 |
Spyware Warrior Help with Spyware, Hijacking & Other Internet Nuisances
|
| View previous topic :: View next topic |
| Author |
Message |
Moore Moderator

Joined: 31 May 2004 Last Visit: 14 Mar 2009 Posts: 785 Location: °°.Right.Here.°°
|
Posted: Tue Jun 15, 2004 11:09 am Post subject: SWW HOSTS File Protection Guide |
|
|
###################################################################
<< SWW HOSTS File Protection Guide >>
###################################################################
Why should I use a HOSTS file ?
Customising your HOSTS file is one of the best free alternatives to blocking ads and spyware sites.
A regularly updated HOSTS file can help to prevent spyware / malware from making connections to and from your computer
and also prevent your browser from accessing sites which serve advertising or collect marketing data on you.
By making good use of the HOSTS file , which is already part of the windows operating system ,
you can greatly improve your safety on the internet, save your bandwidth and reduce the chances of being hijacked.
You can also feel more comfortable in knowing that you have increased your protection against rampant spyware & adware,
while also reducing the amount of personal information that is being gathered about you from websites.
It's important to keep your HOSTS file updated like most other security tools,
many of the HOSTS files listed on this page are updated regularly to keep up with the newer malicious sites discovered.
You can add your own sites as you wish, or download a pre made Hosts file maintained by various sites for free.
How it works
Basically, when connecting to any website, your computer sends out a DNS request to retrieve the IP address of that sites domain name.
The HOSTS file is checked first, before the DNS request is sent out from your system.
The HOSTS file allows you to null route any domain of your choice by substituting your own local host IP address "127.0.0.1" with the real IP address.
Essentially this prevents your system from allowing the DNS request to be resolved to it's real IP address, and so the site is unable to load in your browser or other network enabled application.
This is a very effective and totally free way of preventing/blocking hijackers, popups, advertisements and any other annoyances you may encounter during your internet travels.
=======================================
How do I install this HOSTS file?
Simply download the file and put it in the following location depending on your Operating System:
Windows XP C:>WINDOWS>SYSTEM32>DRIVERS>ETC
Windows 2K C:>WINNT>SYSTEM32>DRIVERS>ETC
Windows 98/ME C:>WINDOWS
The Hosts file must have no file extension to work properly , this means it should not end with a .txt .doc. etc , it should just be labelled HOSTS.
Please read this great post by Blackspear at Wilders Security Forums ,
for an extremely well detailed guide to installing a Hosts file [ with pictures ]
<> http://www.wilderssecurity.com/showthread.php?t=78363 <>
Bluetack HOSTS File information and download -
http://bluetack.co.uk/hosts.html
http://www.bluetack.co.uk/forums/index.php?showforum=125
:: Bluetacks Hosts File ::
http://www.bluetack.co.uk/forums/index.php?showtopic=8406
=======================================
Just in case you're wondering : You cannot block IP addresses in a HOST file , only the hostname.
Example:
YES: fedora.nictechnetworks.com
NO: 69.20.16.183
Entries in the Hosts file must begin with localhost address 127.0.0.1 [ or another null address to resolve the unwanted hostnames to ]
127.0.0.1 fedora.nictechnetworks.com
While you cannot use IP addresses to block connections with a Hosts file you can use an IP address in a Hosts file to "override" the DNS resolution of a hostname.
Hijackers can also make use of this however, often hijacking the Hosts file to allow redirection of search engines, or well known security sites to the IP address of the hijackers site instead. Usually to keep their victims from seeking any help.
One example is this rootkit hijack which wipes out the hosts file and blocks the majority of most well known anti-virus sites , it also patches a few system files to bypass the firewall:
http://www.bluetack.co.uk/forums/index.php?showtopic=15097
In the case of competing spyware companies , they hijack the HOSTS file to prevent connections to other spyware / hijack sites to make sure they are the only ones who get the advertising revenue. It's all about the money.
Hijack redirection example:
69.20.16.183 search.netscape.com
69.20.16.183 ieautosearch
66.79.171.75 www.google.com
66.79.171.75 www.yahoo.com
66.79.171.75 www.altavista.com
Hijack security site prevention example:
These entries below for example , will prevent a computer from accessing any of the security sites for help..
127.0.0.1 www.kaspersky.com
127.0.0.1 www.f-secure.com
127.0.0.1 liveupdate.symantec.com
127.0.0.1 customer.symantec.com
127.0.0.1 rads.mcafee.com
127.0.0.1 trendmicro.com
127.0.0.1 liveupdate.symantecliveupdate.com
127.0.0.1 www.mcafee.com
127.0.0.1 mcafee.com
127.0.0.1 viruslist.com
CWS trojans and various other hijackers can easily change the read only settings of a Hosts file to allow them to overwrite the Hostfile entries with their own data.
So it's important to keep a backup of your HOSTS file.
Another good example is the SpySherrif / SpywareNo Hijacker in this thread at Bluetack forums :
http://www.bluetack.co.uk/forums/index.php?showtopic=9994
It not only took out [ wiped out ] my locked Hosts file , but the trojans that accompany the hijack easily disabled the windows taskmanager and many of my security programs as well..
You cannot be too protected , the more layers of security you have set up the better.
Even if you only safe known sites, there have been cases where Ad servers have been hacked and used to install malware on unsuspecting users through their ad network... and servers hosting the website you visit may even get hacked and end up hijacking it's visitors, totally unknown to the server operators.
These are very rare cases , but anything is possible.
A well maintained/updated Hosts file will stop most if not all of the known threats that you are capable of blocking by hostname from getting into your system , the unknown threats will need to be handled by your next layer of protection.
B.I.S.S. Hosts manager , SpywareBlaster and Toadbee's Hoster [ and probably other programs ] make backing up your Hosts file very easy.. Try to get into the habit of making a backup after you add your own entries just in case it gets wiped out.
=======================================
Warning!: Extremely large Hosts files may slow down browsing in windows 2000 / XP ,
it is advised to switch the DNS Client service in services.msc to manual or disabled.
Go to start-> run-> [ type in] Services.msc
Scroll down to DNS Client and select the option to set it to disable/manual
##############################
Recommended HOST file downloads:
##############################
Bluetack Hosts File
http://www.bluetack.co.uk/forums/index.php?showtopic=8406
HP-Hosts
http://hosts-file.net/
http://someonewhocares.org/hosts/
Great HOSTS file information site -
http://www.accs-net.com/hosts/index.html
HOSTS File / ADSERVERS Lists -
http://pgl.yoyo.org/adservers/
hostsfile.mine.nu
http://hostsfile.mine.nu/downloads/
=======================================
Excellent HOSTS File Guides / Information :
http://www.spywarewarrior.com/viewtopic.php?t=410
http://www.bleepingcomputer.com/forums/index.php?showtutorial=51
http://www.accs-net.com/hosts/index.html
The hosts File - DerkerTechnology.net
http://www.spywarewarrior.com/uiuc/soft8a.htm#HOSTS
===============================================
- Recommended HOSTS file management tools -
===============================================
The best FREE Hosts File Managers:
-------------------------------------------------------------------------------------
- B.I.S.S. Hosts Manager - By Bluetack Admin Kimberly -
:: Latest updates of Hosts Manager / Hosts Switch ::
http://www.spywarewarrior.com/viewtopic.php?t=22331
:: FREE Download ::
http://www.bluetack.co.uk/forums/index.php?act=dscript&CODE=showdetails&f_id=5
:: Details ::
http://www.bluetack.co.uk/forums/index.php?showtopic=9240
---------------------------------------------------------------------------
:: B.I.S.S. HOSTS Switch ::
Full details/history please read :
http://www.bluetack.co.uk/forums/index.php?showtopic=13516
Instead of having the B.I.S.S. Hosts Manager open to disable / enable your hosts file, you can now use the B.I.S.S. Hosts Switch
New Hosts Switch [1.2.2.0-1.3.1.0] features include :
- The popup menu has a new entry called "Add Hosts Entry"
- New Tray Icons
- Included a help file. You will need Acrobat Reader. F1 brings up the help file.
Add Hosts Entry
An input box will show up on your screen to add the new website. Just enter the website, don't type the IP prefix (127.0.0.1 or 0.0.0.0), it will be added automatically.
Tray Icons
The Tray Icon will now show the state of the Hosts file : disabled or enabled
A left click on the Tray Icon will restore the program on the screen. A right click on the Tray Icon brings up a menu.
If you are using Internet Explorer, you can add a toolbutton to the default Toolbar to launch the program very quickly. You can set it to load at Windows boot - Normal or in the Tray ...
B.I.S.S. Hosts Manager 2.0 is recommended to access the full features of the add-on. If you already have B.I.S.S. Hosts Manager 2.0 installed, you don't need to download this Add-On separately, it's included from the 1.7 version upwards.
Select Custom Setup if you want to change the default install folder. If B.I.S.S. Hosts Manager is installed, it's recommended that you install this Add-On in the same folder.
Want easy access while browsing ? Add a button to your IE ToolBar .... it will open up the program when you click on it.
This feature only works with Internet Explorer.
When you check the option in the program, start a new Internet Explorer instance afterwards. If the button does not show up on the toolbar, you might need to go to View | Toolbars | Customize and move the Hosts Switch button from "Available toolbar buttons" to "Current toolbar buttons".
---------------------------------------------------------------------------------
- HostsXpert v3.8 by Toadbee [ Formerly known as Hoster ]
| Quote: |
| HostsXpert is an ultra-groovy Hosts file Manager, Editor and Helper-outter. Below you'll find a list of HostsXpert's functions. Just a Simple word of caution - Hosts files are not to be taken lightly - |
>> More Information / Download Link <<
http://www.funkytoad.com/
Features:
| Quote: |
Append File - Allows selection of a file to be appended to your current hosts file.
Replace File - Allows selection of a file to replace your hosts file.
Merge File - Allows selection of a file to be merged with your current hosts file.
Create Backup - Creates a Backup of you current hosts file. Backup file will be placed where ever HostsXpert.exe resides on your Hard drive.
Restore Backup - Restores the backup hosts file.
Restore MS Hosts - Restores the hosts file to Microsoft's original hosts file.
Add to Hosts Files - Adds the line item into your hosts file.
Delete Line - Deletes highlighted line from hosts file.
Toggle Comment - Toggles whether or not a line is a comment ('#').
Sort File - Sorts the current hosts file in alphanumeric order, removes all comment lines and duplicates.
Swap Localhost - Swaps the current hosts file between 127.0.0.1 and 0.0.0.0
Remove Block Items - Removes all blocking lines in the current hosts file.
Copy to Clipboard - Copies the current hosts file to the clipboard.
Make Hosts read-only/writable toggle
Search - Enter text to be searched for, click Previous or Next.
Open in Memopad - Opens the Memopad built-in to HostsXpert.
Save Hosts - Saves the Hosts file from Memopad.
Save As - Allows you to save the hosts file as a file other than "Hosts".
Save Hosts Exit Memopad - Saves the Hosts file from Memopad, and returns you to normal view.
Exit Memopad - Does not save changes.
Whitelist
Remove Whitelist Items -Removes whitelisted Domains from your hosts file.
Add Whitelist Items - Add the whitelisted domains back into your hosts file.
ViewWhitelist - Opens up your whitelist for direct editing.
Save and Exit Whitelist - Saves changes, and closes the editor.
Exit Whitelist - Exits the editor and Discards changes/does not save the whitelist
Download
Merge with or Replace your existing hosts file with either MVPs Hosts file or HpHosts file.
Both websites offer an email subscription service for notification of updates-
MVPsHosts can be found here: http://www.mvps.org/winhelp2002/hosts.htm
(Notification subscription info at bottom of page)
hpHosts found here: http://hphosts.mysteryfcm.co.uk/
(Notification subscription info on download page) |
-------------------------------------------------
Another great Hosts file application by Toadbee :
Homer v1.3
| Quote: |
Homer v1.3
What is Homer?
Homer is a Localhost webserver.
Homer listens to IP 127.0.0.1 for connections on port 80 - Logs requests, and serves up a picture of your choosing.
Huh?
If you use an Ad-Blocking HOSTS file - Such as HPGuru’s or Bluetack’s - you may see alot of “cannot connect” type messages and missing graphics.
Running Homer will change that by serving an image of your choice. Doing so will make pages load faster as a consequence. |
See here for full details:
http://www.funkytoad.com/
-------------------------------------------------
- Hostess -
http://accs-net.com/hostess/
HOSTS file manager with Hosts Toggle integrated
| Quote: |
| The Hostess program has been designed to help you easily maintain your Hosts file for the purpose of blocking servers rather than for its original purpose of quicker DNS lookups. It stores the hostnames in an indexed database, eliminating duplicates and placing hosts into logical groups that can be ordered for efficiency. Hostess has powerful import, export and search features. It can even create a registry file for adding domains to the Internet Explorer Restricted Zone. |
Hostess will warn you if you already have the same entry in your Hosts file so you can avoid duplicates.
One tip , when importing your hosts file stick to the default group.
-------------------------------------------------
- Hosts Toggle -
http://accs-net.com/hosts/HostsToggle/
| Quote: |
| Switch on / off HOSTS file blocking with a click of a button |
-------------------------------------------------
- Aldos Hosts Manager -
http://www.aldostools.com/hosts.html
| Quote: |
| Merge hosts / remove duplicates |
===============
=============
Other handy tools:
=============
===============
- FastNet99 -
| Quote: |
| FastNet99 is a network utility that will speed up your web browser every time you want to connect to a web site on the Internet, by avoiding time consuming DNS lookups. It provides all the tools you need to help diagnose network problems and get information about users, hosts and networks on the Internet or on your Intranet. It combines DNS Lookup, Ping, TraceRoute, WhoIs, Finger, Time Synchronizer, KeepAlive and more... |
http://w3.quipo.it/gcriaco/
-------------------------------------------------
- NS-Batch -
| Quote: |
JIM PRICE created this utility to allow host name lookups of lots of IP addresses.
It also lets you interactively look up host name from IP addresses or IP addresses from hostnames.
Just feed it a file with IP addresses in it (of the format 127.0.0.1), and it will dig out the addresses,
look up the hostnames, and create a text file containing:
1) the IP address in hex (useful for sorting)
2) the IP address in dotted-octet format (i.e., 207.43.183.2)
3) the corresponding hostname, (i.e., www.jimprice.com) and
4) the hostname reversed (i.e. com.jimprice.www)
5) additional status information about the lookup (whether or not it worked)
You can then import the text file into your favorite word processor, spreadsheet, or other program, and sort it by IP address or other fields. Also, the program now includes features to probe a subnet (listing all the computers on a given network), and to display your local host's IP address, as well as some amount of flexibility in the output format |
- http://www.jimprice.com/jim-soft.htm#nsbatch
-------------------------------------------------
:: Warning ::
| Quote: |
| Hosts file reader by Option explicit, available on various sites, should be avoided as it will destroy your large custom hosts file and reduce it to a much smaller size eg: 64k |
=============================
============================
:: IP ADDRESS GUIDES ::
============================
=============================
IP Addresses Explained -
http://www.bleepingcomputer.com/forums/ind...showtutorial=37
BLUETACK IP ADDRESS GUIDE
http://www.bluetack.co.uk/forums/index.php?showtopic=52
===========================
The ULTIMATE Network Resource Page -
http://www.spywarewarrior.com/uiuc/info19.htm
===========================
==========================
:: WHOIS LOOKUPS ::
==========================
===========================
http://ws.arin.net/cgi-bin/whois.pl
http://ripe.net/cgi-bin/search/gdquery.cgi?
http://www.apnic.net/apnic-bin/whois.pl
http://www.whois.sc/
http://www.dnsstuff.com/
http://www.samspade.org/
http://www.completewhois.com/
http://www.demon.net/external/
http://www.all-nettools.com/toolbox
http://www.dshield.org/ipinfo.php?ip=XXX.XXX.XXX.XXX
http://www.fixedorbit.com/search.htm
============================
===========================
:: IP INDEX SITES ::
===========================
============================
http://www.fixedorbit.com/welcome.htm
http://www.flumps.org/ip/index.html
http://www.sbslinks.com/Ipaddress.htm
############################################################ _________________ | Blockpost | Blocklist Pro Internet Security | BLM | Hosts |
Last edited by Moore on Sat Apr 28, 2007 5:00 am; edited 62 times in total |
|
| Back to top |
|
 |
3162 Honorary Site Admin

Joined: 31 Mar 2004 Last Visit: 04 May 2009 Posts: 6522
|
Posted: Sun Oct 31, 2004 5:11 pm Post subject: |
|
|
I made this a Sticky, for now  _________________ Proud member of the Chest Zipper Club! |
|
| Back to top |
|
 |
|
|
You cannot post new topics in this forum You cannot reply to topics in this forum You cannot edit your posts in this forum You cannot delete your posts in this forum You cannot vote in polls in this forum
|
smartBlue Style © 2002 Smartor
Powered by phpBB © 2001, 2002 phpBB Group
|