Subscribe to Windows IT Pro

 

Get Newsletters

  • Get the Latest News
  • Product Updates
  • Helpful Tricks
  • Productivity Tips

Subscribe Now!

June 28, 2007 12:00 AM

Use a Server HOSTS File to Block Malware

Windows IT Pro
InstantDoc ID #95946
Rating: (0)

I had been considering the installation of a black hole DNS solution to supplement all the other layers of security on our computer system. With this type of solution, you configure a separate DNS server to answer queries from domains associated with malware, spyware, and other malicious or annoying programs, such as ads, banners, and page counters. However, I wasn't keen about having to install another DNS server. Nor was I thrilled with the prospect of having to create and maintain all the necessary records, which is time-consuming. So, I decided to check into some alternatives.

For a long time, I've known about the HOSTS files that are available on the Internet for home users. Like black hole DNS solutions, HOSTS files can be used to block malicious and annoying programs. I decided to give them a try. After looking at several Web sites, I decided to use the HOSTS file from MVPS.org. The criteria this HOSTS file uses to detect malicious and annoying programs are very thorough. And the HOSTS file is updated periodically.

You typically use HOSTS files on individual PCs, but I wanted to see whether I could get them to work on some of the servers in my small home network. I first tried MVPS.org's HOSTS file with my DNS server. Not surprisingly, it didn't work. I then applied the HOSTS file to Microsoft ISA Server 2004. After a reboot, it worked! The malicious and annoying programs were blocked, and the client response times actually sped up. Although the HOSTS file appears to have no effect on firewall traffic, it works great on proxy traffic. It also works well on ISA Server 2006. I suspect it would work equally well on other proxies and gateways.

Since the evaluation went well on my home network, I implemented the HOSTS file at work. We experienced the same results, as indicated by our client security software, which reported fewer incidents. In addition, I implemented the freeware HostsMan to automate the HOSTS file updates. Since the implementation six months ago, no problems have occurred.

With MVPS.org's HOSTS file, I'm able to protect my entire enterprise with another layer of security that's easily updated and maintained. Kudos to the MVPS.org folks for offering this freeware.

—Rob John
Network Operations Manager
Hyundai Motor Manufacturing Alabama

Editor's note: This Reader to Reader item was a winning entry in the Know Your IT Security contest sponsored by Microsoft Learning Paths for Security.

Share Your Security Experiences
Share your security discoveries, comments, solutions to problems, and experiences with products. Email your contributions to r2r@windowsitsecurity.com. Please include your full name and phone number. We edit submissions for style, grammar, and length. If we print your submission, you’ll get $100.

Related Content:

ARTICLE TOOLS

Comments
    There are no comments to display. Be the first one!
You must log on before posting a comment.

Are you a new visitor? Register Here

advertisement

advertisement

White Papers

Get your Windows 7 deployment off to the right start by implementing PC lockdown. A locked-down environment is easier and cheaper to support since users are less likely to make unnecessary changes to the core system configuration - read more here!

Essential Guides

Is your iSCSI "lossy"? The reality is that most off-the-shelf Ethernet hardware deployed for iSCSI can lose packets, resulting in slow performance or application downtime. Learn how to assess your current iSCSI infrastructure and engineer an advanced iSCSI SAN infrastructure.

Web Seminars

What's the best way to keep your network safe from malware? In this web seminar, security expert Greg Shields suggests an alternative method to the traditional blacklisting approach that is common with anti-virus and anti-malware solutions.

eLearning Series

We bring the experts direct to you to share their real-world perspective and expertise. During each event, three sessions stream in real time, so you can learn, ask questions, and get solutions.
Upcoming event: Getting the Most with Exchange 2010 with Paul Robichaux

Subscribe to Windows IT Pro!

Windows is a trademark of the Microsoft group of companies. Windows IT Pro is used by Penton Media Inc. under license from owner.