Page 1 of 2 12 LastLast
Results 1 to 16 of 18

Thread: News - Windows 8 hosts won't block Doubleclick ads or Facebook

  1. #1
    HEXUS.admin
    Join Date
    Apr 2005
    Posts
    18,662
    Thanks
    0
    Thanked
    350 times in 187 posts

    News - Windows 8 hosts won't block Doubleclick ads or Facebook

    Windows Defender is defending advertisers.
    Read more.

  2. #2
    PHP Geek Flash477's Avatar
    Join Date
    Dec 2008
    Location
    Devon
    Posts
    777
    Thanks
    50
    Thanked
    70 times in 63 posts

    Re: News - Windows 8 hosts won't block Doubleclick ads or Facebook

    Interesting that it still allows Bing to be blocked...

  3. #3
    HEXUS.social member
    Join Date
    Jul 2003
    Location
    Internet
    Posts
    18,065
    Thanks
    616
    Thanked
    1,327 times in 862 posts

    Re: News - Windows 8 hosts won't block Doubleclick ads or Facebook

    Windows 8 hosts won't block Doubleclick ads or Facebook
    That's a real sensationalist headline. It will block them fine, you just need to change a setting to allow it.

    The hosts file should have been locked down a long time ago, given redirects are put into it by any malware not written by an idiot.
    Quote Originally Posted by Saracen View Post
    And by trying to force me to like small pants, they've alienated me.

  4. #4
    Registered+
    Join Date
    Sep 2007
    Posts
    22
    Thanks
    1
    Thanked
    0 times in 0 posts

    Re: News - Windows 8 hosts won't block Doubleclick ads or Facebook

    Nice of Microsoft to give the user control over their browsing requirements

  5. #5
    Senior Member
    Join Date
    Jun 2004
    Location
    Kingdom of Fife (Scotland)
    Posts
    2,622
    Thanks
    169
    Thanked
    97 times in 90 posts
    • crossy's system
      • Motherboard:
      • ASUS M4A89GTD Pro/USB3
      • CPU:
      • AMD Phenom II 1090T / Noctua NH-D14
      • Memory:
      • 8GB Crucial Vengenance DDR3-1600
      • Storage:
      • 60GB OCZ Vertex 2E, 1TB Samsung Spinpoint F3, 2TB WD Caviar Green
      • Graphics card(s):
      • XFX 7970 Double D Black
      • PSU:
      • Corsair AX750 (modular)
      • Case:
      • Coolermaster HAF932 (with wheels)
      • Operating System:
      • Windows 7 Pro 64bit
      • Monitor(s):
      • LG Flattron W2361V
      • Internet:
      • VirginMedia 60Mb

    Re: News - Windows 8 hosts won't block Doubleclick ads or Facebook

    Even if you edit your hosts file and write protect it, once you open a web browser it will be restored to unblock the above sites. While you can get around this by turning off Windows Defender ... Windows Defender protects your hosts file to stop malware changing it. Malware often changes the hosts file to redirect your browsing to dodgy websites and to lock you out of from helpful antivirus vendor sites.

    A user at GHacks.net has suggested that Windows 8 users who want to keep Windows Defender yet be able to edit the hosts file can actually exclude the file from “protection”.
    Am I the only one who reads the above and comes to the conclusion that Windows Defender is "broken"? Preventing malware changing the host file seems like a darn good idea, but couldn't they have implemented some form of check-in/check-out system so you - as an informed user - could make your edits in peace and have WD accept them as genuine "yes I really mean that!"?

    My suspicious mind also has a problem with the fact that advertisers seem to figure prominently amongst the list of "do not touch" sites...
    Coalition: a system of government that adds one intellect to another and gets a half-wit as a result

    I want finger extensions ... then I can play this darned guitar properly!

  6. #6
    HEXUS.social member
    Join Date
    Jul 2003
    Location
    Internet
    Posts
    18,065
    Thanks
    616
    Thanked
    1,327 times in 862 posts

    Re: News - Windows 8 hosts won't block Doubleclick ads or Facebook

    Quote Originally Posted by crossy View Post
    Am I the only one who reads the above and comes to the conclusion that Windows Defender is "broken"? Preventing malware changing the host file seems like a darn good idea, but couldn't they have implemented some form of check-in/check-out system so you - as an informed user - could make your edits in peace and have WD accept them as genuine "yes I really mean that!"?

    My suspicious mind also has a problem with the fact that advertisers seem to figure prominently amongst the list of "do not touch" sites...
    99% of users don't know what a hosts file is. Anyone that does will known how to add an exclusion or Google it to find out. If an option did pop up, you'd just get most users hitting "yes".

    The advertisement servers are being added as some of the less harmful malware adds in redirects to different ad servers to get the writers more money. Given that most pages also have ads, you can use it as a way to check for updates of the malware.

    Anything that gets high traffic ultimately is probably on the list. I doubt there is a sinister motive here.
    Quote Originally Posted by Saracen View Post
    And by trying to force me to like small pants, they've alienated me.

  7. #7
    HEXUS webmaster Steve's Avatar
    Join Date
    Nov 2003
    Location
    Bristol
    Posts
    14,144
    Thanks
    268
    Thanked
    788 times in 447 posts
    • Steve's system
      • CPU:
      • Intel i3-350M 2.27GHz
      • Memory:
      • 8GiB Crucial DDR3
      • Storage:
      • 320GB HDD
      • Graphics card(s):
      • Intel HD3000
      • Operating System:
      • Ubuntu 11.10

    Re: News - Windows 8 hosts won't block Doubleclick ads or Facebook

    Quote Originally Posted by crossy View Post
    My suspicious mind also has a problem with the fact that advertisers seem to figure prominently amongst the list of "do not touch" sites...
    Ad companies' scripts are served up on millions of websites. If you hijack the hosts entry for it you can inject code onto a lot of sites the user visits on that machine.
    PHP Code:
    $s = new signature();
    $s->sarcasm()->intellect()->font('Courier New')->display(); 

  8. #8
    Super Nerd
    Join Date
    Jul 2008
    Location
    London
    Posts
    1,276
    Thanks
    11
    Thanked
    81 times in 56 posts
    • kingpotnoodle's system
      • Motherboard:
      • Asus P8Z68 Pro
      • CPU:
      • Core i7 2600K
      • Memory:
      • 8GB Corsair Vengeance DDR3 1600MHz CL8
      • Storage:
      • 256GB Corsair m4 SSD & 1.5TB Seagate
      • Graphics card(s):
      • Asus GTX-670 DirectCU-II
      • PSU:
      • Corsair AX 750W
      • Case:
      • Silverstone FT02B
      • Operating System:
      • Windows 7 Pro 64
      • Monitor(s):
      • Hazro HZ27WD
      • Internet:
      • Be ADSL2+ ~8Mb

    Re: News - Windows 8 hosts won't block Doubleclick ads or Facebook

    Sounds like it's actually doing as intended and probably as it should for the vast majority of users - i.e. monitoring the hosts file and removing redirects which would be highly likely to impact your web experience or be used to replace common pages with malware replacements.

    If you're a virus writer and you want to make sure the zombie is checking in then you could DNS spoof the most common ad provider URLs to send ads in pages to your command and control server, simples.

    If anything Defender is not doing ENOUGH (given the number of entries untouched above) - for 99% of users the hosts file should be devoid of custom entries and Defender should enforce this but possibly allow setting of any hosts entries via a secure mechanism buried in it's own UI and do what some anti-spam tools do and add entries to localhost for known bad/dangerous URLs. Oh and add a nice friendly comment to the file letting power users know what's going on...

  9. #9
    Registered+
    Join Date
    Aug 2008
    Posts
    46
    Thanks
    0
    Thanked
    0 times in 0 posts
    • Numenor's system
      • Motherboard:
      • Asus P5Q-PRO
      • CPU:
      • Wolfdale E8400
      • Memory:
      • 4GB OCZ DDR2
      • Storage:
      • 320GB Spinpoint F1 + 1TB Spinpoint F1
      • Graphics card(s):
      • Powercolor HD4870 1GB
      • PSU:
      • Corsair HX620
      • Case:
      • Antec 300
      • Operating System:
      • Vista Home Premium 64-bit
      • Monitor(s):
      • 37" 1080p TV
      • Internet:
      • Be Unlimited

    Re: News - Windows 8 hosts won't block Doubleclick ads or Facebook

    Dangerous ground, this. Surely with UAC there should be a mechanism by which Windows Defender can know that a change has been intentionally made by the user. Maybe even a way of identifying that the entry is pointing to 127.0.0.1 and is therefore highly unlikely to have been done by malware.

  10. #10
    Only@Hexus! watercooled's Avatar
    Join Date
    Jan 2009
    Posts
    7,392
    Thanks
    1,245
    Thanked
    562 times in 497 posts

    Re: News - Windows 8 hosts won't block Doubleclick ads or Facebook

    A lot of security software monitors the hosts file, often warning the user if anything changes it. Upon reading the headline it does sound quite worrying, but it's nothing new; as others have said, it should be doing more really.

    Just because it points to 127.0.0.1 doesn't mean it's legit, in theory the malware could host its own web server locally, especially if the writers knew localhost entries remain untouched.

  11. #11
    Senior Member
    Join Date
    Jun 2009
    Location
    Bracknell
    Posts
    468
    Thanks
    47
    Thanked
    18 times in 17 posts
    • AGTDenton's system
      • Motherboard:
      • ASUS P6T7 WS Supercomputer
      • CPU:
      • Intel Core i7 980
      • Memory:
      • 12GB Corsair Dominator GT
      • Storage:
      • Seagate 300GB SAS Cheetah + 2x 2TB Seagate Barracuda XT
      • Graphics card(s):
      • Gigabyte GeForce GTX 680
      • PSU:
      • 1050W Enermax Revolution
      • Case:
      • Fractal Design Define XL
      • Operating System:
      • Vista Ultimate x64
      • Internet:
      • 60MB Virgin

    Re: News - Windows 8 hosts won't block Doubleclick ads or Facebook

    I use SpybotSD to monitor my Hosts file. Im not a massive fan of Windows Defender as to get a new version seems to require a new operating system.

    Home/Small Business routers have the ability to block websites/IP's, but none of them that I'm aware of allow you to upload a list, instead you have to sit there forever entering in new sites to block. It would be really really handy to be able to upload a text file to your router to block sites, then you dont need to worry about individual PC's host files because all of them will be blocked (while this doesnt help with portable equipment, for small businesses or just multiple desktops at home this would be useful). Routers with space limitations could utilise USB/SD memory for large text files/database.
    Quote Originally Posted by Jason Brody
    Jiggle the key, depress the pedal

  12. #12
    Registered+
    Join Date
    Aug 2008
    Posts
    46
    Thanks
    0
    Thanked
    0 times in 0 posts
    • Numenor's system
      • Motherboard:
      • Asus P5Q-PRO
      • CPU:
      • Wolfdale E8400
      • Memory:
      • 4GB OCZ DDR2
      • Storage:
      • 320GB Spinpoint F1 + 1TB Spinpoint F1
      • Graphics card(s):
      • Powercolor HD4870 1GB
      • PSU:
      • Corsair HX620
      • Case:
      • Antec 300
      • Operating System:
      • Vista Home Premium 64-bit
      • Monitor(s):
      • 37" 1080p TV
      • Internet:
      • Be Unlimited

    Re: News - Windows 8 hosts won't block Doubleclick ads or Facebook

    Good point, watercooled. It may be a necessary evil then. I'm sure other methods of blocking such sites will fill in the gap left by this change.

  13. #13
    Monkey Apex's Avatar
    Join Date
    Jul 2003
    Location
    Huddersfield
    Posts
    3,744
    Thanks
    426
    Thanked
    62 times in 45 posts
    • Apex's system
      • Motherboard:
      • Asus F1A55-M
      • CPU:
      • AMD A6-3670K APU
      • Memory:
      • 16 GiB
      • Storage:
      • 5.0 TiB
      • Graphics card(s):
      • ATI (ASUS) HD6850 1024MiB
      • PSU:
      • 750
      • Case:
      • SilverStone TJ08-E
      • Operating System:
      • Windows 7 64Bit
      • Monitor(s):
      • Dell U2410 24"
      • Internet:
      • 20Mb nTL Cable

    Re: News - Windows 8 hosts won't block Doubleclick ads or Facebook

    Quote Originally Posted by AGTDenton View Post
    I use SpybotSD to monitor my Hosts file. Im not a massive fan of Windows Defender as to get a new version seems to require a new operating system.

    Home/Small Business routers have the ability to block websites/IP's, but none of them that I'm aware of allow you to upload a list, instead you have to sit there forever entering in new sites to block. It would be really really handy to be able to upload a text file to your router to block sites, then you dont need to worry about individual PC's host files because all of them will be blocked (while this doesnt help with portable equipment, for small businesses or just multiple desktops at home this would be useful). Routers with space limitations could utilise USB/SD memory for large text files/database.
    Use OpenDNS and you can block the sites at the dns level

  14. #14
    Registered+
    Join Date
    Mar 2012
    Posts
    65
    Thanks
    0
    Thanked
    4 times in 3 posts

    Re: News - Windows 8 hosts won't block Doubleclick ads or Facebook

    Abp.

  15. #15
    Senior Member
    Join Date
    Jun 2004
    Location
    Kingdom of Fife (Scotland)
    Posts
    2,622
    Thanks
    169
    Thanked
    97 times in 90 posts
    • crossy's system
      • Motherboard:
      • ASUS M4A89GTD Pro/USB3
      • CPU:
      • AMD Phenom II 1090T / Noctua NH-D14
      • Memory:
      • 8GB Crucial Vengenance DDR3-1600
      • Storage:
      • 60GB OCZ Vertex 2E, 1TB Samsung Spinpoint F3, 2TB WD Caviar Green
      • Graphics card(s):
      • XFX 7970 Double D Black
      • PSU:
      • Corsair AX750 (modular)
      • Case:
      • Coolermaster HAF932 (with wheels)
      • Operating System:
      • Windows 7 Pro 64bit
      • Monitor(s):
      • LG Flattron W2361V
      • Internet:
      • VirginMedia 60Mb

    Re: News - Windows 8 hosts won't block Doubleclick ads or Facebook

    Quote Originally Posted by kingpotnoodle View Post
    If anything Defender is not doing ENOUGH (given the number of entries untouched above) - for 99% of users the hosts file should be devoid of custom entries and Defender should enforce this but possibly allow setting of any hosts entries via a secure mechanism buried in it's own UI and do what some anti-spam tools do and add entries to localhost for known bad/dangerous URLs. Oh and add a nice friendly comment to the file letting power users know what's going on...
    That's pretty much what I was getting at when I said:
    Quote Originally Posted by crossy View Post
    couldn't they have implemented some form of check-in/check-out system so you - as an informed user - could make your edits in peace and have WD accept them as genuine "yes I really mean that!"?
    Maybe someone needs to log an improvement request with the 'Defender team?
    Coalition: a system of government that adds one intellect to another and gets a half-wit as a result

    I want finger extensions ... then I can play this darned guitar properly!

  16. #16
    Member
    Join Date
    Jul 2012
    Posts
    164
    Thanks
    11
    Thanked
    13 times in 8 posts

    Re: News - Windows 8 hosts won't block Doubleclick ads or Facebook

    Quote Originally Posted by watercooled View Post
    Just because it points to 127.0.0.1 doesn't mean it's legit, in theory the malware could host its own web server locally, especially if the writers knew localhost entries remain untouched.
    One more reason to use 0.0.0.0 "black hole" redirects instead of 127.0.0.1 loop-back address on systems that support this. It's also a lot faster (since that address doesn't exist) and uses less resources as it won't try to establish a connection to localhost firing all kinds of network aware events and running locally installed software. Many users are running web servers and/or update services listening on specific ports and 127.0.0.1 redirects would try to establish a connection with these services. Too many connections to localhost without specifying a port number can create all kinds of problems, including extremely long log files and random system crashes if certain advanced SYN Flood or DDoS detectors are installed and block incoming ports on a network loop-back address as a result of too many requests. Do try however, if your system supports 0.0.0.0 redirects before using them with all DNS targets you'd like to block with specific redirects in your HOST file! Cheers!
    Last edited by howdee; 20-08-2012 at 04:42 PM.

Page 1 of 2 12 LastLast

Thread Information

Users Browsing this Thread

There are currently 1 users browsing this thread. (0 members and 1 guests)

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •