Phant0m`` Rule-set $v3.0 *NEW*

Discussion in 'LnS English Forum' started by Phant0m, Aug 13, 2003.

Thread Status:
Not open for further replies.
  1. Siddhartha

    Siddhartha Guest

    It was necessary for me to create 2 rules for 3 DNS servers (DNS-allowed-1)
    But you're right; if I desactivate both rules, I cannot access the web.
    Why do I need 2 rules for 3 DNS servers ?
    Why 3 servers here while you're talking of primary and secondary?
     
  2. Phant0m

    Phant0m Registered Member

    Joined:
    Jun 7, 2003
    Posts:
    3,726
    Location:
    Canada
    Hey Siddhartha

    Most ISP gives their customers two Domain Name Servers (DNS), however there are ISP’s that give their customers more then two. You can put the Primary and Secondary DNS addresses into the 1st rule (DNS-Allowed-0) and make another rule which using only “Equal” selection and place it down near the current DNS-Allowed-0 rule position in the rule-set… :D
     
  3. Siddhartha

    Siddhartha Guest

    Exactly what I did.
    Tell me Phant0m, when I do the scan test at grc.com, I see a new warning now:
    *Your Internet connection's IP address is uniquely associated with the following "machine name":

    modemcablexxx.xxx-xxx-xx.mtl.mc.videotron.ca*
    ---------------------------------------------------------------------
    xxx.xxx-xxx-xx is my IP, but written from right to left instead of left to right.
    I cannot hide this thing ?
    My IP change maybe each 3 months.
    Is it normal?
    ---------------------------------------------------------------------
    I'm using BlackICE with LnS, but the firewall in BI is desactivated, the Application Protection too.
    Just the Intrusion Detection is running.
    Any conflicts possible?
    Thank you.
     
  4. Phant0m

    Phant0m Registered Member

    Joined:
    Jun 7, 2003
    Posts:
    3,726
    Location:
    Canada
    Hey Siddhartha

    Yea additional updates at grc.com, if you want to hide your external IP Address then use web-proxy and surf anonymous.

    IP changes are normal indeed, and as for the conflict possibility with two or more Software Firewalls installed… Truthfully yes conflicts possibility is high and depending on number of factors the conflicts can possibly be “visible” to you... :rolleyes:
     
  5. Siddhartha

    Siddhartha Guest

    OK.
    Thank you Phant0m.
    I won't keep BlackICE, just LnS runnning.
    I trust your judgement.
    Have a good day.
    :)
     
  6. Phant0m

    Phant0m Registered Member

    Joined:
    Jun 7, 2003
    Posts:
    3,726
    Location:
    Canada
    Hey Siddhartha

    There is no need to trust my judgement, keep BlackICE installed and just keep an eye on abnormal System issues like Crashes, Freezes, and Delays. And even abnormal Internet Performance Delays and connection issues. Monitor Look ‘n’ Stop on regular bases to verify everything stays properly functional, and do online web-scans quite regular too.

    If you encounter any anomalies please don’t hesitate to post or Contact Frederic the Author or me…
     
  7. Siddhartha

    Siddhartha Guest

    No... I prefer to avoid possible conflicts, and I don't have the skill I think to check if everything is running fine between LnS and BlackICE, specially for very deep hidden "things".
    But let me ask: why do we see when we install LnS a message like :drivers not signed.. (didn't have the time to see correctly).
    Microsoft dislikes LnS ?
    :D
    On my side, I love it.
    I just hope that Frederic will keep it simple.
    Sometimes, when you add to much when you update, the product is not so good as before.
    We just need I think a good protection from outside, but a powerful one from our computer to the Web.
    Thank you.
     
  8. wong

    wong Registered Member

    Joined:
    Aug 14, 2003
    Posts:
    3
    hi Phant0m,

    thx very much for the explanation, i like your rule-set very much, but sadly i couldnt get it to work, as usual, i have problems with windows xp, when i ran Wntlpcfg, i got these ugly popups, (see pic). i will have to sort this out first before i can proceed further. if you know what those popups mean, please help.

    1 question: can i import some rules in your set to Enhancedruleset.rls? or can you make a less robust Phant0m rule-set that can be used straight away, just like EnhancedRulesSet.rls?
     

    Attached Files:

    • 1.JPG
      1.JPG
      File size:
      4.4 KB
      Views:
      877
  9. Phant0m

    Phant0m Registered Member

    Joined:
    Jun 7, 2003
    Posts:
    3,726
    Location:
    Canada
    Hey Siddhartha

    I apologize for what I had said which disappointed you; maybe people can tell you that they installed up-to several Software Firewalls on the current System without “noticing” any anomalies…

     
  10. Phant0m

    Phant0m Registered Member

    Joined:
    Jun 7, 2003
    Posts:
    3,726
    Location:
    Canada
    Hey wong

    You receiving DNS/DHCP Look-up Issues, that’s probably because you changed into the Phant0m`` Rule-set before collecting the Adapter/DHCP/Adapter Addresses while still on your current rule-set… ;)
     
  11. wong

    wong Registered Member

    Joined:
    Aug 14, 2003
    Posts:
    3
    and this:
     

    Attached Files:

    • 2.JPG
      2.JPG
      File size:
      5.6 KB
      Views:
      877
  12. Phant0m

    Phant0m Registered Member

    Joined:
    Jun 7, 2003
    Posts:
    3,726
    Location:
    Canada
    Hey wong

    If I introduce to the public a robust rule-set then I’m sending a message that this rule-set requiring necessary Tweaking to avoid unnecessary Leaks. I’ve made it so people need to configure the necessary rules and activate them order to use the Phant0m`` Rule-set, if one didn’t follow the web-page instructions to a tee you’ll experience such anomalies. Your situation is occurring because you switched into the Phant0m`` Rule-set before retrieving the DNS/DHCP/Adapter addresses… ;)
     
  13. Phant0m

    Phant0m Registered Member

    Joined:
    Jun 7, 2003
    Posts:
    3,726
    Location:
    Canada
    Hey wong

    Make sure you using WINIPCFG Utility if you on Win9x/ME, and use IPCONFIG or separate Utility such like WntIpcfg if you using Win2K/XP....
     
  14. Siddhartha

    Siddhartha Guest

    I'm not disappointed.
    I think that Lns will protect me enough without BlackICE installed. And less programs and memory used then.
    Sincerely.
    Sidd.
     
  15. aerox

    aerox Registered Member

    Joined:
    Jun 16, 2003
    Posts:
    5
    thank you Phant0m for the great work !

    :cool:
     
  16. Phant0m

    Phant0m Registered Member

    Joined:
    Jun 7, 2003
    Posts:
    3,726
    Location:
    Canada
    Thank you aerox! :eek:

    :)
     
  17. MickeyTheMan

    MickeyTheMan Security Expert

    Joined:
    Feb 9, 2002
    Posts:
    1,017
    http://pages.infinit.net/carbo1/firewalls.html
    Quote from my firewall page:

    One of LNS's great fan ( besides me ) is known as Phantom
    It is worth to take a look at at what is now known as Phantom's ruleset

    :D
     
  18. Phant0m

    Phant0m Registered Member

    Joined:
    Jun 7, 2003
    Posts:
    3,726
    Location:
    Canada
    awwww MickeyTheMan!!!!!

    :D
     
  19. Phant0m

    Phant0m Registered Member

    Joined:
    Jun 7, 2003
    Posts:
    3,726
    Location:
    Canada
    Karma Cookie 4 u! :rolleyes:
     
  20. FluxGFX

    FluxGFX Registered Member

    Joined:
    Jan 23, 2003
    Posts:
    667
    Location:
    Ottawa/Canada
    Just check it ?!?? You mean GRAB a f* copy and load the rule up and setit right and WOA !

    Provided that you have yourself also other layers of protection

    But if you could build yourself a small tower with 6 NIC and install a basic kernel model and make a couple of nic loop back you just made yourself a Hardware firewall with no effort and almost no cost ;)
     
  21. kamui

    kamui Registered Member

    Joined:
    Aug 19, 2003
    Posts:
    218
    Location:
    France
    Hi Phantom ,

    I use look for 3 month , it's the best firwall i ever use , thanks for your site and guide to configure this FW ;), but i have a problem.

    I dl your rules but I can connect to the web :'( , because I need DHPC or BootIP address but how can i find it ?? I use adsl speed touch adsl thomson , wanadoo 512Ko , running on XP Pro Sp1 I use , WNTIPCFG.EXE utility but it didn't notice my dhpc or bootip address ,well what can i do to use your rules plz , help :)
     
  22. aerox

    aerox Registered Member

    Joined:
    Jun 16, 2003
    Posts:
    5
    kamui in win xp go to start -> run and type cmd ; in there type ipconfig /all

    there u should see all u need :cool:
     
  23. kamui

    kamui Registered Member

    Joined:
    Aug 19, 2003
    Posts:
    218
    Location:
    France

    thx ;) but I try it an DHCP is disable "non activé" in French , How to enable it plz o_O

    Help :'(
     
  24. Phant0m

    Phant0m Registered Member

    Joined:
    Jun 7, 2003
    Posts:
    3,726
    Location:
    Canada
    Hey kamui

    Before switching from the current rule-set and onto Phant0m``s Rule-set, try retrieving your DNS/DHCP/Adapter Addresses.
     
  25. kamui

    kamui Registered Member

    Joined:
    Aug 19, 2003
    Posts:
    218
    Location:
    France
    I already have my DNS and adapter address but I only need DHCP address :( how to find it or enable it i, xp pro ??
     
Thread Status:
Not open for further replies.
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.