Тёмный

Using DNS As A Firewall 

Ken Harris
Подписаться 11 тыс.
Просмотров 12 тыс.
50% 1

Опубликовано:

 

15 сен 2024

Поделиться:

Ссылка:

Скачать:

Готовим ссылку...

Добавить в:

Мой плейлист
Посмотреть позже
Комментарии : 56   
@TheOriginalJoeBloggs
@TheOriginalJoeBloggs 7 дней назад
I bet you are blocked too
@KenHarrisio
@KenHarrisio 6 дней назад
Worse than an LA freeway. I forgot to take my daily dose of Metamucil.
@optimizedujjwal1592
@optimizedujjwal1592 9 дней назад
brother this small small steps makes us hero and fully harded pc tq for the help man take care have a great day
@KenHarrisio
@KenHarrisio 9 дней назад
Thanks for supporting the channel brother! Have a good day!
@KenHarrisio
@KenHarrisio 9 дней назад
Something I forgot to mention in the video - it's astronomically rare for a legit website to get block by one of the DNS providers. If you notice a site does get blocked, they might have been caught trying to spread something by one of the CTI groups and got added on a blocklist.
@virtualheadless4764
@virtualheadless4764 9 дней назад
dude simplewall is malware or not its on virustotal scan its shows 7 flags.Your suggest simlewall in your last watched video.whats yout thought
@KenHarrisio
@KenHarrisio 9 дней назад
I've got a couple theories on why this is happening. The first is that it might have something to do with an option that can be toggled to allow it to startup with the system and override the UAC warning. I don't think this would be the issue though. The more likely issue is that it allows the user to have granular control over the network and the app isn't signed. The dev, henrypp, seemed like he would have done it if there was a way to do it without having to pay to do it. Most CAs charge about $400/year, which is an unreasonable cost for someone who makes a free program. MS says they want devs to do this for safety reasons, but some open source devs can't accommodate for the cost. Thread: github.com/henrypp/simplewall/issues/211 I looked through a couple VT scans and noticed the newest version for some reason has 8 detections. I ran 3.8 as well and it only had detections from SecureAge and Trapmine. Given how much the tool is used by others and that I've ran it myself for years without issue, it seems like these are consistent false positive issues.
@virtualheadless4764
@virtualheadless4764 9 дней назад
@@KenHarrisio i also think its false positive. also i have bitdefender installed in my system and when i boot my system every time simplewall ask for evevation permission bec bitdefender somehow mess with that and can also see on vs total. now i hate how only trusted antivirus even do such kind of sentic things fuck that to who support coward monopoly
@KumbaIvor
@KumbaIvor 7 дней назад
Adguard Home will also do a brilliant job and it's free to deploy. My only problem with Pi-Hole is that it doesn't do DNS-over-TLS
@keffey99
@keffey99 6 дней назад
Based on this video, I turned off the default DNS on Firefox and changed the DNS from Cloudflare to Quad9 on my computers, phone, tablet, and router. I passed on ControlD for now because you said it is not needed and an account is required. Good video. Thanks.
@soskom
@soskom 9 дней назад
Great info. iOS configuration profile instaled. Thank you. Following profile. You deserve it.
@KenHarrisio
@KenHarrisio 6 дней назад
Hell yeah, thanks brother!
@supriyochatterjee4095
@supriyochatterjee4095 8 дней назад
Excellent information and another great video, Next DNS and Quad 9 and Cloudfare are the best DNS options in terms of security I guess, please kindly make more details videos on deep configurations of Windows Firewall for advanced security and other software firewalls.
@KenHarrisio
@KenHarrisio 6 дней назад
Thanks for supporting the channel and suggestion! I'll add a Windows Firewall config video to the list to make.
@baldina943
@baldina943 9 дней назад
Love ur content
@loupasternak
@loupasternak 7 дней назад
Why dont google and opendns use this blocklist ? Also, couldn't this blocklist be used from the client side, either in advance of the request , OR after the ip address is resolved, but before the site is accessed ?
@KenHarrisio
@KenHarrisio 6 дней назад
My guess would be they don't want to accidentally block legit websites/services, through this has been extremely rare in my use. If I understand your question, you're asking if you can use the blocklist on your PC? If so, there's a couple different options I know of. Something with built in blocklists such as Portmaster (which have a lot of similarity to DNS providers and can be turned on/off as you see fit). Windows Firewall also has the ability to block connections, though it isn't as user friendly.
@J-Ernie
@J-Ernie 8 дней назад
Hi Ken, Can DNS0 be used while using Portmaste? also, should it be used in Portmaster or just do it through windows?
@KenHarrisio
@KenHarrisio 6 дней назад
Yeah, it'll work through Portmaster! In the settings panel at the top of the page, you can change your DNS provider. I personally prefer to set DNS through Portmaster, but it'll work well through Windows too. The following two lines should work for DoT: dot://dns.dns0.eu?ip=193.110.81.0 dot://dns.dns0.eu?ip=185.253.5.0 The following should work for DoH: dns0.eu
@J-Ernie
@J-Ernie 6 дней назад
​@@KenHarrisio Thank you. I am currently using the default DNS provider, which I believe is Cloudflare. Would you recommend switching to DNS0? I often game and do streaming, so I am concerned about any potential negative impact on performance.
@KenHarrisio
@KenHarrisio 5 дней назад
@@J-Ernie Hey John, I just recognized your channel. I'm glad to see you're still around! In your case, it'll be a toss up. Cloudflare's speed is going to be hard to beat. I imagine even a 10ms difference in competitive PVP could be a big difference. You could try a before/after test on speedtest[dot]net and see what it would look like for your area. If the latency would be an issue to change DNS from the OS/router level, you could just switch providers through browser settings and still get some of the benefits.
@J-Ernie
@J-Ernie 5 дней назад
@KenHarrisio Thank you, it's no walk in the park but I'm going to keep going at it.
@KenHarrisio
@KenHarrisio 4 дня назад
Hell yeah brother, you never know when the big break can happen. It's a great time to grow as a creator.
@Rockingorc
@Rockingorc 8 дней назад
just set up a pihole and use this~ can use multiple DNS-Services on it.
@evilleader1991
@evilleader1991 7 дней назад
I use pihole with dnscrypt and anonymized dns
@craigbell001
@craigbell001 9 дней назад
Thanks Ken very helpful. If you’re open to requests it would be awesome if you show how to deploy STIG or CIS Benchmarks. (Automate?) 😊
@KenHarrisio
@KenHarrisio 6 дней назад
This is a great idea, thanks for suggesting it!
@ronaldhofman1726
@ronaldhofman1726 8 дней назад
Set this up in my UBNT UDM PRo with add blocking allso now.
@TheOriginalJoeBloggs
@TheOriginalJoeBloggs 7 дней назад
Interesting
@Mbro-dq2do
@Mbro-dq2do 8 дней назад
great video Ken. Thanks for all the info. Is my Pi hole considered a DNS firewall? I have all my devices DNS changed to an extra Pi4 that all my internet goes thru then to my devices. Even my linux machines
@KenHarrisio
@KenHarrisio 6 дней назад
Yeah, the pi hole is an excellent choice for this. Thanks for supporting the channel!
@mrhassell
@mrhassell 7 дней назад
Lol, hardening and windows, don't belong in the same sentence.
@googleaccountuser3116
@googleaccountuser3116 9 дней назад
You talk about tagging but everyone is allowed to know i'm using virtio drivers. My hardware? Windows never gets too see that part unless i pass through my gpu. Windows is for playing games, use it like that and you'll worry less about malware and security. After all, who cares my windows vm has malware.😉
@robyee3325
@robyee3325 8 дней назад
what about self-hosting your own dns resolver with unbound dns or something?
@KenHarrisio
@KenHarrisio 6 дней назад
Yeah, making your own resolver is a great option. A pi hole is another option as well to do this and is something a lot of people will use.
@plebius
@plebius 9 дней назад
Mullvad DNS is separate and free to use by anyone. You dont have to be a customer.
@savage_tribal_chief
@savage_tribal_chief 9 дней назад
I did tried dns0 zero and it was slow. Please do a review of TwinGate.
@KenHarrisio
@KenHarrisio 9 дней назад
Yeah, some of the dns providers can cause speed issues. I've been using Quad9 for several years and haven't noticed any issues, but your milage may vary depending on where you're located. Thanks for letting me know about TwinGate. I hadn't heard of them before.
@PtolemyPetrie
@PtolemyPetrie 9 дней назад
Yes, good coverage, I think the industry term to put out there (at least until they change it) is called; DNSSEC. It runs on the same port, 53, but is encrypted. I want to say Google's and cloud flare both use DNSSEC by default. The problem can arise from greedy, data hungry ISP because essentially, they are DHCP'ing your publicly visible WAN IP address. So even though you have established DNSSEC at your Router, your ISP is up stream from you in the hierarchy and they have ways of, similar to the way you can inadvertently be split tunneling your VPN which is a security concern because of identity leakage, you have to go back and verify your configuration because your ISP will go back through and split tunnel your DNS so they can keep their sweet sweet revenue stream which is your data, they literally do not care about your security. And so we have a fundamental incentive disalignment.
@jfbeam
@jfbeam 8 дней назад
DNSSEC does not _encrypt_ anything; it adds a digital signature to verify ("authenticate") the data. Your ISP can still snoop on your DNS queries, but can't necessarily intercept/redirect your queries. DNS over TLS (HTTPS) is what you're thinking of.
@virtualheadless4764
@virtualheadless4764 9 дней назад
dude simplewall is malware or not its on virustotal scan its shows 7 flags.Your suggest simlewall in your last watched video.whats yout thought
@lussor1
@lussor1 9 дней назад
Its on github
@brokenneedle-l9l
@brokenneedle-l9l 9 дней назад
false positives
@naapsuvaimne740
@naapsuvaimne740 9 дней назад
its ok
@naapsuvaimne740
@naapsuvaimne740 9 дней назад
im using quad9 at router lvl
@Hawk_112
@Hawk_112 9 дней назад
great choice also they did not comply with censorship of sony which is a great thing to see
@KenHarrisio
@KenHarrisio 6 дней назад
For anyone wondering what Hawk_112 is talking about, here's an article: www.quad9.net/news/blog/sony-s-legal-attack-on-quad9-censorship-and-freedom-of-speech/ I've used Quad9 for about 4 years and they've been solid as a rock.
@TrustJesusToday
@TrustJesusToday 7 дней назад
One word solution: Linux.
@nubfaceforthelose
@nubfaceforthelose 3 дня назад
How are the latest games running? Just kidding. I love linux.
@AdamDavid
@AdamDavid 7 дней назад
What are you talking about, LOL? you really do not have any idea how surveillance works. DNS Provider? Budd DNS is a distributed "system". There are no "providers", you can run your own Recursive DNS server within your network, and you don't need to use a "Public" Recursive DNS server. Just get Pi-Hole if you want to do it the lazy way, it's free. Also, The government isn't going to use DNS to catch you. and your ISP can still track the websites you connect to, especially since they are routing you internet traffic. 😂 Also, a VPN has nothing to do with protecting your privacy or identity from the government, and especially the website you are connecting to, especially when you need to log in. The ONLY valid reason to use a VPN is to stop MITM or to allow you to access another LANs internal resources. No other reason. If the "Government" wants to see what you're doing, they can still track what is going into and out of that tunnel endpoint.
Далее
Windows Hardening Guide | 2024 Edition
50:00
Просмотров 10 тыс.
What is DNS? (and how it makes the Internet work)
24:22
MINECRAFT CREPPER EXPLODES SHARK PUPPET!
00:15
Просмотров 7 млн
Real respect sig
00:48
Просмотров 1,5 млн
Why get anything else? - Ubiquiti Cloud Gateway Max
11:45
DON'T Underestimate This Cheap MicroServer
18:07
Просмотров 184 тыс.
is apple intelligence safe?
10:39
Просмотров 94 тыс.
Kaspersky Is Cooked
24:13
Просмотров 5 тыс.
MINECRAFT CREPPER EXPLODES SHARK PUPPET!
00:15
Просмотров 7 млн