List of bad ways to create a website blacklist: 1) Modify the host file to resolve the sites to loopback. 2) I'm sure there's a number 2, but it doesn't really matter to the point I'm making.
List of better ways to do it: 1) Set up a transparent web proxy in the DMZ that automatically updates its blacklist from a trusted provider and redirects requests to an internal page explaining the company's internet use policy. While you're at it, set up the firewall to automatically drop packets originating from the blacklisted sites, as well as those from a different blacklist of malicious IPs.
I think he was just showing us more of what we can do with a loopback address. I think he will address DMZ in security+. He tries not to do too much security+ in the network+ class but he will go off on some fun security+ tangents.
Yeah, see, he wasn't showing us how best to create blacklists. That wasn't the lesson. He was talking about the host file.
"The free utility Spybot - Search & Destroy, for example, includes a feature called "Immunize" that populates the hosts file with thousands of URLs of such websites redirected to 127.0.0.1 (localhost) to block them."
He grabbed one of those URLS from spybot to illustrate how the host file can blacklist a website by redirecting the sites to the loopback.
Comments 7
1) Modify the host file to resolve the sites to loopback.
2) I'm sure there's a number 2, but it doesn't really matter to the point I'm making.
List of better ways to do it:
1) Set up a transparent web proxy in the DMZ that automatically updates its blacklist from a trusted provider and redirects requests to an internal page explaining the company's internet use policy. While you're at it, set up the firewall to automatically drop packets originating from the blacklisted sites, as well as those from a different blacklist of malicious IPs.
I'll be here all week.
Reply
Reply
Reply
"The free utility Spybot - Search & Destroy, for example, includes a feature called "Immunize" that populates the hosts file with thousands of URLs of such websites redirected to 127.0.0.1 (localhost) to block them."
He grabbed one of those URLS from spybot to illustrate how the host file can blacklist a website by redirecting the sites to the loopback.
Reply
And this guy is teaching security?? QFE.
Reply
Reply
Reply
Leave a comment