Recommended Posts

You can?t block Facebook using Windows 8?s hosts file

The Windows hosts file offers a great way of blocking or redirecting certain Internet hosts. I?m for instance using it whenever I move websites to a new hosting company to check the life site before the DNS has fully propagated. You can also download software like Hosts Man that allow you to add lists of known malicious sites or advertising servers to the file to block those automatically from being visited on the computer.

In theory, you can add any domain, host or website to the hosts file so that it is blocked on the system. Ghacks reader SGR just informed me that this apparently has changed in the Windows 8 RTM version.

windows-8-hosts-file.png

While you can still add any host you want to the hosts file and map it to an IP, you will notice that some of the mappings will get reset once you open an Internet browser. If you only save, close and re-open the hosts file you will still see the new mappings in the the file, but once you open a web browser, some of them are removed automatically from the hosts file.

Two of the sites that you can?t block using the hosts file are facebook.com and ad.doubleclick.net, the former the most popular social networking site, the second a popular ad serving domain.

The strange thing is that even write protecting the file does not have an effect on it as entries are still removed once you open a web browser. Actually, any kind of Internet connection seems to be enough for that behavior. If you open the Windows Store for instance, the entries get removed as well automatically.

This could be a bug that is affecting only some high profile sites and services, or something that has been added to Windows 8 deliberately. We have contacted Microsoft and are currently waiting for a response from a company representative. Since it is Sunday, it is not likely that this is going to happen today.

It is also in the realm of possibility that the hosts file may not accept other hosts.

Update: Tom just pointed out that turning off Windows Defender, which basically is Microsoft Security Essentials, in Windows 8 will resolve the issue. It appears that the program has been designed to protect some hosts from being added to the Windows hosts file. To turn off Windows Defender press the Windows key, type Windows Defender and hit enter. This launches the program. Switch to Settings here and select Administrator on the left. Locate Turn on Windows Defender and uncheck the preference and click save changes afterwards.

Please note that this turns off Windows Defender, and that it is recommended to have another antivirus program installed on the system to have it protected against Internet and local threats.

Source: ghacks.net

Link to comment
https://www.neowin.net/forum/topic/1099791-you-can/
Share on other sites

in MSE (and i imagine windows defender) you can exclude files. just excludes the hosts file and it should not change it back

^this.

If you modifiy the host file manually, it will trigger a warning (since it's a good way to do man in the middle attacks for example) but you can tell MSE/Windows defender to allow the change, then it won't revert it back.

Link to comment
https://www.neowin.net/forum/topic/1099791-you-can/#findComment-595106487
Share on other sites

A lot of anti-malware suites will prevent changes to the hosts file.. common way to hijack sites and such. Exclude or use a different suite.

Yep... can understand their reasons for doing it. Bit annoying though if you do alter your hosts file when doing testing and so forth.

Link to comment
https://www.neowin.net/forum/topic/1099791-you-can/#findComment-595106497
Share on other sites

A lot of anti-malware suites will prevent changes to the hosts file.. common way to hijack sites and such. Exclude or use a different suite.

It's the fact that it only blocks some sites, that seems very fishy. If you are going to protect the hosts file in this manner, why not protect it entirely?

Link to comment
https://www.neowin.net/forum/topic/1099791-you-can/#findComment-595106829
Share on other sites

It's that fact that it only blocks some sites, that seems very fishy. If you are going to protect the hosts file in this manner, why not protect it entirely?

Look how big facebook.com is. If some trojan decided to link it to a different IP within the hosts file, thats why it only does some domain names. Malware authors dont care about picsofmygranny.com with its 5 users

Link to comment
https://www.neowin.net/forum/topic/1099791-you-can/#findComment-595106851
Share on other sites

or just install some parental lock software. Im assuming you want to block facebook so your kids cant go on cause they are too young and not cause you have no self control can't just not go there

Link to comment
https://www.neowin.net/forum/topic/1099791-you-can/#findComment-595106877
Share on other sites

It's that fact that it only blocks some sites, that seems very fishy. If you are going to protect the hosts file in this manner, why not protect it entirely?

this

i knew that anti-malware solutions block access to the host file or at least that access triggers a warning; the new thing here is that Windows Defender only blocks some sites, witch is odd.

Link to comment
https://www.neowin.net/forum/topic/1099791-you-can/#findComment-595106885
Share on other sites

I am a bit concerned about doubleclick. Is that the common ad platform for Windows 8?

It's one of the biggest ad networks on the internet. Someone being able to redirect all that traffic for their own purposes by modifying someone elses hosts files is quite the issue - considering how many websites have ads served by doubleclick.

By the way, doubleclick is run by Google - Microsoft tends to use their own advertising platform.

Link to comment
https://www.neowin.net/forum/topic/1099791-you-can/#findComment-595106903
Share on other sites

It's one of the biggest ad networks on the internet. Someone being able to redirect all that traffic for their own purposes by modifying someone elses hosts files is quite the issue - considering how many websites have ads served by doubleclick.

By the way, doubleclick is run by Google - Microsoft tends to use their own advertising platform.

Ah, that makes sense.

I would be curious to know if other high-profile sites are prevented from being redirected as well. I'd expect at least the Alexa top 50. Right now, we can justify each of those sites individually, but if it's ONLY those two sites, it's worth questioning.

Link to comment
https://www.neowin.net/forum/topic/1099791-you-can/#findComment-595106927
Share on other sites

It's the fact that it only blocks some sites, that seems very fishy. If you are going to protect the hosts file in this manner, why not protect it entirely?

I am glad it doesn't protect the whole file. I can still use it for my own work (which uses internal domains).

Link to comment
https://www.neowin.net/forum/topic/1099791-you-can/#findComment-595107031
Share on other sites

I can see a very legit use for only doing certain sites. Since DoubleClick is one of the biggest ad networks out there, redirecting it to a mailious IP address using the HOSTS file is a good way to get malware installed. Same with Facebook, and if something like that ever did happen to Mr Average J. User, he wouldn't even begin to know how to fix it.

Link to comment
https://www.neowin.net/forum/topic/1099791-you-can/#findComment-595109165
Share on other sites

Can't believe I'm defending Windows 8, but here goes: I did my own testing here with XP, Vista and 7. It has nothing to do with the OS you are using, and everything to do with MSE. End of story, try it for yourself. MSE will remove certain things from your HOSTS file even if it's Read Only.

Link to comment
https://www.neowin.net/forum/topic/1099791-you-can/#findComment-595109193
Share on other sites

Can't believe I'm defending Windows 8, but here goes: I did my own testing here with XP, Vista and 7. It has nothing to do with the OS you are using, and everything to do with MSE. End of story, try it for yourself. MSE will remove certain things from your HOSTS file even if it's Read Only.

while true, MSE is install by default on windows 8. By doing this i count MSE on windows 8 as part of the windows 8 OS. Im very interested in this, but am not going dog MS and Windows 8 till more is known.

Link to comment
https://www.neowin.net/forum/topic/1099791-you-can/#findComment-595109283
Share on other sites

This topic is now closed to further replies.
  • Posts

    • WTF? I am not taking a video of myself to access a site or to create an account. What are they thinking? I don’t even have a webcam on my main desktop PC. The powers to be are really looking to normalize the taking of pics or submitting ID for everything. I afraid most people will end up just going along with it.
    • Free eBook: A Comprehensive Guide to the NIST Cybersecurity Framework 2.0 (worth $126.95) by Steven Parker Claim your complimentary copy (worth $126.95) of "A Comprehensive Guide to the NIST Cybersecurity Framework 2.0" for free, before the offer ends on July 8. (link below) Description The National Institute of Standards and Technology (NIST) Cybersecurity Framework, produced in response to a 2014 US Presidential directive, has proven essential in standardizing approaches to cybersecurity risk and producing an efficient, adaptable toolkit for meeting cyber threats. As these threats have multiplied and escalated in recent years, this framework has evolved to meet new needs and reflect new best practices, and now has an international footprint. There has never been a greater need for cybersecurity professionals to understand this framework, its applications, and its potential. A Comprehensive Guide to the NIST Cybersecurity Framework 2.0 offers a vital introduction to this NIST framework and its implementation. Highlighting significant updates from the first version of the NIST framework, it works through each of the framework’s functions in turn, in language both beginners and experienced professionals can grasp. Replete with compliance and implementation strategies, it proves indispensable for the next generation of cybersecurity professionals. A Comprehensive Guide to the NIST Cybersecurity Framework 2.0 readers will also find: Clear, jargon-free language for both beginning and advanced readers Detailed discussion of all NIST framework components, including Govern, Identify, Protect, Detect, Respond, and Recover Hundreds of actionable recommendations for immediate implementation by cybersecurity professionals at all levels A Comprehensive Guide to the NIST Cybersecurity Framework 2.0 is ideal for cybersecurity professionals, business leaders and executives, IT consultants and advisors, and students and academics focused on the study of cybersecurity, information technology, or related fields. How to download for free Please ensure you read the terms and conditions to claim this offer. Complete and verifiable information is required in order to receive this free offer. If you have previously made use of these offers, you will not need to re-register. A Comprehensive Guide to the NIST Cybersecurity Framework 2.0 Was $126.95, but is now FREE | Above link offer expires on July 8. The below offers are also available for free in exchange for your (work) email: View our recent time-limited free eBook offers The Complete Free AI Learning: Master ChatGPT, Claude, Gemini & More ($21 Value) now FREE How to Build an AI Design Workflow with Gamma ($21 Value) now FREE The Ultimate Linux Newbie Guide – Featured free content Python Notes for Professionals – Featured free content Learn Linux in 5 Days – Featured free content Quick Reference Guide for Cybersecurity – Featured free content We post these because we earn commission on each lead so as not to rely solely on advertising, which many of our readers block. It all helps toward paying staff reporters, servers and hosting costs. Other ways to support Neowin The above deal not doing it for you, but still want to help? Check out the links below. Check out our partner software in the Neowin Store Buy a T-shirt at Neowin's Threadsquad Subscribe to Neowin - for $14 a year, or $28 a year for an ad-free experience Disclosure: An account at Neowin Deals is required to participate in any deals powered by our affiliate, StackCommerce. For a full description of StackCommerce's privacy guidelines, go here. Neowin benefits from shared revenue of each sale made through the branded deals site.
    • I'm not unblocking my camera for this crapola. Sorry, Google.
  • Recent Achievements

    • One Year In
      BA the Curmudgeon earned a badge
      One Year In
    • Conversation Starter
      rosiecharles earned a badge
      Conversation Starter
    • First Post
      KMilenkoski1202 earned a badge
      First Post
    • First Post
      carols23 earned a badge
      First Post
    • One Month Later
      Tom Willson earned a badge
      One Month Later
  • Popular Contributors

    1. 1
      +primortal
      518
    2. 2
      +Edouard
      264
    3. 3
      PsYcHoKiLLa
      151
    4. 4
      Steven P.
      95
    5. 5
      macoman
      66
  • Tell a friend

    Love Neowin? Tell a friend!