Showing posts with label security. Show all posts
Showing posts with label security. Show all posts

Saturday, March 20, 2021

Help - Ping request could not find host ... DNS problem

 You may have seen this message before:

Ping request could not find host www.cnn.com. Please check the name and try again.

There could be many things that can go wrong with the networking that caused this. Ultimately it is very likely the DNS that is the problem.

Firstly, let's simply go through a few troubleshooting options - just to rule out it is not because of the them. Do one step at a time, check the WiFi and if it works, don't need to progress to the next step.

1. For older laptops, believe it or not, there is actually a slider switch to click the WiFi on or off. Check this if you have it.

2. On Windows, on the TaskBar, ensure that the Wifi (not any particular Wifi network yet) itself is turn on. The WiFi can be either On or Off or Flight Mode or something else.

3. Check that the Wifi is connected to a particular WiFi network. Make sure it says Connected and Secured. And there is no yellow exclamation mark.

4. Open up CMD command terminal, type:

ipconfig  /release 

ipconfig /renew

ipconfig /flushdns

5. Reboot the computer.

If all else does not work, it is now time to suspect the DNS.

The DNS, in layman's term (you can Google for the exact definition), is directory service that lookup the URL you type and translate to an IP address. Its like a Post Office that receives an address and then go to that address. Our computer need to have the address of the DNS server itself - eg. we need the POST OFFICE's address, so that we can give them our letter.

The so somehow, our computer needs to know which DNS IP address to use. Most of the time, this is hidden from the user, that is why most computer user don't have to deal with it and so don't understand it. It can be automatically set on the modem or router, and also optionally automatically set on the Windows network settings.

So why should there be a problem when the DNS working nicely behind the scenes one day, then the internet is not working the next day? There could be many answers, but a recent experience has shown that some software, including VPN software can go it to the network settings and change the DNS address.

Hence one more solution to above error message is to change the DNS address on the Windows networking level. Whichever Windows version you have, 

- find your own way to the 'Network Connections' page or 'Change Adapter Settings' and you can see a page with a list of your network (ethernet, Wifi, VPN) adapters. 

- Right click on the Wifi adapter, if you are using the Wifi adapter.

- Choose 'Internet Protocol Version 4', and click on the Properties

- Go to the section called 'Use the following DNS server addresses', and add 'Preferred DNS' and 'Alternative DNS'


Some of the free DNS addresses are:

Quad9 - known for security

9.9.9.9, 149.112.112.112 (Secured)

9.9.9.10, 149.112.112.10 (Unsecured)

Google - you know them

8.8.8.8, 8.8.4.4

Cloudfare - known for speed

1.1.1.2, 1.0.0.2

OpenDNS - mature and known for security, 

208.67.222.222, 208.67.220.220

CleanBrowsing - known for parental filtering

185.228.168.168, 185.228.169.168

Sunday, April 06, 2014

How to use hotel wifi safely


The links below are to a few articles about how to use FREE hotel wifi safely. In summary:
1. There is no real safe way to use hotel wifi - Be Warned
2. Using the hotel LAN (not wifi) is even worse
3. Using VPN provides a layer of protection since it hides the data transmitted from your device to the internet. However it still doesn't prevent a trojan from being planted on your system and accessing your file system.


http://us.norton.com/yoursecurityresource/detail.jsp?aid=free_wifi


http://traveltips.usatoday.com/safely-use-wireless-internet-hotels-2970.html


http://www.wikihow.com/Stay-Safe-While-Using-Hotel-WiFi


http://blog.hotspotshield.com/2013/06/17/hotel-wifi-security/


http://forums.cnet.com/7723-6132_102-565662/how-can-i-use-free-wifi-in-hotel-safely/

Wednesday, April 06, 2011

Security RSA - links

OBSOLETE - see http://xtechnotes.blogspot.com/2011/08/news-security.html

This article consist of links to other sites or blogs about RSA news:

Written on April 1, 2011 by Uri Rivner
"The first thing actors like those behind the APT do is seek publicly available information about specific employees – social media sites are always a favorite.  With that in hand they then send that user a Spear Phishing email. Often the email uses target-relevant content; for instance, if you’re in the finance department, it may talk about some advice on regulatory controls.
The attacker in this case sent two different phishing emails over a two-day period. The two emails were sent to two small groups of employees; you wouldn’t consider these users particularly high profile or high value targets. The email subject line read “2011 Recruitment Plan.”............

Sunday, July 13, 2008

Online Scan - AntiVirus

As with Firewalls, there should be at most, one Antivirus program running on your PC. More than that will cause uncertain behaviour. But how do we know that our antivirus is a good one. Or if we scan a file and it passed our antivirus scan, are we sure it is OK? One solution is to scan the file or files using online scanners available from the web. Here are a few of them:

http://housecall.trendmicro.com/
http://www.kaspersky.com/virusscanner
http://www.bitfender.com/scan8/ie.html
http://www.pandasecurity.com/homeusers/solutions/activescan
http://us.mcafee.com/root/mfs
http://onecare.live.com/site/en-US/default.htm
http://pestpatrol.com/
http://www.f-secure.com/en/web/labs_global/removal/online-scanner

Even easier is to upload one file and have it scanned by multiple antivirus software. This can be done at: http://www.virustotal.com/

Malware can be checked by submitted a file to this website:
http://malwr.com/about/

Alternatively, one can use a sandbox to test our suspicious applications first. Some of the sandbox are:
Norman Sandbox - www.norman.com/microsites/nsic

(this article can also be found at:
http://pckingsford.com//index.php?option=com_content&task=blogcategory&id=19&Itemid=39 )

Saturday, July 12, 2008

Firewall Testing (Hardening)

Here are some tools and techniques to test if your firewall is up to scratch:
1. www.pcflank.com
Contains various test for the firewall including: port scanners, stealth testing, leak test and others.
For leak test, download PCFlankLeaktest.exe. This test tries to send some information out of your PC to the PCFlank site. The results are shown in http://www.pcflank.com/pcflankleaktest_results.htm

. According to PCFlank, only Outpost Firewall Pro and Tiny Personal Firewall pass the leaktest. At PCKingsford, we have tried the FREE Comodo Firewall Pro (CFP) and this works. If it fails, you just need to be sure that you have not tell CFP to ALLOW it. To check whether an application is allowed in CFP, open up the CFP, go to the Defense+ on top, then go to the Advanced tab on the left menu, then click Computer Security Policy. Look for the application name and edit the rules for it.

2. ShieldsUp at http://www.grc.com/faq-shieldsup.htm
Click on Services tab on the website, then select ShieldsUp. Follow the instruction to test your firewall via this website. The tests include:
File Sharing
Common Ports
All Service Ports
Messenger Spam
Browser Helpers

3. Leaktest 1.2 at http://www.grc.com/lt/leaktest.htm This is one of the original firewall leaktest program that started it all.

4. Firewall Leak Tester - www.firewallleaktester.com
This is a one-stop shop for leak tester programs you can use to test your software. It has over 26 leak testers. The website published results comparing various firewalls but note that the comparison was done in 2006 so that may have been outdated. You can always download the leak testers and test individually.
Other leak testers are:
http://www.pcflank.com/pcflankleaktest.htm

(this article can be seen at
www.pckingsford.com)

5. Testing exploits to PC.
http://www.pcflank.com/exploits.htm - simulates Denial of Service attacks on your system.

6. Question on "How Does a Router Protect?" has some answers here:
http://xtechnotes.blogspot.com.au/2012/04/how-does-router-protect.html

7. Linux - IPTABLES
For Linux users, the software firewall IPTABLES allow maximum configurability.
More details can be found in the "Linux Firewall" section in: http://xtechnotes.blogspot.com.au/2012/05/notes-linux.html

A list of simple rules is given here as an example  for
Super Stealth mode
----------------
iptables -P INPUT DROP
iptables -P OUTPUT ACCEPT
iptables -F
iptables -X
iptables -A INPUT -m state --state RELATED,ESTABLISHED -j ACCEPT
iptables -A INPUT -i lo -j ACCEPT
----------------
Once you've executed them, use this command for the stealth config to stick:
Code:
service iptables save

The above rules are quite strict. For simple web browsing, try this:
Basic Web Browsing mode
-----------------------------------
iptables -F
iptables -A INPUT -i lo -j ACCEPT
iptables -A INPUT -m state --state ESTABLISHED,RELATED -j ACCEPT
iptables -A INPUT -p tcp --sport 80 -j ACCEPT
iptables -A INPUT -p udp --sport 53 -j ACCEPT
iptables -A INPUT -j DROP
iptables -A OUTPUT -j ACCEPT
iptables -P INPUT DROP
iptables -P FORWARD DROP
iptables -P OUTPUT DROP
iptables-save > /etc/sysconfig/iptables
----------------------------------

then to restart:
service iptables save
service iptables start

Links to IPTABLES configuration:
http://www.thegeekstuff.com/2011/06/iptables-rules-examples/
http://www.thegeekstuff.com/2012/08/iptables-log-packets/
http://www.thegeekstuff.com/2011/01/redhat-iptables-flush/
http://www.thegeekstuff.com/2011/03/iptables-inbound-and-outbound-rules/
http://www.thegeekstuff.com/2011/02/iptables-add-rule/
http://www.thegeekstuff.com/2011/01/iptables-fundamentals/