& some virus/spywares do so, like QHosts) by using regedit.exe & going here: HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Servic es\Tcpip\Parameters & checking to see it has NOT been misdirected from C:\WINDOWS\SYSTEM32\DRIVERS\etc (Unless you KNOW that YOU move it, as I do!) I move mine INTENTIONALLY to another disk here that is less used & faster on seeks! That is just so it init.'s faster since the HDD is not contending with other programs loading etc. or data loading etc. - mine's on an SSD (solid-state ramdisk, for access-seek gains for example). ---- FOR FIREWALL BLOCKING RULES (or IE "restricted zones" lists (in IE options), OR possibly IP Security Policies usage): I.P. address block for Russian Business Network: 81.95.144.0/20 #SBL43489 (81.95.144.0 - 81.95.159.255) And the address blocks for its equally corrupt cousins at Intercage, Inhoster, and Nevacon: 85.255.112.0/20 #SBL36702 (85.255.112.0 - 85.255.127.255) 69.50.160.0/19 (69.50.160.0 - 69.50.191.255) 194.146.204.0/22 #SBL51152 (194.146.204.0 - 194.146.207.255) Lastly/Optionally - You should block all IPs starting with these if you do not care about Russia and China: 193. 194. 195. 213. 217. 62.64. 62.76. (AND, A few major Internet providers that provide services to RBN including) Tiscali.uk SBT Telecom Aki Mon Telecom Nevacon LTD Frame Cash 76service Noc4Hosts APK |
|
|
|
|
9
14th May 10:48
Orquidofilo
Mombu User
Join Date: May 2008
Location: NY, U.S.A.
Posts: 26
![]() |
"New NEWS": Well, it appears I was correct in my "assumption/guess" above (about my suspecting the "RBN being @ it again") 2 posts up, which are NOW verified, per this quote from the above source:
SECOND MASS HACK EXPOSED: http://www.itnews.com.au/News/72214,second...ck-exposed.aspx AND, the source I used for this list: http://ddanchev.blogspot.com/2008/03/more-...ame-attack.html And, the salient portion that notes that my suspicion was correct: "if you look at the IPs used in the IFRAMEs, these are the front-end to rogue anti virus and anti spyware tools that were using RBN's infrastructure before it went dark, and continue using some of the new netblocks acquired by the RBN" So, with that said? Here are those URL's from the list above, albeit altered to 0.0.0.0 equations, for your CUSTOM HOSTS FILE, that shuts out RBN (these appear to be their newly acquired domains list) & the servers they use: START OF LIST TO ADD TO YOUR CUSTOM HOSTS FILE FOR BLOCKING OUT BAD SITEs/ADBANNERS THAT MAY BE INFECTED ETC.: 0.0.0.0 do-t-h-e.com 0.0.0.0 rx-pharmacy.cn 0.0.0.0 m5b.info 0.0.0.0 hotpornotube08.com 0.0.0.0 hot-pornotube-2008.com 0.0.0.0 hot-pornotube08.com 0.0.0.0 adult-tubecodec2008.com 0.0.0.0 adulttubecodec2008.com 0.0.0.0 hot-tubecodec20.com 0.0.0.0 media-tubecodec2008.com 0.0.0.0 porn-tubecodec20.com 0.0.0.0 scanner.spyshredderscanner.com 0.0.0.0 xpantivirus2008.com 0.0.0.0 xpantivirus.com 0.0.0.0 bestsexworld.info 0.0.0.0 requestedlinks.com END OF LIST TO ADD TO YOUR CUSTOM HOSTS FILE FOR BLOCKING OUT BAD SITEs/ADBANNERS THAT MAY BE INFECTED ETC.: FOR THOSE INTERESTED (or, those that need actual IP addresses to add to firewall rules tables OR IE restricted zones etc.), here are the actual IP addresses of the bogus servers: do-t-h-e.com (69.50.167.166) rx-pharmacy.cn (82.103.140.65) m5b.info (124.217.253.6) hotpornotube08.com (206.51.229.67) hot-pornotube-2008.com (206.51.229.67) hot-pornotube08.com (206.51.229.67) adult-tubecodec2008.com (195.93.218.43) adulttubecodec2008.com (195.93.218.43) hot-tubecodec20.com (195.93.218.43) media-tubecodec2008.com (195.93.218.43) porn-tubecodec20.com (195.93.218.43) scanner.spyshredderscanner.com (77.91.229.106) xpantivirus2008.com (69.50.173.10) xpantivirus.com (72.36.198.2) bestsexworld.info (72.232.224.154) requestedlinks.com (216.255.185.82) Also - These you won't be able to block via HOSTS file filtering methods, but still can be blocked via other means (IE restricted zones, firewall rules tables, etc. et al): 89.149.243.201 89.149.243.202 72.232.39.252 195.225.178.21 ![]() * Enjoy, stay safe, & keep surfing! APK |
|
|
|
|
|