PDA

View Full Version : Modification of Phant0m's Rule-set for dial-up


Blackcat
December 11th, 2004, 08:49 AM
I am trying out Phantom's final rule set for dial-up on WIN 2000 SP4.

I managed to find my Primary and Secondary DNS Servers, loaded the new rule-set, but apparently some four of the rules need modifying before activating! How do I do this?

Blackcat
December 11th, 2004, 08:50 AM
Another Window which may be relevant here.

phaedrus
December 12th, 2004, 10:07 AM
I think there`s just the one for dial up. The other one`s are for adsl

Cheers,

Trev.
____________________
Useful Links:
Anti-virus:
NOD32 Anti-virus (http://www.nod32uk.com/home/home.htm) ... Avast Anti-virus (Free) (http://www.avast.com/eng/down_home.html) ... AVG Anti-virus (Free) (http://free.grisoft.com/freeweb.php/doc/1/) ... Housecall (Online Scan) (http://housecall.trendmicro.com/housecall/start_corp.asp)
Firewall:
LooknStop Firewall (http://www.looknstop.com/En/index2.htm) ... Sygate Personal Firewall (Free) (http://smb.sygate.com/products/spf_standard.htm)
Anti-trojan:
TDS-3 (http://tds.diamondcs.com.au/) ... Trojan Hunter (http://www.trojanhunter.com/) ... A² (Personal & Free) (http://www.emsisoft.com/en/) ... BOClean (http://www.nsclean.com/boclean.html)
Anti-Spyware:
AdAware SE (http://www.lavasoftusa.com/support/download/) ... Spybot S&D 1.3 (http://www.safer-networking.org/en/download/index.html) ... HijackThis! (http://tomcoyote.com/hjt/) ... SpywareBlaster (http://www.javacoolsoftware.com/spywareblaster.html) ... DialerWatcher (Dial up guard) (http://www.antidialer.co.uk/)
Misc:
System Safety Monitor (App Firewall) (http://maxcomputing.narod.ru/ssme.html?lang=en) ... Proxomitron (web filter) (http://www.proxomitron.info/) ... Firefox Browser (http://www.mozilla.org/products/firefox/) ... SysMetrix (desktop clock/meters) (http://www.xymantix.com/sysmetrix/) ... Rainlender (desktop calender) (http://www.ipi.fi/~rainy/index.php?pn=projects&project=rainlendar)

Blackcat
December 12th, 2004, 10:22 AM
But how do I modify and activate the one in Question?

Kush
December 12th, 2004, 10:28 AM
Hello BlackCat,


Please try this link http://www.fluxgfx.com/forum/viewtopic.php?t=45
or if you need more info please check this link http://www.fluxgfx.com/forum/viewtopic.php?t=47, it will give you a good idea of what you need to enter.

I am on cable and just use DNS,but BOOTP / DHCP I found I could do with out it.


I found making 3 DnS rules works better,on my computer anyway,I just went to run typed in WINIPCFG and then browse for the two other dns severs
this way work's great,but if I just put them in one rule,I get UPD blocked on my some DnS severs.But by making 3 rules for DnS I have no more problems

Good Luck

Blackcat
December 12th, 2004, 10:51 AM
Yes I have followed the instructions over at Software Security Central, but I still cannot get the DNS-Allowed-1 Rule to activate.

Back to Enhanced Rules set!

Kush
December 12th, 2004, 11:16 AM
Please try this by looking at your second post
where you have 213.253.16.72
198. 8. 69 .7


If 213.253.16.72 is your first DnS sever try this as DnS:1 below


213.253.16.72 rule 1 DnS sever 1
0. 0. 0. 0.

these two are just examples

For dns rule 2 EXAMPLE

213.343.5.34 sever 2
0. 0. 0. 0

For DnS rule 3

24.16.245.65 sever 3
0. 0. 0. 0.

I also had problems and the only thing that made it work was creating 3 DnS rules,so please try this the sever address and under the sever address
just add 0.0.0.0 ,until you have 3 DnS rules.

Blackcat
December 12th, 2004, 11:53 AM
Hi Kush,

Thanks for your patience.

1. If I type in WINIPCFG, I receive a 'cannot find file message'.

I can only find my DNS Servers by using IPCONFIG /ALL in the run field and these are the ones I listed in the second post above. i.e. I can only find two of them at present!

2. I tried using 0.0.0.0. in the second IP address, but I could not connect out.

3. Further how do I activate the rule that needs modifying. I clicked on applications and added one of my connections listed but again my Internet connection died.

Any more ideas ?

Kush
December 12th, 2004, 12:44 PM
Hi Blackcat,



Don't give up yet! It took me a week to figure why I had problems connecting using
Phantom's final rule-Set V6.

Ok so your first DnS sever is 213.252.16.72,and the second is 195.8.69.7

So the first DnS rule one would be:

213.252.16.72
0. 0. 0. 0.

And the second should be

195.8.69.7
0. 0. 0. 0.

Not sure why you can't browse the other severs?But look at you LnS Log and you should see
an IP address that say's UPD blocked! If you add that one to your DnS allow rule it should now work.You seem to have a sever blocking your connection,and by looking at your log file
you should find it in a second.And add a 3rd DnS rule the IP address,and the 0.0.0.0 underneath
as the others DnS allowed rules

To enable a rule just put a green check as in your first post,and that's about it,but your problem lie's in your log file,there must be a sever that has a UPD block on it,not to say that you put it there,but it will tell you what IP needs to be added to your DnS rules allowed.

To test your problem just try and load explorer,then check your log file,you should see upd blocked in the log,also try your email and check the log,if you are not able to connect you don't have them all added to the DnS allowed rules,check the log and add them.

And if your ip every changes,you might have to enter a new DnS rule's.but it is easy once you check your log file you can fix all of your connections problems.

I have had LnS for about 8-9 months always using Phantom's ruleset,like I said it takes a bit of playing around,but LnS rule creation makes thing's a breeze.And always check your log file,it will tell you what is blocking you from the Internet,good luck and if it still won't work,I can send you my ruleset by email so you will have a better idea on just things should
look,if all else fails.lol

kamui
December 12th, 2004, 01:05 PM
-{ Quote: "for dial-up on WIN XP SP4.
" }-

It doesn't exist lol !

you must change your ISP dns in your dial up connection to activate dns rules, like that
http://kamui.kenshiro.free.fr/lns/
;)

Blackcat
December 12th, 2004, 02:29 PM
-{ Quote: "It doesn't exist lol" }-
Brain spasm. Now corrected. :D
-{ Quote: "you must change your ISP dns in your dial up connection to activate dns rules, like that
http://kamui.kenshiro.free.fr/lns/
;)" }-
Thanks. I will try to follow this with an on-line translator.

MeanBud
December 12th, 2004, 11:38 PM
Thanks. I will try to follow this with an on-line translator." }-


Funny but true,I like how they alway's expect an english person to understand French without any problems very helpful!...thanks kamui