PDA

View Full Version : Have a secure DNS (Domain Name Server) and its EASIER than you thought!



REDZULU2003
06-28-10, 12:53 PM
I'll just get stuck in.

DNS = Domain Name Server


(1) Short for Domain Name System (or Service or Server), an Internet service that translates domain names into IP addresses. Because domain names are alphabetic, they're easier to remember. The Internet however, is really based on IP addresses. Every time you use a domain name, therefore, a DNS service must translate the name into the corresponding IP address. For example, the domain name www.example.com might translate to 198.105.232.4.

The DNS system is, in fact, its own network. If one DNS server doesn't know how to translate a particular domain name, it asks another one, and so on, until the correct IP address is returned.

(2) Short for digital nervous system, a term coined by Bill Gates to describe a network of personal computers that make it easier to obtain and understand information.

^ Copied & pasted from http://www.webopedia.com/TERM/D/DNS.html

Okay with it being explained what one is, how do you change the DNS address? Well you will go into network connections or network settings if your with Windows. I don't know the equivalent for Linux or the Mac, so if anyone can help with that please do.

See THIS THREAD (http://www.mediacollege.com/computer/network/dns.html) for details on how to change the DNS address. It will also show currently the DNS server you currently use, so write it down.

So before its changed, write it down and have it tested for security with the well trusted online GRC Nameserver spoofabilty test (https://www.grc.com/dns/dns.htm) It will inform you how secure the current DNS used is and if its safe from DNS attacks such as spoofing or cache poisoning.

Next you want to know the speeds of alternative DNS servers you can use. So download the following free software called DNS Bench. It has a built in list of public DNS servers incl many of the best ones. It will check to see which one is best suited for you, based on the current location your at (IP address dependant)

The free software is available here (http://hidemyass.com/files/JqM8z/). I uploaded it myself, so its safe.

Once you have a certain DNS server in mind, again write it down and close the application. You now need to enter these details into your settings and to do this we revert back to the beginning here. Simply visit the website (http://www.mediacollege.com/computer/network/dns.html)again for instructions on how to do that, if your still not sure.

Make sure you change the DNS server for ALL your devices in that section. If your connected via a router as well, than you will need to connect to that via a web browser and enter these numbers in the DNS section within it, otherwise you'll have troubles.

Once your done, repeat the GRC DNS test and the Speed test again and check for yourself how much better and safer it is. Many times the default ISP DNS settings are complete crap and this is how, the ISP's control what is being sent to the customer ... for example in China they control these DNS servers to limit the information and sites the locals can see as they are programmed to only send back whatever the Chinese feel should be seen and is also how Australia and New Zealand will implement its child porn block list into the ISP, which is actually a good thing .. thats how its done.

As you can see though, its not hard to get around but still if you are in a country such as China and managed to change the DNS server, you will still get censored internet as the ISP your with is most likely Chinese and hence already has the blocked content on its servers as this passes over to you.

Some things that will be noticed if you choose a good fast open DNS server? FASTER browsing on the net because you will be using better servers, faster safer securer servers. Less likely to have your data compromised from DNS poison attacks, where a false DNS is placed in and your redirected into it without knowing this . You also have better protection from viruses as well, more so from bad sites that load that crap up .. many good services block those on reliable DNS servers.

So thats it really. Get your connection faster and safer with a simple tweak. ALSO if you use a VPN service or anonymous proxy, your still not truely secure <:( This is because of your default DNS server still relaying your original ISP IP address web requests (Addresses typed in etc) through the DNS server and into the ISPs servers, so only being partly anonymous in your surfing but your SEARCHES and WEB ADDRESSES are all still viewable by the ISP.

Keep that in mind as many, if not all VPN providers don't reveal this to the customer.

I will not list the most popular, fastest and secure Open DNS servers for you. So check them out and aswell with the DNSBench software, can add additional servers as you go to check and compare with others.

GOOGLE DNS

8.8.8.8
8.8.4.4

MONZOON DNS

80.254.79.157
80.254.77.39

OpenDNS

208.67.222.222
208.67.220.220

Scrubit

67.138.54.100
207.225.209.66

DNS advantage (Comodo uses the exact same servers)

156.154.70.1
156.154.71.1

^ ALL of those with the exception of Google and Monzoon are primarily in the business of DNS and have a good reputation.

Monzoon is a Swiss company and has excellent anti spoofing along-with good privacy laws, with it being in Switzerland. I have used it for months in the past with no problems but it may be slower for those not based in Europe.

I've also used the OpenDNS servers which were also good and auto change to the nearest location based on where you surf on the net i.e. you visit a Japanese website, so it adjusts itself to the nearest server to Japan, such as for example lets say Taiwan and when you revert back, in this example we will choose Peru it will use a server closest to that nation and so fourth.

Currently I'm now using Google's DNS servers as they are the fastest. Google do have a reputation for collecting and sortieing data, so read the privacy policy http://code.google.com/speed/public-dns/privacy.html but if you used an encrypted VPN and highly secure elite proxy, they cant collect anything anyway.

Give these a try and let me know how you get on and if you need help than just ask.

REDZULU2003
08-13-10, 07:25 AM
UPDATED

I've been testing several of these and the best to now is certainly OpenDNS.

REDZULU2003
10-04-10, 06:59 AM
Has anyone found this helpful? please let me know because I can offer more guides and as-well questions if your stuck on something.

Dashdeming
10-04-10, 10:28 AM
Very good info Red. It may be over the heads of many users but it will be a great reference fro many later and I certainly get something from it now. Thanks Bro

REDZULU2003
02-18-11, 06:01 PM
Benchmark your DNS servers to find the best one with free software via GRC's tool here (http://www.grc.com/dns/benchmark.htm)and Google's tool here (http://code.google.com/p/namebench/).

REDZULU2003
02-26-11, 05:08 PM
Found some more public free DNS servers

Two Danish DNS servers ran by a Mr Thomas Steen Rasmussen. They completely uncensored the internet for you, nothing is filtered whatsoever with these. Thomas also promises that all query's through the servers are not logged.


Absolutely nothing is being logged, neither about the users nor the usage of this service. I do keep graphs of the total number of queries, but no personally identifiable information is saved. The data that is saved will never be sold or used for anything except capacity planning of the service.

89.233.43.71
89.104.194.142

He has a website http://www.censurfridns.dk/ and blog http://blog.censurfridns.dk/en

REDZULU2003
02-26-11, 05:11 PM
Norton

198.153.192.1
198.153.194.1

GTEI DNS (now Verizon)

4.2.2.1
4.2.2.2
4.2.2.3
4.2.2.4
4.2.2.5
4.2.2.6

REDZULU2003
02-26-11, 05:43 PM
Some more :)

Thailand

203.150.17.17
203.155.33.1

Seychelles

196.1.120.162

Luxembourg

158.169.9.30

Trinidad & Tobago

200.12.229.1

Ukraine

85.255.114.12
85.255.114.11
85.255.114.40

Servermatrix.com

216.185.111.10
69.56.222.10
67.19.0.10
67.19.1.10
70.84.160.11

Antigua

209.59.96.12

cyberbunker.com which is Dutch and interesting.

The server location was built for nuclear war.
Operating from a Cold War era government command bunker that was purpose-built by the Military to house sensitive electronic gear, CyberBunker combines the best of modern commercial technology with Military-grade reliability and Military construction to provide the most secure and reliable solution for people and equipment. The facility was built in 1955 to survive through a full-scale nuclear war.

Have a peak arond the site for some pictures, very cool.

84.22.106.30

Its also registered not in in Holland but Antarctica :) So on the forms Antarctica is listed.

American Samoa

202.70.116.11

Austria

212.33.55.5
213.162.64.1
213.162.64.2
213.33.99.70

If you need specific location than let me know and I'll find you one.

REDZULU2003
02-26-11, 06:19 PM
Public DNS servers from countries with good privacy & security laws.

Panama

200.90.132.200
200.46.243.29

Costa Rica

163.178.48.66
163.178.88.2

Faroe Islands

81.18.224.2

Gibraltar

195.166.192.1
195.166.192.8

Iceland

62.145.128.1

Mauritius

196.192.4.4

Monaco

195.78.6.210
195.78.6.36

Western Samoa

202.4.60.1

Suriname

200.1.156.11
200.1.157.10
200.1.157.11

Venezuela

159.90.200.8

Antigua

209.59.65.202

REDZULU2003
02-27-11, 06:04 PM
The last two posts in this thread are not like organisations such as OpenDNS or DNS advantage etc that specialize in DNS content filtering and making sure shit on the web doesn't get into your path as you surf. They are from the nations mentioned and more for privacy and uncensored than anything else. Seychelles and Panama for example have VERY strict data security laws and privacy is taken very seriously unlike most places now, which is why the Seychelles and Panama have allot of offshore banks, insurance companies and various companies have the office registered there to make-sure its protected by the nations laws, as they are good.

Sadly using one of those DNS unless your close to them is going to give really really shit slow internet access and so you may use it in exceptional cases and than switch it back. Best to use as well various security measures such as good proxy and encrypted vpn provider to anonymous your internet surfing with state of the art encryption and no the government, your ISP cannot even crack it if its secure enough and you route it around enough times through various other places it cannot be tracked :)

Like offshore dodgy bank accounts setup in false names, they may be in for example Cyprus but that account leads to Croatia which leads to the Cayman Islands which leads to the Seychelles which leads to Panama which leads to Switzerland which finally reaches the real persons account in Russia :) Law enforcement would find it VERY difficult to crack a bastard like that, especially with false names, different people being used and regular chaining the cash around various points .... its a work of art, beautiful magnifique.

So use them wisely as many are not really for longterm use for your DNS but the ones on the first page are. Also this next one is really good permanent alternative for your DNS.

http://clearclouddns.com/


ClearCloud is a free service that checks every website address your computer is trying to access, whether you're browsing the internet, clicking a link in an email, or a program "under the hood" trying to communicate with servers for information or updates.

ClearCloud prevents you from being able to access known bad websites, sites that will download malicious files to your computer. Even better, ClearCloud prevents you from being able to access malicious websites that you may not even know your computer is trying to access — and it prevents potentially nasty programs from "phoning home" and secretly communicating between your computer and cybercriminals.

Many programs legitimately phone home to get software updates. Microsoft Windows and Adobe Reader are two common programs that will check for current updates. ClearCloud knows the websites accessed by over a million safe programs and provides free passage to these sites.

How does ClearCloud know which websites are malicious?

ClearCloud is part of the DNS network, and has access to every URL in the world. When you type in the URL in your browser and click "Go" or "Enter" your browser sends the URL to ClearCloud. ClearCloud looks it up in a table, checks it against the list of bad websites, and if it passes, sends back the numeric IP address so your browser knows where to go to get the web page. All in milliseconds.

If ClearCloud discovers that it's a bad URL, it sends back the IP address of our webpage that informs you about the malicious site.

Get the security you need for safe and reliable internet surfing. Start using ClearCloud today.

The server addresses you need are as follows 74.118.212.1 & 74.118.212.2

So enjoy and PLEASE DO comment and if you need help ASK!!! I have also gone through this thread and color coded the DNS servers that are good for a permanent solution in BLUE and the ones for other use in RED.

REDZULU2003
02-27-11, 06:19 PM
Let me also just point out that once you have added a DNS please MAKE SURE you visit https://www.grc.com/dns/dns.htm and run the spoofability test. Check the results and if it fails or its not passed as excellent than ditch that DNS, its as simple as that. It may come as a shock to many but Google's DNS servers listed on the first page to this thread, when I last tested them approx 10 months ago because I was going to use them, they failed miserably in the test and so they are not secure enough to use.

Also when you are thinking of checking many DNS name servers or want to see if the one you like is fast enough than check with the benchmark software which is free from GRC here (http://www.grc.com/dns/benchmark.htm)or Googles here (http://code.google.com/p/namebench/).

I cant believe that so many of us put up with the default ISP DNS we have already configured. Did you also know that even if you use a elite proxy (Top one) or an encrypted VPN that if the DNS is still that of your ISP that the chances are high they will see the URL requests made because it will be going through their servers via the DNS to your secure line. They can be eliminated full stop by using another DNS along with elite proxy and encrypted VPN.

REDZULU2003
04-06-11, 03:05 PM
Just found out about this free software called TreeWalk DNS that installs on your system and acts as your own DNS server and so you dont have to rely on the ISP DNS provided by default. Sounds interesting but I cant comment on its effectiveness having not tried it but has good reviews.


You need TreeWalk DNS if:

Your ISP's DNS servers are slow or offline
Accurately resolving web sites is a problem
You wish to capture or debug DNS routing data
You want to custom configure DNS settings and servers
You'd simply like faster repeat visits to sites via cached lookups
You have poor DNS with your wireless or satellite Internet connection
You use Internet Connection Sharing and want to improve surfing speeds

Features:

Runs as a Win32 service
Realtime debugging ability
Auto-installs on small LAN's
Accepts BIND 9 configurations
DNS caching server by default
Updates DNS data automatically
Control Panel with debug options
Simple, automatic install and setup
Can protect against DNS cache poisoning
Easy uninstall procedure returns original settings
Reduce "not found", "404", and "DNS error" messages
Program installer fits on one floppy disk for portable setup
A workstation can be modified to work as a full DNS server
Custom Internet root server plugins available for 1,000 additional TLDs
Optional persistent caching is installed by default to keep DNS records between sessions

Requirements:

Minimum 32 MB RAM (128 MB preferred)
Must install using an Administrative logon
Dial-up, Cable, or ADSL Internet connection
Windows® XP, 2000, .NET and 2003 workstations or servers (Vista version pending) *

Here's the site http://ntcanuck.com/index.htm

REDZULU2003
08-29-11, 06:42 PM
ClearCloud DNS stops its free service from 1st October. I have now changed my DNS provider. They were good though http://clearclouddns.com/

REDZULU2003
09-06-11, 11:16 AM
Recently came across a site with free Public Access (Tier-2) DNS Servers that are based around the globe and have anonymous features and logging disabled. Website is http://www.opennicproject.org/en/publictier2servers.

Indonesian public DNS iMz Public DNS (Indonesia) 119.2.43.172 and 119.2.43.173

REDZULU2003
10-16-11, 04:38 PM
Recently been given a list of several new open DNS servers for public use based around various locations in the world.

Europe/Middle East – 176.67.84.19 (UK)
North America – 173.234.163.178 (USA)
South America – 189.1.162.197 (BRAZIL)
Oceania – 180.92.192.234 (AUSTRALIA)
Asia – 180.210.201.168 (SINGAPORE)

The DNS servers used were setup using OpenDNS.

REDZULU2003
04-27-12, 05:32 PM
Excellent Swedish DNS TELECOMIX http://blog.greenpirate.org/telecomix-dns/ & http://dns.telecomix.org/

91.191.136.152
85.229.85.109

Dangler
04-27-12, 06:33 PM
What I like about OpenDNS, is I have a list of domains that i keep blocked so that they are not available to my home network:

bg
cn
gs
kr
nu
ro
ru
st
tk
vg

Also they block known "nasties", in the case some content/AD server tries to pass along some drive by trojan.
I've no complaints !

REDZULU2003
04-29-12, 09:30 AM
Thanks for sharing your experiences.