Wikiposts
Search
Computer/Internet Issues & Troubleshooting Anyone with questions about the terribly complex world of computers or the internet should try here. NOT FOR REPORTING ISSUES WITH PPRuNe FORUMS! Please use the subforum "PPRuNe Problems or Queries."

Redirects via "jupk.com"

Thread Tools
 
Search this Thread
 
Old 1st Dec 2006, 22:15
  #1 (permalink)  
Sellby_date Expired
Thread Starter
 
Join Date: Jan 2003
Location: East Anglia
Age: 83
Posts: 169
Likes: 0
Received 0 Likes on 0 Posts
Redirects via "jupk.com"

For info only now.
I have just recovered from a couple of days where by calls to such innocent places as GoogleUK finished up at some porn site or other unwanted locales.
It turned out that this 'Bug' had altered the DNS setting in Network Connections
The cure was quite simple.
'Settings/Control panel/Network Connections/'Right click' Internet conection/ Properties/Networking/ Double click TCP/IP and ensure that "Obtain DNS Server Address Automatically" IS SELECTED
Hope his make sense to anyone who may need it.
terryJones is offline  
Old 1st Dec 2006, 22:53
  #2 (permalink)  
Spoon PPRuNerist & Mad Inistrator
 
Join Date: Sep 2003
Location: Twickenham, home of rugby
Posts: 7,390
Received 245 Likes on 163 Posts
TJ,

I assume that the DNS server address(es) had been altered to a specific IP address - I don't suppose you recorded it, by any chance?

This is what a ping reveals:

dns.jupk.com [209.85.51.47]

SD
Saab Dastard is offline  
Old 1st Dec 2006, 23:44
  #3 (permalink)  
Sellby_date Expired
Thread Starter
 
Join Date: Jan 2003
Location: East Anglia
Age: 83
Posts: 169
Likes: 0
Received 0 Likes on 0 Posts
Saab.
The exact numbers I cannot recall, but "who is" shows it as part of the RIPE Network in Amsterdam.
They were in the order of 85.xx.xx.xx
Terry.
terryJones is offline  
Old 2nd Dec 2006, 10:09
  #4 (permalink)  
 
Join Date: May 2002
Location: Green and pleasant land
Posts: 658
Likes: 0
Received 0 Likes on 0 Posts
Thank God for Pprune!

I've been getting this problem / am in the middle of trying to sort it out. Assuming it's the same thing - a pale blue screen with 'find something interesting' in the top left corner and a bunch of links, many adult, in nature. And a pic of of a pretty, clothed female.

The IP addresses in the TCP/IP boxes are 85 255 114 20 and 85 255 112 175. Is there a specific way to block these addresses then?
cargosales is offline  
Old 2nd Dec 2006, 11:56
  #5 (permalink)  
Per Ardua ad Astraeus
 
Join Date: Mar 2000
Location: UK
Posts: 18,579
Likes: 0
Received 0 Likes on 0 Posts
Both addresses resolve to

inetnum: 85.255.112.0 - 85.255.127.255
netname: inhoster
descr: Inhoster hosting company
descr: OOO Inhoster, Poltavskij Shliax 24, Kharkiv, 61000, Ukraine
remarks: -----------------------------------
remarks: Abuse notifications to:
remarks: Network problems to:
remarks: Peering requests to:
remarks: -----------------------------------
country: UA
org: ORG-EST1-RIPE
admin-c: AK4026-RIPE
tech-c: AK4026-RIPE
tech-c: FWHS1-RIPE
status: ASSIGNED PI
mnt-by: RIPE-NCC-HM-PI-MNT
mnt-lower: RIPE-NCC-HM-PI-MNT
mnt-by: RECIT-MNT
mnt-routes: RECIT-MNT
mnt-domains: RECIT-MNT
mnt-by: DAV-MNT
mnt-routes: DAV-MNT
mnt-domains: DAV-MNT
source: RIPE # Filtered

organisation: ORG-EST1-RIPE
org-name: INHOSTER
org-type: NON-REGISTRY
remarks: *************************************
remarks: * Abuse contacts: *
remarks: *************************************
address: OOO Inhoster
address: Poltavskij Shliax 24, Xarkov,
address: 61000, Ukraine
phone: +38 066 4633621
e-mail:
admin-c: AK4026-RIPE
tech-c: AK4026-RIPE
mnt-ref: DAV-MNT
mnt-by: DAV-MNT
source: RIPE # Filtered

person: Andrei Kislizin
address: OOO Inhoster,
address: ul.Antonova 5, Kiev,
address: 03186, Ukraine
phone: +38 044 2404332
nic-hdl: AK4026-RIPE
source: RIPE # Filtered

person: Fast Web Hosting Support
address: 01110, Ukraine, Kiev, 20 , Solomenskaya street. room 201.
address: UA
phone: +35 79 91 17 759
e-mail:
nic-hdl: FWHS1-RIPE
source: RIPE # Filtered
BOAC is offline  
Old 2nd Dec 2006, 15:17
  #6 (permalink)  
Spoon PPRuNerist & Mad Inistrator
 
Join Date: Sep 2003
Location: Twickenham, home of rugby
Posts: 7,390
Received 245 Likes on 163 Posts
Chocolate teapot territory!

Here's an interesting piece from Spyware Confidential.

SD
Saab Dastard is offline  
Old 2nd Dec 2006, 15:41
  #7 (permalink)  
Spoon PPRuNerist & Mad Inistrator
 
Join Date: Sep 2003
Location: Twickenham, home of rugby
Posts: 7,390
Received 245 Likes on 163 Posts
Is there a specific way to block these addresses then?
In Win XP, there is no obvious and easy way. Windows built-in firewall doesn't allow this sort of IP address filtering - nor does OneCare (say that over and over, you end up saying wa*ker!).

I digress.

Some other software firewalls may allow you to block a source / destination address or address range. I don't know.

Hardware firewalls may allow you to do it - my Netgear firewall doesn't allow IP address ranges (just domain names) to be blocked, but I simply set up a static route, so that the route to 85.255.112.0/20 (the /20 means a 20-bit subnet mask, i.e. 255.255.240.0) is directed by the firewall BACK to my own computer. Similarly for 69.50.160.0/19.

Crude, but effective!

SD
Saab Dastard is offline  
Old 2nd Dec 2006, 17:02
  #8 (permalink)  

Plastic PPRuNer
 
Join Date: Sep 2000
Location: Cape Town
Posts: 1,898
Received 0 Likes on 0 Posts
"In Win XP, there is no obvious and easy way."

Actually there is - That's what your HOSTS file is there for (not strictly speaking, but you can use it for that).

Rather than me explaining, pop over to http://accs-net.com/hosts/ and read all about it. It ain't difficult and doesn't cost anything.

Use your HOSTS file (which is built into Windows [and Linux]) in combination with eDexter and/or DNSKong and Hostsman from abelhadigital - http://pwp.netcabo.pt/0413933601/abe.../hostsman.html - and you're all set.

And it's all free
Mac the Knife is offline  
Old 2nd Dec 2006, 19:55
  #9 (permalink)  
Spoon PPRuNerist & Mad Inistrator
 
Join Date: Sep 2003
Location: Twickenham, home of rugby
Posts: 7,390
Received 245 Likes on 163 Posts
Mac,

You are answering the wrong question - the question was "How can I block access to this range of IP addresses", not how can I manage name resolution.

The HOSTS file manages translation of host names into IP addresses, NOTHING ELSE!

It cannot be used to block access to IP addresses BECAUSE IF YOU KNOW THE IP ADDRESS IT IS NOT EVEN CONSULTED!!

With a proper firewall it is simple to write rules to block traffic to / from specific addresses or whole blocks of addresses as in this case; however, Windows isn't a firewall (understatement of the century), and most of the home WAP/Switch/Firewalls don't allow this level of customisation. I'm sure that there are some that allow this - I'm also sure that some of the software firewalls that run on Windows can do this.

I believe that you could write static routes into Windows networking via the command line, and it would be simple to put this into a script that runs whenever you boot, but with more than one device on the network, it makes more sense (and is easier) to put it on the firewall.

SD
Saab Dastard is offline  
Old 3rd Dec 2006, 05:10
  #10 (permalink)  

Plastic PPRuNer
 
Join Date: Sep 2000
Location: Cape Town
Posts: 1,898
Received 0 Likes on 0 Posts
Oooops! You're right.

What'll teach me to engage brain before speaking

As you say, the firewall is the place to block access to specific or ranges of IP addresses.
Mac the Knife is offline  
Old 4th Dec 2006, 08:59
  #11 (permalink)  
Wunderbra
 
Join Date: Aug 2006
Location: Bedford, UK
Age: 44
Posts: 313
Likes: 0
Received 0 Likes on 0 Posts
I use zone alarm which allows blocking of specific IP addresses and/or ranges of addresses.
matt_hooks is offline  
Old 4th Dec 2006, 10:08
  #12 (permalink)  
Per Ardua ad Astraeus
 
Join Date: Mar 2000
Location: UK
Posts: 18,579
Likes: 0
Received 0 Likes on 0 Posts
Which version of ZA is that please?
BOAC is offline  
Old 4th Dec 2006, 20:27
  #13 (permalink)  
Wunderbra
 
Join Date: Aug 2006
Location: Bedford, UK
Age: 44
Posts: 313
Likes: 0
Received 0 Likes on 0 Posts
It's the free version from www.zonelabs.com

info gives

ZoneAlarm version:6.5.737.000
TrueVector version:6.5.737.000
Driver version:6.5.737.000
matt_hooks is offline  

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are Off
Pingbacks are Off
Refbacks are Off



Contact Us - Archive - Advertising - Cookie Policy - Privacy Statement - Terms of Service

Copyright © 2024 MH Sub I, LLC dba Internet Brands. All rights reserved. Use of this site indicates your consent to the Terms of Use.