Tuesday, 3 December 2013

How to Tell if a File is Malicious

These days the internet is awash with malware. You can never be certain that the file you just downloaded isn’t some malicious file pretending to be safe. In fact many malicious files are designed to do exactly this. This article will explain how to tell the difference between a safe file and a dangerous one. Although this may seem like a very daunting task, I do promise that it’s not too difficult. These days there are many very sophisticated, and simple, online services that allow you to make sure a file is not malicious. If you believe that the file is probably safe then make sure that you read section 1 first before you continue on. It may save you a lot of time.

Index

1. Check If File Is In Comodo's Whitelist

2. Check File Using Comodo Valkyrie

    A) Use Valkyrie To Find Out For Sure If File Is Safe

    B) Alternatively Interpret Automatic Analysis Results Yourself

3. Check File Using VirusTotal

4. Check File For Malicious Behavior

   A) Use Comodo Instant Malware Analysis

   B) Use Anubis

5. Report Dangerous Files


1. Check If File Is In Comodo's Whitelist

If you believe that the file in question is probably safe then it may not be necessary to go through the rest of the steps outlined in this article. First upload the file to Comodo Valkyrie. This is a free service provided by Comodo that allows users to upload files up to 20MB to be analyzed almost instantly. After uploading the file look at the upper left corner. There is a part that says "SHA1". Please copy the entire string of letters and numbers that are next to it. Now go to the page for Comodo File Intelligence .


We will be using this service to see if the file has already been verified to be safe and is already present in Comodo's huge whitelist of safe files. Once on that site change the search box from "Search by Filename" to "Search by SHA1". Then paste in the SHA1 and click "Search Now". Look at the information it provides. If it says that "The file is safe" then quickly look at the results from Comodo Valkyrie. If the Final Result from Comodo Valkyrie says that the file is Safe or Unknown then you can trust the file. You do not need to continue on to the rest of the steps. However, if Comodo Valkyrie says that the file is Malicious then you may want to continue to the second section to verify that the file is in fact not dangerous. It's almost certainly safe, but it shouldn't take too long to confirm that using a few more methods.


2. Check File Using Comodo Valkyrie


Comodo Valkyrie is a free service provided by Comodo that allows users to upload files up to 20MB to be analyzed almost instantly. This service can be found on this page. Just go to the site and browse to the file you're investigating. Then upload the file. These files will be checked by multiple types of detection including static detection, behavioral analysis, whether it is detected by Comodo Antivirus, and advanced heuristics.


Using these detectors this service is able to provide a prediction as to whether the file is “Normal”, “Unknown”, or “Malicious”. A verdict of “Normal” means that the file is safe. “Malicious” means that it’s dangerous. If the analysis finds the file to be “Unknown” this means that it’s not sure.


A) Use Valkyrie To Find Out For Sure If File Is Safe

Also, some files may have already been manually analyzed by Comodo staff. If it has been analyzed the staff will have assigned it a verdict of Normal, Unknown, or Malicious. If they find it to be "Unknown" or "Malicious" then I'd advise getting rid of the file.  I wouldn't trust it.


By the way, having them manually analyze a file is the only way to be absolutely certain that it’s safe. Thus if you want to be certain about the file, and it has not already been analyzed, you can manually submit the file to Comodo staff for analysis. To do this first make sure that you have an account with Comodo Valkyrie, and are signed in. If you don't already have an account, then it's very easy to get one. Simply go to "Sign Up", choose a UserName, give them a valid email address, and enter a password. I would highly advise that you create an account. After logging in you will see that at the top of the page it shows pictures of the analysts you can assign the file to. You can choose any analyst to investigate the file. It doesn't really matter which you choose.

After assigning the file they will manually analyze it and present you with the verdict. The possible verdicts are already explained above. This analysis should often take less than 24 hours. If you do decide to have the file manually analyzed then you don't need to worry about any other methods discussed in the rest of the article. Just submit the file and wait for the results. However, if you want to find out more about the file, and aren't willing to wait for the manual verdict, then the rest of this article should be very useful for you.


B) Alternatively Interpret Automatic Analysis Results Yourself

If you decide not to wait for the analysis then you can also use this service to quickly get a lot of information about the file. After the file is analyzed the most important parts to look at are the "Auto Result" and the "Final Result". Both results are given at the top of the page. The "Auto Result" will give you the overall result from the static detection". The "Final Result" combines the results from all types of detection to provide an overall prediction for the safety of the file. All services are discussed in greater detail below. If both of these give a verdict of normal then the file is likely safe. However, before looking at these overall results check the tabs for "Dynamic Detection and "Advanced Heuristics" tab to make sure that they have finished analyzing. This will take longer than the static detection. However, to get an even better idea if the file is truly safe then you will also want to look more closely at the individual results for each tab.


Note that for some files the result will read "No PE File". What this means is that the file does not contain enough information for Valkyrie to correctly run it. More information can be found on this page. Thus, if this is the result you receive I would recommend that you skip to the next section and continue to analyze the file using the alternate methods discussed in this article.


After the file is analyzed you will be presented with three different tabs of information. The first is called “Static Detection”. The tab shows the verdict of the 17 different AI detectors that checked the file. The individual verdict of these detectors is not important. Comodo uses a very sophisticated algorithm to determine the final verdict based on each of these detectors. What’s important is the overall result given at the bottom of the screen. This gives the automatic verdict in the box under where it says “Static Verdict Combination”. It also gives its confidence under “Probability of Static Verdict”.

The tab for "Dynamic Detection" has both the results for Comodo Antivirus (CAV) and for Comodo Instant Malware Analysis, which is also known as CAMAS. The box for Comodo Antivirus will tell you if it is currently detected by Comodo Antivirus and, if it is, what type of malware it is detected as. CAMAS, or CIMA as it is also known, is a behavioral analyzer. For more information on how to understand the results please see this section of this article. In the Valkyrie results the report URL option will link you to the CIMA results. This is helpful so that you can understand what, if anything, was found to be suspicious about the files behavior. However, do be aware that there is a bug such that if you select "Report URL", when the behavior is found to be undetected, it will instead link you to the page for "Static Detection".

The other tab we will be looking at is called “Advanced Heuristics”. This examines the file with more sensitive algorithms. These are more likely to catch malware but are also more likely to incorrectly identify a file as “Unknown” or “Malicious”. Please keep this in mind when interpreting these results.


3. Check File Using VirusTotal


You can also find out whether any antiviruses (AV’s) detect it. One of the best services for this is VirusTotal. It can be found on this page. This service will scan any file you upload with over 40 different products and show the results separately for each one. You can upload files up to 64MB in size and the entire process should only take about a minute.


By far the most difficult part of using VirusTotal is interpreting the results. It can sometimes be difficult to tell from the results whether a file is likely to be dangerous. In general, if a significant number of scanners show a warning the file is likely to be dangerous. However, even if only a few detect it that does not necessarily mean that it is safe. Below are example findings for two files that are indeed malicious.




Using VirusTotal does have a few drawbacks. One of these is that it is certainly possible for malware to be so new that not a single antivirus yet detects it. I have personally seen this on multiple occasions. Thus, even if VirusTotal shows that no AV detects a file it does not mean that it is not dangerous. A related problem is that malware is being created so quickly that antivirus companies are forced to use heuristic detections and generic signatures in an attempt to keep up with it. The problem with this approach is that these detection methods may incorrectly identify a legitimate file as malicious. This is known as a false positive. These types of mistakes do occur, and with increasing frequency.


Thus, if only a few AV’s detect a file with heuristics, and the other AV’s do not, then this may be a false positive. However, this does not guarantee that it is. It's for reasons such as this that you should always check a file using all three methods discussed in this article. Below are example findings for legitimate files that are being incorrectly identified as dangerous by VirusTotal.



I want to be clear that even if only a single antivirus, or even none, detects a file as malicious then the file can still be dangerous. VirusTotal cannot be used to guarantee that a file is safe. However, if a very large number of antiviruses find the file to be malicious, then it likely is. This is the true strength of VirusTotal.


4. Check File For Malicious Behavior


In addition to the above methods you may also want to check the file for malicious behavior. There are many great services that can do this, but I have selected the two that I would most highly recommend. Do remember that legitimate files can be flagged as suspicious by them and that it’s also possible for malware to slip through undetected. In fact, some malware is even able to tell that it’s running in a virtual environment and thus refuse to run. It's for this reason, again, that it's best to use all three methods discussed in this article to analyze a file.


A) Use Comodo Instant Malware Analysis

omodo Instant Malware Analysis (CIMA) can be found on this page. I believe that the results of this service should be understandable by all users. You can upload files of any size to it and, after the upload is complete, it will immediately begin analyzing the file. The amount of time this takes is largely dependent on the size of the file and the complexity of its behavior. That said, in most cases it’s actually quite fast to analyze. I’d highly recommend using this service as it's very effective at recognizing suspicious behavior. Once the analysis is complete the results will be given at the end of the report.


The verdict may be “Suspicious”, “Suspicious+”, or “Suspicious++”. If the verdict is any of these this means that possibly malicious behavior was detected. It also gives the reasons it flagged it as such immediately below the verdict. “Suspicious++” indicates the most suspicious behavior.


If it instead says that the “Auto Analysis Verdict” is “Undetected” then it did not find any suspicious activity. This doesn't guarantee that it's not dangerous, but it does make it more likely that it's not. Thus if the above steps didn't find any malicious behavior, and neither did CIMA, then you can be relatively certain that the file is safe.

B) Use Anubis

More advanced users may also wish to use Anubis. This service can be found on this page. This is another highly effective behavioral analysis service. However, uploading files sometimes takes a very long time and the results are more difficult to interpret. That said, this service does provide a lot of information about the behavior of the file and will serve as a great second opinion to CIMA. If you're an advanced user I would highly recommend also checking the behavior of files with Anubis.

5. Report Dangerous Files

If your analysis shows that a particular file is dangerous I would recommend that you submit it to as many anti-malware vendors as possible. The easiest way to do this is to follow the advice I give in my article about How to Report Malware or False Positives to Multiple Antivirus Vendors. By following the steps outlined you can help prevent anyone else from being infected with that piece of malware.

Please help by rating this article. Also, if you believe this article deserves anything less than 5 stars, please leave a comment below explaining how you think it can be improved or where you find fault. This article is written by me but fueled by the community. Thus your opinions and advice are not only much appreciated, but actually necessary in order for this article to grow and improve.


How to Tell If A Website Is Dangerous

These days it can be very difficult to tell if a site is trustworthy or not. Many nefarious sites are being designed to look respectable. Thus you should always make sure that a site is not dangerous by using multiple approaches. This is especially important to consider before providing a site with sensitive information such as credit card numbers, banking information, your email address, etc...



In general you may want to be wary of a site if it asks you for unnecessary personal information, a credit card number, or a bank number when it's not necessary. This could be evidence of them phishing for your sensitive information. In order to better recognize phishing scams, and thus avoid them, please see the examples provided on this page. You should also be wary of sites with offers that seem too good to be true, have very intrusive ads, have multiple popups, tell you that you need to install a plugin to view content, etc... For sites such as these you should definitely consider using the methods described below to make sure that the site is actually safe before proceeding further.



Index

1. How To Investigate A Site Before Visiting It

2. General Approach To Analyzing Sites

    A) Check Site With Zulu URL Risk Analyzer and Comodo Web Inspector

    B) Check Site With VirusTotal And URLVoid

    C) Check Reputation Of Site With Web Of Trust

3. Make Sure SSL Certificate Is Trustworthy Before Making Purchases

4. How To Report Dangerous Sites



1. How To Investigate A Site Before Visiting It



If the source of a link seems phishy, such as if it came in an unrecognized email or it is a suspicious link posted online, I would recommend that you don't click it until you've made sure the site is not dangerous. To copy the link for analysis, without ever visiting the site, you can right click on it and select the option to "Copy link address" (For Chrome), "Copy link location" for Firefox, etc... If this link appears to be a shortened URL, then you must first unshorten the URL before testing it. If you don't do this then your analysis will actually just test the site that shortened it. To unshorten the link you can go to this site and paste the shortened URL into the box. It will then provide you with the actual URL, which you can copy to use for the analysis below.



2. General Approach To Analyzing Sites



A) Check Site With Zulu URL Risk Analyzer and Comodo Web Inspector

The first thing I would advise doing is copying the website's URL and pasting it into Comodo Web Inspector. However, this analysis may take a while as it is running an in-depth real-time analysis of the site to check for any possibly malicious content. Thus, I would advise running Zulu URL Risk Analyzer at the same time. However, once Comodo Web Inspector is done it will present you with its findings. If the site is rated as High Risk it's very likely that the site is dangerous. If it rates it as Suspicious the site is probably dangerous, but you may want to see what the other services mentioned in this article rate the site.



Then also copy the URL into Zulu URL Risk Analyzer. If given the choice choose to reanalyze the site. This also uses multiple methods to analyze the site. After it is done analyzing the site it will present you with an overall risk score of how likely the site is to be dangerous from 0 to 100, with 100 being very dangerous. It will also provide you an interpretation of this in which it will rate the site as Benign, Suspicious, or Malicious. While I have seen it have some false positives on safe sites, in which it rated them as Suspicious, I have never seen it rate a safe site as Malicious. Thus, my advice for using this service is that if it rates the site as Malicious you can be relatively confident that the site is dangerous. However, if it rates it as Benign or Suspicious then you should move on to the following steps to further evaluate the site.


B) Check Site With VirusTotal and URLVoid

To check the site against the databases of many reputation engines and domain blacklists the next thing you should do is copy the website's URL and paste it into VirusTotal. If the site was previously rated you should select the option to Rescan. If the site is already known to be dangerous it will likely be flagged by at least a few services. However, even if they all come up clean it doesn't necessarily mean that the site is trustworthy. Remember what was discussed earlier about how the age of the site comes into play when interpreting these results.



Also copy the website's URL into URLVoid. This service is similar to VirusTotal in that it also checks the site against many blacklists. If presented, choose the option to "Update Report", as this will provide you with the most up-to-date results. Also, near the top it provides you with when the domain was first registered. Although this information by itself tells us very little, in general, if a site is new it may not mean much if it is not flagged as dangerous by any of the above services. It often takes a while for any of the services to locate, and analyze, new dangerous sites. Also, even old sites, which were previously safe, can be hacked and turned into phishing, or malware infested, sites. Thus, just because a site is old, and not flagged as dangerous, does not mean that it is certainly not dangerous.


C) Check Reputation of Site With Web Of Trust

At the bottom of the URLVoid results for the site it also presents you with the WOT ratings. This trust score, by itself, should be helpful for you in judging whether the site is trustworthy. However, clicking on the button in the third column brings up the WOT scorecard for the site, which provides even more information. This information includes people's comments about the site, assuming anyone has left comments. In terms of the comments, it should be noted that the comments of individuals may be biased for many reasons, but by reading through many comments you should be able to get an idea of whether the site is dangerous and the main problems people have with the site, assuming there are a lot of negative comments. This information can also be used to decide whether the site is actually dangerous.



Note that another very useful aspect of using WOT is that nearly all popular sites should already be rated. Thus, if you find yourself on a site which is popular, such as Paypal, Gmail, etc..., but WOT says that the site is unrated, it may be a phishing page.



3. Make Sure SSL Certificate Is Trustworthy Before Making Purchases



Even if none of the above methods indicate that the site is dangerous, before transmitting your sensitive information to the site there are additional issues to be aware of. One of these is to make sure that the page where you fill in your sensitive information, which may include credit card numbers or banking information, is secured with a SSL certificate. If the URL of the page you're on begins with https then an encrypted connection is being used and your information is probably safe, at least assuming that the site is trustworthy. As long as the site is secured then nobody other than you and the people operating the site can view the information you are submitting. I would strongly recommend that you do not transmit sensitive information through any site that is not secured in such a way.



However, there is one subtle danger to be aware of. There are actually many different types of SSL certificates. These provide varying levels of trust. An extended validation certificate will guarantee that the business is legitimate, while many other types are only validated with respect to the domain, but not the owners and operators of the domain. Do note that some phishing sites have been known to purchas low-level validation certificates in order to trick people into believing they are trustworthy. For more information about the differences between these certificates please see this page. I'd strongly recommend reading the information on that site. Only if the certificate itself guarantees that the site is safe, and belongs to a valid business, should you have complete trust in that domain.

Monday, 2 December 2013

How to Set Up Your Own Web Server

If you have an old Windows-compatible PC lying around, it's a fun exercise to set it up as a web server.  It's also not too difficult if you have a guide such as this one to hand, and it doesn't matter if the PC is pretty old. Even something with 64 MB of RAM and an 8 GB hard disk is plenty.

If you're undertaking such an exercise, a server-oriented version of Linux is a good choice.  Why server-oriented?  Because the added GUI desktop is totally unnecessary.  Why not Windows?  Because, unless you have a spare copy of Windows Server around, you’ll be limited in the number of simultaneous connections your server can support (Windows XP Home and Professional are deliberately crippled in this respect). And Windows doesn’t run very well on old hardware anyway.

The only thing you need to check is that your computer has a built-in Ethernet connector. If its networking capability comes via a USB or PCMCIA plug-in adaptor, chances are that it won't work without you getting involved in some substantial fiddling.

I'm going to use Ubuntu Server 7.10 for this project.  It’s ideally suited to the task, and it (and all the other components we’ll be installing) is available totally free of charge.  So if you fancy giving it a go, here’s what you need to do.

Our Goal

Once you have followed this document, you’ll have a working Web server onto which users can safely and securely upload files via ftp. You’ll also have Webmin installed, for remote admin functionality, plus Webalizer for generating web usage stats. Plus, you’ll be able to host PHP/MySQL sites too.

Note that commands you need to type are in a bold courier typeface like this.

By the way, if this is the first time you’ve done anything like this (which it probably is, hence needing this document) you are strongly advised to keep your new web server within the confines of your own LAN and use it purely for your own education and experimentation. Assuming your new server is connected to the internet via a broadband router, it won’t be accessible by the world in general unless you change your firewall settings in order to allow incoming connections on port 80. And frankly, that’s the way it should stay! If you want to host real live web sites, leave it to the professionals.

First Install the OS

Get hold of a Ubuntu Server 7.10 CD, which you can download from http://releases.ubuntu.com/7.10/ubuntu-7.10-server-i386.iso. Yes, I know that this isn't the very latest version, but it's perfectly acceptable for this project and it works well. If you really want to get the latest version of Ubuntu Server instead then feel free, but the instructions below might not work exactly as you expect.

To get started, boot the PC from the CD-ROM.

When asked, name your machine. I called mine webtest, but the precise name that you choose doesn't really matter.

Your PC is probably connected to the internet via a broadband or cable router that handles DHCP, in which case the Ubuntu installer should be able to make contact with the internet automatically and obtain from the router an IP address for your server.  If it can't, you’ll be asked to enter an IP address, netmask and gateway address. If this works, then that's just fine.

A word of advice: If Ubuntu can't detect a working network connection at all, that's probably because it doesn't have the necessary drivers available for your computer's ethernet socket. In which case, to be brutally frank, you should probably give up at this point. You won't have messed up your PC with a half-installed copy of Linux yet, and trying to troubleshoot Ubuntu networking is not something for amateurs. Trust me.

Anyway, assuming that Ubuntu detected a network connection, you'll now be asked how to format the hard disk. Choose "guided – use entire disk".

When asked, choose a name and password for your day-to-day user account.

From the software selection menu, select only LAMP server. That's Linux, Apache, MySQL and PHP.

Next you’ll be asked for a mysql root password. Be aware that you’ll only be asked once (no confirmation required) and that the password you enter isn’t shown on screen. So make sure you know what you’re typing!

That's the basic Linux installation over.  Remove the CD when prompted and the machine will restart. If you don’t see a login: prompt after a minute or so, press Return and one should appear. Remember that this is a server installation so there's no pretty graphical interface here (and thus no need to connect a mouse to this PC).

At the login: prompt, log in with the username and password you created earlier.

If the server acquired its own IP address using DHCP, you’ll need to know what address it was allocated.  Type ifconfig and have a look at what’s listed for inet addr. You’ll need to know this address in order to connect to the machine, unless you register a domain name that points to it or you add an entry to your company’s internal DNS servers. If there's more than one entry under ifconfig, make an intelligent guess as to which is the right one.  You may find, for example, that a non-existent wifi connection with an IP address of 127.0.0.1 is also shown.

From now on we'll assume that your server is on 192.168.1.10.  Whenever you see this address mentioned below, substitute the correct address for your server.

So far, we’ve only got one account set up. We also need to set a password for the root (ie, administrator) account for when we need to do things that require root access. So type sudo passwd root, specify your current password when asked, then choose a password for the root username.

Linux doesn’t normally allow you to log in as root directly so if/when you need to use your root privileges, log in with your normal user account and then type su, then enter the root password when prompted. In case you're wondering, it stands for super-user.  If you ever forget who you’re logged in as, the whoami command will tell you. Or look at the command prompt, which will end with $ for a normal user and # for a root user.

Some Useful Commands

Here are some useful commands to get you started, now that you’ve got a usable Linux system:

shutdown –h now turns off the computer.
exit logs you out. You’ll need to do this twice if you used su. Remember that the web server is still running when you log out, so web/telnet connections to it will still work just fine. There’s no need to remain logged in all the time.
ls shows a directory listing (that's LS).
ls –la shows a better one (that's LS -LA).
cd / switches to the root directory.
cd dirname switches to the specified directory name, eg cd /etc.
clear clears the screen, like cls does in Windows.
cat is the linux version of the Windows "type" command if you want to display the contents of a text file.
rm deletes a file
cp is the linux equivalent of the DOS/Windows copy command.
find / -name xyz.ext will search the entire system for a file named xyz.ext
pwd (print working directory) tells you which directory you’re currently in

Within an ls –la directory listing, lines that start with a "d" are directories, otherwise they’re files. The other characters at the start of the line (such as rwxr--rw-) tell you who has permission to read, write, and execute the file.  A google search for chmod will tell you how to understand and change these.

Get Updated

Now we need to scan the internet for any important updates. The list of locations in which Ubuntu Server searches for updates is stored in a text file at /etc/apt/sources.list but the first entry in this file points to the Ubuntu Server CD-ROM. We need to remove this entry, otherwise we’ll keep getting prompted to insert the CD whenever we perform an update.

This file is read-only, so you’ll need to be logged in as root (via su) to proceed beyond this point. In fact, everything that follows is best done as root (this is an exception rather than a rule - if you're not doing server maintenance, never log in as root).

Type cd /etc/apt
Type vi sources.list

You’ll now find yourself facing vi, undoubtedly the worst editor ever invented. But without a GUI on your server you have little choice. Plus, it’s very handy to know the basics of vi because it's part of every Linux and unix system.

To move the cursor up, down, left and right, use the k, j, h and l keys (I told you it was bad). To delete the character under the cursor, press x. That should be enough to allow you to delete any line that makes reference to "deb cdrom" and which isn’t already commented out (ie, which doesn’t have a # at the start).

If you mess up, type :q! and press return to abandon vi. If you manage to make it work, type :w to save the file and then :q to quit vi.

You won’t have to use vi very often. Later on we’ll install Webmin, which lets you maintain your server from another machine via a web browser. There’s a proper file manager and editor built into Webmin, thankfully.

It’s now time to update the system so that you’re running the latest versions of everything.

Type apt-get update to update the catalog of possible updates.
Then type apt-get upgrade to download and install any that need installing.

Note that apt-get may not work if your internet connection goes via a proxy server. Even if you entered the name of a proxy server when you first set up the machine and configured it with an IP address, apt-get doesn’t take any notice. To fix this, type:

export http_proxy="http://yourproxy.com:80"

specifying the address (and port) of your company’s proxy server. Then try the apt-get again.

Test Your Web Server

You should now have a basic working web server, although we’re not finished yet. But you can test that everything is working by typing the server’s IP address into a web browser on another machine on your LAN. You should see a web page with a link to apache2-default, and clicking on the link will bring up a brief message.  Depending on your web browser, you may need to add http:// at the start of the address, eg http://192.168.1.10.

Next we’ll install a telnet server so that we can connect to the machine remotely over the LAN in command-prompt mode without the need to actually be seated at the server itself.

Install the Telnet Server

Type apt-get install telnetd

This will download and install the telnet server. Now we need to kick-start it, by typing:

/etc/init.d/openbsd-inetd restart

You can now log out by typing exit (you need to type it twice because you used the su command, and the first time just takes you back into non-root mode).

Everything we do from now on can be done remotely via telnet, so if you want to install the server in a hard-to-reach cupboard that’s no problem. You won’t need physical access to the server again unless something goes wrong or if you need to turn it back on after a shutdown command.

To access your server type telnet 192.168.1.10 (or whatever the IP address of your server is) from any machine on your LAN and you’ll get a login prompt. You can do this from Windows or Linux or even a Mac.

Install the ftp server and set up a Web User account

Next, we need to install an ftp server so that people can upload html pages to your new web server. An ideal tool for this particular job is proftpd (that’s Unix-speak for the Pro FTP Daemon).

If you haven’t done so already, telnet to your server and type su to get root access. Or you can work on the server directly if it’s easier, of course.

We need to take a little care to set up the ftp server in a reasonably secure manner, even though this is only for test or educational purposes. We need to ensure that a user who logs into the ftp server in order to upload web pages can’t browse the entire server but is locked into one directory. Also, we need to ensure that a user who has an ftp username and password with which to upload web pages can’t use those credentials to access the system via telnet, as that would grant them far too much power.

Type apt-get install proftpd to install the ftp server. You’ll be asked whether to choose an inetd installation or standalone. Choose inetd.

The basic ftp server is now up and running, and you should be able to log into it with your non-root account. But we still need to set up an account that will allow someone to upload their web pages without having access to any other parts of the system.

First, switch to the /etc directory by typing cd /etc. We need to edit the file called shells and add a new line that says /bin/false to the file. Then, when we set up a new user account for our web user, we’ll configure their account so that /bin/false is their command shell. Because there’s no such shell, they won’t be able to log in with telnet.

Type vi shells to edit the file. Use the cursor keys (h,j,k,l) to move the cursor to the start of a new line, then press i to enter insert mode. Press Return to insert a new line, and add /bin/false as a new line in the file. Press Esc to leave insert mode, save the file with :w then exit vi with :q and you’re done.

Each user has a home directory which contains their various files. It’s like My Documents in Windows and normally it resides in the /home directory. For web users, rather than setting their home directory to be somewhere within /home we’ll put it under /var/www, which is the root of the web server.

Let’s make an account for a user called webuser1 with a password of flintstone.  These are the steps that you need to do for each web user account you want to create:

cd /var/www
mkdir webuser1
useradd webuser1 –p xxxx –d /var/www/webuser1 –s /bin/false
chown webuser1 webuser1
passwd webuser1 and, when asked, choose flintstone as the password.

Note that xxxx above is your root password, not the one that you want to assign for the webuser1 account.

Also note the chown command which changes the ownership of the webuser1 directory from root (which created it) to webuser1. If you don’t do this, webuser1 won’t be able to upload files.

Just to make sure that everything is working, verify that you can’t telnet to the server using the webuser1 account.

Now create a simple index.html file and use ftp to upload it, using the webuser1/flintstone account.  Then surf to http://192.168.1.10/webuser1 from any machine on your LAN and you should see the uploaded page.

Before we leave proftpd, there are a couple of changes that we need to make to its configuration file in order to improve security and make things neater.

Type cd /etc/proftpd and then vi proftpd.conf to edit the config file. Move the cursor up and down with j and k until you reach the DefaultRoot line, and remove the # symbol from the start of the line by pressing the x key. This will lock all ftp users into their home directory (eg /var/www/webuser1) and won’t let them view files that are further up the tree. Without this step, our webuser account holders could use their ftp software to browse the entire server's directory structure.

While you're in proftpd.conf, add a new line near the top of the file which says:
IdentLookups        off

This will fix the problem which you’ll no doubt have noticed, of a few seconds’ delay when logging into the ftp server or uploading files.

You may also wish to change the ServerName entry from Debian to the name of your server, to make the welcome message more relevant. With vi, remember that typing i puts you into insert mode, for typing text, and Esc then puts you back into command mode from where you can type :w to save the file and :q to quit vi.

Webmin

Now that ftp is working, let’s install Webmin so that we can remotely administer the server from anywhere on our LAN via a web browser. It’s more fun and friendly than using telnet, and a great way to explore the machine.

First, make sure you’re logged in as root (via your normal user account and su) then type the following, all on one line:

apt-get install openssl libnet-ssleay-perl libauthen-pam-perl libio-pty-perl libmd5-perl

Then type:

wget http://prdownloads.sourceforge.net/webadmin/webmin_1.380_all.deb

Note that wget probably won't work if your internet connection goes through a proxy server.  In which case, type export http_proxy="http://yourproxy.com:80" first, and then issue the wget command.

Finally type dpkg -i webmin_1.380_all.deb and Webmin should be installed and ready to use.

From another machine on your LAN, surf to https://192.168.1.10:10000 and log in as root, using your server’s root password. Note the https bit – it won’t work with plain http. Also note the :10000, which is essential.

Ignore the warning about a missing SSL security certificate – you can trust this server unconditionally because it’s yours. You will, though, need Java installed on the PC from which you intend to use Webmin, otherwise it won’t work.

Possibly the most useful part of Webmin is the file manager, which also lets you edit files. You’ll find it in the “others” category at the bottom of the left-hand menu.

Webalizer

Now we’ll install Webalizer, which is a great tool that produces graphical stats to show your web site usage. Even if you’re only using your server for test/educational purposes, it’s useful to be able to see the sort of stats that are available with such programs.

To install webalizer type apt-get install webalizer

You need to tweak the Webalizer config file before the program will work. Type cd /etc/webalizer then vi webalizer.conf and delete the .1 from the end of the LogFile entry.

Webalizer produces its reports by analyzing the Apache web server log file on a regular basis. To make it do this, you need to set up what’s called a cron job in order to run /usr/bin/webalizer regularly. Every 15 minutes should do nicely, and the easiest way to do this is via Webmin.

Go into Webmin via https://192.168.1.10:10000 from another PC and, under the System category, click on "Scheduled Cron Jobs". Then click "Create A New Scheduled Cron Job".

Choose to execute the job as root. The command to execute is /usr/bin/webalizer. Click on "Times And Dates Selected Below". Under the minutes, tick "Selected" and choose 0, 15, 30 and 45. For hours, days, months and weekdays, select "All".

Now click the Create button and close your web browser. After 15 minutes or so, surf to http://192.168.1.10/webalizer and you should see the reports and stats.  Wait another 15 minutes and you should see an updated version.

PHP and MySQL

Now we need to make PHP and MySQL work, to ensure that we can host not just static html sites but also dynamic database-driven ones. PHP should already be working just fine, so we need to test that. Create a file called test.php which contains:

<?
echo “this is a test file”;
?>

Upload it using the webuser1 account. Surf to http://192.168.1.10/webuser1/test.php and check that you see a web page containing just the message “this is a test file”. If it works, PHP is working on your web server.

To allow users to create database-driven sites we’ll install phpMyAdmin, which is a graphical web-based tool for managing MySQL databases. It’s best if we don’t allow web users to create their own databases, but we do want them to be able to manage the databases that we set up for them. PhpMyAdmin will work for both of these tasks. IE, for us to create databases and for our web users to maintain the tables within their allocated database.

As root, type apt-get install phpmyadmin

When asked which web server you’re using, choose apache2.

To use phpMyAdmin, surf to http://192.168.1.10/phpmyadmin and log in with a username of root and the MySQL root password that you set up right at the start of this document.

On the front page of phpMyAdmin, scroll down to the Privileges link and click it. Then click "Add A New User". Enter their username (webuser1 in this case), and assign them a password. This will be used for them to log into phpmyadmin, and they’ll also use it in their PHP code in order to connect to their database (using a host name of localhost). It’s up to you whether you make it the same as their ftp password (flintstone). In this example, let’s set the password as barney.

Click "Create database with same name and grant all privileges" and all the hard work will be done for you. A database called webuser1 will be created, with permission for the webuser1 account to do everything except creating new databases.

Log out of phpmyadmin (just close your browser), and then log in again. This time, use a username of webuser1 and a password of barney. You should see only the webuser1 database and no others, and you should find that you can create tables on the database but you can’t create new databases.

How to Change DNS Server

Introduction
Want to change your DNS server? You might need to know more about What DNS Servers Do or you might need to know How to Find the Best DNS Server.

There are three sections in this how to guide.

Why change my DNS Server?
How is your system configured for DNS
How to change your DNS settings
1. Why change my DNS server?
For speedy performance

Every web page requires an IP address before it can be loaded. The time taken to resolve a DNS name can add several seconds to the loading of a page. The faster your DNS server then the quicker your pages will load.

The larger the database of the DNS server then the greater the likelihood that the name will be found without searching on other DNS servers. These cached hits are much faster than uncached hits. Typically by a factor of ten so a 0.1 second.cached name could take 1 second if it is not found in the DNS server database.

For increased reliabilty

Most DNS servers are available near enough to 100% of the time. If your isn't then find a more reliable server. DNS queries can timeout or, in the worst case, receive no response at all. There are several ways to reduce such problems:

Your primary DNS server should be the fastest DNS server for you.
Define more than one DNS server to use - a minimum of two and probably more - to reduce the risk of one or more DNS servers not being available.
Use DNS servers that are in different cities or countries, ie geographically diverse, to reduce the likelihood that one 'disaster' will affect all your DNS servers at the same time.
Have at least one DNS server that is close to your location, probably a DNS server at your Internet Service Provider (ISP).
If your ISP is small then definitely look for a DNS server with a larger database.
For greater safety

All DNS servers do not offer the same features or have the same vulnerabilities. Many DNS servers still do not operate using established security features like DNSSEC.

Some DNS servers provide additional features such as the filtering of web addresses to improve security. These solutions can create other problems.:

Malware protection is provided by Norton DNS and others
Phishing protection is provided by OpenDNS and others
Category filtering for parental controls is provided by OpenDNS and others
2. How is your system configured for DNS
Configuration

Automatic configuration from your ISP?

You will usually define your DNS servers when you configure your Internet network connection whether dial-up or broadband. Most Internet Service Providers (ISPs) have automatic configuration of some sort so the DNS servers are defined automatically. If you had to manually configure the network connection then chances are that you also had to manually define the DNS servers.

Configuration on your system

DNS servers settings will exist for each PC you use on the Internet whether they were manually input or automatically configured. The key question is where are my external DNS servers defined?

At your PC? If it is directly connected to a modem for Internet access then it will have the system DNS servers.
At your router? If you have a local area network (LAN) then a router is usually the best place to define your DNS servers. Any device connected to that router can be updated automatically using the Dynamic Host Configuration Protocol (DHCP). This means that changing the external DNS servers at the router will affect all devices connecting to it using DHCP.
The problem with this is that cheap home routers can cause problems. This seems to be the case with my router. I have more problems when my router is configured as the DNS Server with the IP address192.168.2.1 (an address reserved for internal networks) than if I define the DNS servers manually at each PC.
How to find your system DNS servers

There are several methods to find your system DNS servers. If you want to know more then go to the next section Changing your DNS configuration for further resources.

I recommend that you use the excellent resources for changing your DNS configuration in the next section. The best cover most operating systems and many routers.
In your network connection settings, go to the properties for your network connection, select the network card if there is more than one, and then the TCP/IP protocal properties which include the DNS servers..
The programs described in How to Find the Best DNS Server will tell you what your DNS servers are.
The Windows command line: ipconfig /all displays the system IP configuration including the system DNS servers
Example of method 2 - Inspect your network connection settings in Windows

Note that you can exit out of this by pressing the Esc key, selecting Cancel, or closing each window.

Find the network connection icon in the system tray at the bottom right of your screen.
Right click on the network connection icon with your mouse to bring up the context menu.
Select the 'Status' menu item.


The Local Area Connection Status dialog should display.
Select the 'Properties' button.


The Local Area Connection Properties dialog should display.
Select 'Internet Protocol TCP/IP'


The Internet Protocol (TCP/IP) Properties dialog should display.
The DNS configuration is visible at the bottom.
In this example, the DNS servers have been defined manually but they would not be visible if the radio button was selected for 'Obtain DNS server address automatically'.
If they are visible, select the 'Advanced' button to see the Advanced TCP/IP Settings where we can see if more than two DNS servers are defined.


The Advanced TCP/IP Settings dialog should display.
The IP Settings tab will be displayed first.
Select the 'DNS' tab to display the DNS server addresses. In this example, there are only two DNS servers.
I have also selected the 'Add' button to bring up the 'TCP/IP DNS Server' dialog in which I've entered a DNS server IP address 8.8.4.4 ready to 'Add'.
The sort order can be changed using the arrows at the right.


How to test if the system DNS configuration is damaged

You can incorrectly configure your system DNS by, for example, typing in incorrect IP addresses for the DNS servers. If you do this then your web browser will not be able to access Internet resources using domain names but you should be able to use URLs with a valid IP address. Just type a valid IP address in as the URL and your browser should add the rest e.g. 72.52.134.16 is converted to http://72.52.134.16/.

If you find you have lost all web access even using IP addresses then that is very unlikely to be a DNS problem. Your network connection could be down or malware could have changed your configuration (e.g. by setting your network connection to use a proxy server).

3. Changing your DNS configuration
Before configuring your chosen DNS Servers

You might want to run a DNS Spoof Test to check the vulnerability of your chosen DNS servers. Just be aware that some routers lockup or crash if you run these tests. GRC provides a list of routers with known problems. It didn't include mine which crashed when I tested it. I had guessed it might because it is similar to some of those listed. That's a good reason to get a better router. See GRC's notes at the bottom of the DNS Spoof Test page for a list of routers that fail in this way.

Resources to help you change your DNS configuration

There are programs to automate the changeover to better DNS servers but I'd give them all a miss. Instead, I encourage you to visit some excellent resources that will help you.

Web quides and tutorials

If you are at all unsure, you should have a look at these resources about configuring your DNS servers. Just remember that the DNS server IP addresses they show you in the guides are for their servers. You can substitute the IP addresses for your preferred DNS servers.

OpenDNS has an excellent Setup guide for most operating systems. There are video tutorials which some will find useful. DNS Benchmark discusses the issues around router-based DNS configuration. The site also recommends the OpenDNS guide.
Google has good instructions for both changing and then testing the new configuration.
Other simpler, less complete guides can be found at DNS Advantage (Comodo DNS). ClearCloud has instructions to switch away it as it is discontinuing its free DNS service.
Software that might help you to change your configuration but are too limited

DNS Jumper will change your DNS addresses for you but has some significant weaknesses:

Only the first two DNS servers can be changed on your system. If you want more than two then you will need to find another solution.
By default it only includes public DNS servers in its database. You can add others.
It can only change to a set of DNS servers e.g. both from Google or both from OpenDNS. If you want to mix service providers then you will have to add a new set yourself.
DNS Helper (formerly Google DNS Helper) is a utility to change to one of the main global DNS service providers that I do not recommend:

You cannot add your own servers apart from one set of custom DNS servers.
If you change DNS servers while in a Windows session it will not update the DNS server IPs to restore until you start a new session.
Likewise Public DNS Server Tool is too limited to be recommended.

After you change your DNS configuration

Flush the system DNS caches

When you change your DNS configuration you should clear the system caches so that the new DNS settings take immediate effect. I use CCleaner, the Editor's Choice for Best Free File Cleaner, to clear the caches because it runs once and cleans each browser's cache. Other options are more limited.

Flush the system DNS resolver cache.
The Windows command ipconfig /flushdns will flush the DNS resolver cache and refresh it with only the entries in the Hosts file. ipconfig /displaydns will display the system DNS cache.
Flush your web browser caches
Some browsers will allow you to do this from the menu.

How to Find the Best DNS Server

Introduction
DNS servers are the most trusted component of your web browsing experience but few people understand how they work or how their security vulnerabilities can cause you problems. I recommend that you read both What DNS Servers Do and How to Change DNS Server before you change the DNS servers your system relies upon.

Three free utilities can help you to find the best DNS servers for your system.These benchmarking programs use their databases of DNS servers to test those that will give you the best improvement. The best performance is likely to be from from a mixture of DNS servers that are close to your location and a global DNS server that has a large database. These programs are portable (run without installation), use similar methods and provide similar results. Their reporting is very different so I recommend that you try both NameBench and DNS Benchmark.

Google NameBench is easy to use and comprehensive but doesn't preview the DNS servers being benchmarked. It is compatible with Windows, Mac OS X, and UNIX.

Gibson Research Corporation DNS Benchmark is the program I prefer. It is a little more complex but provides a lot of documentation and help for each step. It does preview the servers that will be tested before you run the actual benchmark. It is a Windows program that also runs in Windows emulation (Wine) for Mac OS X and Linux.

I recommend DNS Benchmark for all users outside of North America. It clearly identifies one problem that NameBench does not. My primary DNS server had slow response times for major dot com sites which  usually have their home in the United States.

DNS Jumper is the simplest with very limited testing. It provides a quick test of public DNS servers, allows you to customize the DNS server list, and can change your configuration. It runs under Windows.

There are two sections in this how to guide.

How to configure the testing software
How to run the tests using NameBench, DNS Benchmark or DNS Jumper.
1. How to configure the test software
Installing  the software

These programs run directly from the download and have no install procedure so they don't alter the Windows registry or add shortcuts to the desktop or menu.

How to copy the files to the folder you want to run them from

They also won't create their own folders to install to so if you want that you will have to do it yourself.

namebench-1.3.1-Windows.exe and DNSJumper.zip should be unzipped to the folder you desire.
DNSBench.exe should be copied to the folder you desire.
Download additional files as required

Namebench command line version requires Python 2.5 to 2.7 to be installed. UNIX and Mac OS X usually have it so it is mainly Windows users who might have to install it.

Advanced configuration

The average user can skip the rest of this section and go straight to testing.

Editing the configuration files before running the first test

The first test will be the most accurate because it is more likely that the tested domains will not be cached. Once the test has run then any further requests for the same domain are likely to be cached. Therefore some advanced users might want to edit the configuration files before running the first test.

Namebench has three configuration files in a subfolder (\namebench\config) of the folder you have unzipped it to:

namebench.cfg is the main configuration file and probably the only one that you will edit. I edited it to increase number of servers tested and added more global DNS servers.
It contains the following:
Settings, most of which can be overridden if you use the Python command line.
Global DNS servers. The default is to test them.
Regional DNS servers. The default is to test them.
hostname_reference.cfg contains two lists of websites.
censored sites which are not tested unless specified
sanity checks sites which are used to check that the returned IP is correct for the DNS name.
These are tested everytime unless you have a version of NameBench which includes the option to turn this off, ie download_latest = 1 becomes download_latest=0.
data_sources.cfg points to the sources of the website test list:
List files provided with NameBench
Browser databases
DNS Benchmark has two configuration lists which do not exist when you first run DNS Benchmark. I created both lists from those tested in NameBench so that I can compare the results of the two programs.
I opened the NameBench .csv results in Excel, summarized the list of sites and DNS hosts using two pivot reports (there are other ways to do it), then copied the lists into the respective files:

DNSBench.ini contains the list of DNS servers to be tested. It is not created until you decide to add or remove servers using the menu or until you have run the test to create your own customized list of servers. You can create many .ini files with different names and add or remove them from the test list anytime that you like.
domains.txt contains the list of websites to be used for the tests. The default is the top 50 Alexa sites from 2009, there is also a list of 100 top Alexa sites. Note that both lists are uncensored so by testing these sites there is potential for embarrassment or worse. Both files are available at Resource Files for Advanced Benchmarking.
Once edited you have to run DNS Benchmark with the command line option:
dnsbench.exe /domains domains.txt

DNS Jumper has one configuration file:

DNSJumper.ini contains the DNS server list, a few program options, and the text for each language.
To add another DNS server type append it to the list  in the format <server name?=<server IP address>,<server IP address> etc., e.g."my setup=192.168.2.1,202.180.64.2". DNSJumper will automatically assign the correct server number.

2. How to test for the best DNS servers
In this section I explain how to test using a real example of my own.

Checklist before you start testing

Only the DNS test program should be using the Internet connection otherwise your results will be affected by other traffic and may not be consistent with any later test.
If your firewall has outbound-blocking then it can block the tests. You might need to turn that off temporarily by following the specific instructions for each product.
DNS Benchmark firewall FAQ

The first test is likely to be most accurate because later tests will be running the same queries which should then be cached in the servers. If you have your own list then now is the time to use it.

Testing with NameBench

 1. Run NameBench and set the test options.

The NameBench options are explained as follows:

Nameservers lists the IP addresses of your system DNS servers. You can delete them from the test or append other servers to the list.

In this screenshot, 192.168.2.1 is an IP address reserved for private networks such as my router which has two DNS servers defined. On my PC 192.168.2.1 is automatically assigned (by DHCP) from the router. 202.180.64.2 is the secondary IP address that I manually input in Windows.

Include global DNS providers should probably be checkmarked. They will provide a good baseline for comparing other DNS servers. If you don't check this then you will only get results for the fastest DNS servers for your system.

NameBench defaults to 10 DNS servers so the more global servers that are included then the fewer regional DNS servers will be included. For the results graphs, NameBench will usually only use the primary DNS server because it removes duplicated/backup/replicated servers so, for example, Google DNS will only count as one DNS server although Google has many servers and several IP addresses.
Include best available regional DNS services should be checkmarked because these will usually be your fastest DNS servers.

Include censorship checks will include websites that are often censored because of political views, violence and hatred, gambling, etc.

Upload and share your anonymized results should be checkmarked if you want an easy way to share your results over the Internet. I expect that in the future NameBench will provide reporting from this database without running a benchmark.

Health Check Performance should be set to Fast (to query 40 DNS servers at a time) unless you have poor connection in which case set it to Slow (to query 10 DNS servers at a time).
Number of queries defaults to 250 web sites for each of the 11 DNS servers. You can speed up the tests by changing it to 50 which is the default for DNS Benchmark.

Query Data Source determines where NameBench gets its list of domain names to test. As well as five test scenarios , NameBench can extract the information from Camino, Chrome, Chromium, Epiphany, Firefox, Flock, Galeon, Icab, Internet Explorer, Konqueror, Midori, Omniweb, Opera, Safari, Seamonkey, Squid and Sunrise.


2. Run the benchmark

First, NameBench checks the connection quality and makes adjustments for the connection condition. That is why you should not have other Internet activity while running the tests.

NameBench then selects the fastest to benchmark:

checks the DNS servers are available to the test system
performs TTL tests
checks for cache sharing with replicated servers and then removes the slower DNS replicas
selects the DNS servers for benchmarking


The DNS queries are sent to the selected DNS servers.

3. View the benchmark results.

Click on the images in this review to see the results of a full test that I ran

The primary report is a table.

NameBench presents a recommended configuration for three DNS servers.
The current primary DNS server is highlighted in pale yellow.

In this case, a 5.1% improvement would not be enough to change without doing further tests to confirm that the improvement is consistent. The red bars indicate timeouts for the proposed server. In this case, two queries timed out at 3.5 seconds so that is not good and another reason to test again.

Ignore that "www.paypal.com is hijacked hijacked" because this is a known bug.

Replica DNS servers are indicated so you know which servers have backups available.


There are two types of graph presented. The first are bar graphs of the average and fastest response times. Note that each graph uses a different scale.

Look at the second graph first because the fastest response time shows you the best that you can get. This graph shows that network distance, which is similar to geographical distance, is the main driver for response times. So the response time is roughly proportional to the distance from my home. The six NZ DNS servers are grouped first then one Australian DNS server then the four global DNS servers mainly located in the USA.

The averages response time look quite different because the second driver is the size of the name cache. Global DNS servers perform much better because they have larger name databases. OpenDNS, Google and UltraDNS are ranked fifth to seventh but still remain 50% slower than the best regional DNS server.


Then there are line graphs of cumulative response times.

The distribution graphs show what percentage of queries are answered in what period of time.
The first graph is for the first 200 milliseconds ie 0.2 seconds.

The second graph continues to the 3.5 second default for the timeout.
Although it is available when you first view the results, when you go to the website it will not be there.
This graph shows how the global providers though slower at the start are much more consistent with fewer timeouts. By a quarter of a second and 30% awaiting a response they're competitive. By a third of a second and 10% awaiting a response they're performing better.

It is the long tail for the slower response times that will be noticeable when you are browsing. So if you are prepared to live with slower average response times that you don't notice then you can stop the really slow and annoying response times by using a global DNS service.

Then there are line graphs of cumulative response times.

The distribution graphs show what percentage of queries are answered in what period of time.
The first graph is for the first 200 milliseconds ie 0.2 seconds.
The second graph continues to the 3.5 second default for the timeout.


Although it is available when you first view the results, when you go to the website it will not be there.
This graph shows how the global providers though slower at the start are much more consistent with fewer timeouts. By a quarter of a second and 30% awaiting a response they're competitive. By a third of a second and 10% awaiting a response they're performing better.


It is the long tail for the slower response times that will be noticeable when you are browsing. So if you are prepared to live with slower average response times that you don't notice then you can stop the really slow and annoying response times by using a global DNS service.

The online results include sample index results for Wikipedia.com and Google.com instead of presenting the second response distribution graph.

Finally, the benchmark parameters are listed.

Testing with DNS Benchmark

1. Start DNS Benchmark


To view the DNS servers click on the Nameservers tab highlighted above. You will have to wait about 10 seconds for the list of servers to be loaded.

Your system DNS servers will appear first in the list. The remaining servers are sourced from DNS Benchmark's list of global servers. The advantage of this approach is that you have the opportunity to refine the server list before testing.



At this point you can add or remove servers by using either of two menus:

Click on the Add/Remove button to display the first menu shown below.
Click on the system icon at the top left to get the system menu which is a superset of the Add/Remove menu.




The servers can be added or removed individually or in three groups:

Your system DNS servers
The default global servers
Your own .ini file.
You can remove all servers to clear the list and start again. Once complete you can save your list to an .ini file.

There are two further options that you might consider to prune the list:

Remove dead servers that are not responding. This is well worth doing.

Remove redirecting DNS servers. This might remove DNS servers that you want to avoid but it will also remove OpenDNS and other filtering DNS servers.

The final option is to build the custom server list without running the global benchmark. If you want to save time then do this and skip to Create the regional DNS server list.

2. Run the global server DNS benchmark

As well as clicking on "Run Benchmark", you can also click on the Gibson Research Corporation (GRC) logo to start or stop the benchmark.


The first two servers are the system DNS servers as indicated by the solid green circle.
The other servers are not the system DNS servers because they have hollow circles.
The colour of the circle indicates the quality of the connection:
Green = good
Orange = redirecting or hijacking DNS servers
Red = the server is not responding ie is dead. I remove dead servers so there are no red circles in the example results.
OpenDNS also has a blue circle around the server status. This indicates that IP addresses reserved for private networks are being blocked. There are four ranges of addresses so in this case three of the four are being blocked.
Green = both IPv4 and IPv6 reserved private addresses are being blocked
Blue = either IPv4 or IPv6 but not both reserved private addresses are being blocked
The organization owning the DNS server is shown at the right.
The main results display the results of cached queries. DNS Benchmark provides two particularly useful test results if you check the Show Uncached checkbox:

Uncached queries (green) where the DNS server cache is bypassed.
DotCom queries (blue) for major global websites (dotcoms) that are mainly located in the United States.
In the example below my primary DNS server has unacceptably slow response for major global websites (DotComs). This problem was not visible in the NameBench results.

DNS Benchmark highlights slow uncached results

The server that is reported to be fastest is one of my ISP's DNS servers. I should probably change to it because it is faster and has no problems with DotComs unlike my primary DNS server. However it does have a problem with lost queries as indicated by the red bar which displays over the server IP address on the left. It is not a big problem but I would test again to see if it is a regular problem.

3. Create the regional DNS server list




The Custom Namerserver List is a list of your regional DNS servers that are likely to give you the best service. DNS Benchmark goes through its database of nearly 5,000 DNS servers to find those that are likely to perform best for you. It creates the list and then you can run the benchmark.

While it is creating the list you can see the total number of servers including the following:

Resolved = those you can use
Refused = those that reject your queries maybe because you are in a region that they don't service
No reply = dead servers


4. Run the regional DNS server benchmark

The regional DNS server benchmark runs the same as the default server benchmark. So the results apply just the same.

5. View the results

DNS Benchmark displays the results as it works so you will quickly be able to see which DNS servers are performing the best. I've drawn a few conclusions from the final results displayed at right. Note that DNS Benchmark allowed me to save these results as an image file because a screenshot wouldn't show enough servers.

By default DNS Benchmark gives you a better comparison of more servers than NameBench which has to be configured to provide results for more than 10 servers.
Servers in my country are the fastest. Like NameBench, DNS Benchmark illustrates the same relationship.
The results illustrate that the primary driver for DNS query time is the delay (latency) due to the distance between systems on the Internet. This network distance is roughly the same as geographical distance. You will notice the same sort of delay If you ever make a phone call to the other side of the world.
Query response time = network latency + server processing time

The speed of the DNS server itself is far less important but does make a difference where several DNS servers are located in the same region.
You can also see that DNS servers with lost queries tend to perform worse. The lost queries are indicated by the red bars overlaying the DNS server IP address in the left hand column.  Seven of the eight New Zealand servers with lost queries are the worst performing in that group.This is likely to be the same in other countries
Remember that DNS Benchmark has several tabs to view the various results:

Nameservers shows you:
Server name
Server owner
Server status
Server response times
Cached response times are displayed by default
Uncached response times are displayed by checking the box
Tabular Data shows you the numeric results in a small table for each server. The formatting is text-based so you can export it to any editor.
Conclusions provides you with a comprehensive list of conclusions and recommendations. These are clearly explained to guide you. In the screenshot below, I have only shown the start of the first of seven conclusions. It has a positive green tick so there is no action required. Where DNS Benchmark displays a red cross you will be advised what you should do to improve your configuration.


6. After completing the benchmark:

The DNS server list will be saved in the default.ini file. As discussed above, you can amend the list or detete it and start again.

To save the results go to DNS Benchmark's System Menu and select 'Export last results to CSV file'. DNS Benchmark also provides for saving any of the results pages either as an image file (.png or .bmp) or a formatted text file (.rtf).

Testing with DNS Jumper

DNS Jumper is relatively simple but I do not rate it highly so I''m only showing the main window for your information.


1. Select your network card.

2. Add or remove any DNS servers to the DNS Jumper database using the + or - buttons.

3. Find the "Fastest DNS"

The fastest will appear in the "Manual DNS Servers" list.
Response time is displayed in milliseconds.
If the DNS server is invalid or unavailable thenthe result will be "Host is offline"
You can also flush your system's DNS cache but the flush is not as effective as using the Windows/DOS command "ipconfig /dnsflush"
4. If you want to use the fastest servers then select "Apply DNS" to save the change.

I found the results unreliable and would be reluctant to use them without a second opinion. But the program is a quick and easy introduction to selecting a global DNS services.

Sunday, 1 December 2013

How to Surf More Securely

With the number of hostile websites increasing every day surfing has become a much more risky activity. In this article Gizmo shows you two different ways to increase your surfing safety. Additionally he explains how to configure all your programs that use the internet, to work more safely.

A. Introduction

The good old days of casual and carefree surfing are over. Today a simple act like clicking on a search engine hit or responding to an ad may take you to hostile website whose main mission is to infect your PC with spyware, trojans and worse.

Worse still, hackers are now regularly attacking and compromising legitimate websites and then using these sites to infect surfers.

And don't expect your anti-virus program to save you. Many of these evil sites make use of specially crafted malware products that your AV program doesn't know about or cannot see.
Nor can you hope to be saved by keeping your software up-to-date with the latest security patches. These hostile sites often exploit new or undocumented flaws in Windows, your browser or other products to take control of your PC.

The good news is that it's possible to protect your PC against hostile sites. There are actually several different ways but in this article I'm going to discuss two of the most convenient ways. Happily, they are also among the most effective.

A. Introduction

The good old days of casual and carefree surfing are over. Today a simple act like clicking on a search engine hit or responding to an ad may take you to hostile website whose main mission is to infect your PC with spyware, trojans and worse.

Worse still, hackers are now regularly attacking and compromising legitimate websites and then using these sites to infect surfers.

And don't expect your anti-virus program to save you. Many of these evil sites make use of specially crafted malware products that your AV program doesn't know about or cannot see.
Nor can you hope to be saved by keeping your software up-to-date with the latest security patches. These hostile sites often exploit new or undocumented flaws in Windows, your browser or other products to take control of your PC.

The good news is that it's possible to protect your PC against hostile sites. There are actually several different ways but in this article I'm going to discuss two of the most convenient ways. Happily, they are also among the most effective.


This should start your default browser securely locked away in its own sandbox.  SandBoxie indicates to you the browser is sandboxed by putting a "#" sign before and after your browser window title bar caption.

You can use your sandboxed browser perfectly normally. In fact apart from the # signs in the title bar you wouldn't know that it is sandboxed.

But sandboxed it is. That means that for all practical purposes your real PC cannot get infected by visiting a hostile website.
When you have finished browsing shut down your browser and then right click the yellow SandBoxie tray icon again. This time select  "Terminate Sandboxed Processes."


Once selected everything that happened while surfing is deleted, including of course any malware infections and files.
That also includes of course any bookmarks you created and any files you deliberately downloaded. If you want to permanently bookmark sites while browsing in a sandbox I suggest you use an online bookmarking service like Google Bookmarks or Del.icio.us.  Advanced users can configure Sandboxie to share bookmarks with the non-sandboxed version of your browser thus making any new bookmarks created while surfing in the sandbox permanent.  Details can be found on the Sandboxie site.

You can copy downloaded files from your sandbox to your real PC before you delete the sandbox contents. That way you permanently keep file you want. You can find full instructions how at the SandBoxie site here. I do however suggest that before you move any file out of the sandbox that you actually first install the downloaded file from within the sandbox. If your security software doesn't sound any alarms and the programs seems to be behaving as you expect then go ahead and move it to your real PC and install it again. Remember though to still delete the contents of the sandbox.

For more information on using SandBoxie consult the online tutorials at the SandBoxie site

C. Running your browser with reduced privileges using DropMyRights

For a hostile website to install malware on your PC the malware must have access to full "administrator" rights on your PC. That's not normally a problem as most Windows users operate with full administrative privileges; its the default setup for users in all Windows systems prior to Vista.

By denying malware access to administrator rights you can prevent it from installing. The easiest way to do this is to use a limited rights Windows user account rather than one full administrator privileges.

It sounds like a great idea but there are many practical problems using a limited user account. For example lots of simple routine tasks like changing the system clock, plugging in a USB drive, running a defragger and updating software can't be carried out in a limited user account.

An alternative approach and more practical is to adopt the converse policy, that is, to routinely use an administrator account with full rights but reduce the privileges just of your web browser and other risky programs. It's a strategy that offers fewer inconveniences than running a limited user account at the cost of a slightly lower level of security.

Several free tools are available that allow you run your browser and other specified programs with reduced privileges. Best known is Microsoft's own DropMyRights which works with Windows XP and above.

Using DropMyRights is quite easy. In essence you use the program to create a desktop shortcut to a special version of your browser that operates with limited privileges. To surf safely you just click the desktop icon.  If you want to use your browser normally with full administrator privileges then just start your browser the normal way.

The instructions for installing and using DropMyRights with Internet Explorer on the author's site are a bit cryptic for beginners so I've created a fuller version below:

1. Download DropMyRights from here It's only a tiny 164KB file so it should download in just a few seconds.

2. Locate the downloaded file DropMyRights.msi and double click it to start the install. Accept the EULA and click "Next"

3. When asked the location of the installation folder cut and paste the following line into the box and then click "Next" and then "Close."

C:\Program Files\DropMyRights

4. Right click on your Desktop and select New / Shortcut
5. In the first screen of the shortcut wizard cut and paste one of the following lines into the blank box headed "Type the location of the item:"

Cut and paste the following line if you use Firefox as your browser:

"C:\Program Files\DropMyRights\DropMyRights.exe" "C:\Program Files\Mozilla Firefox\firefox.exe"

Cut and paste the following line if you use Internet Explorer as your browser:

"C:\Program Files\DropMyRights\DropMyRights.exe" "C:\program files\internet explorer\iexplore.exe"
6. Click "Next" and enter an appropriate name for your Shortcut for example "Safe Firefox" or "Limited User Internet Explorer" then click "Finish."

That's it. You now should have a desktop shortcut that when clicked starts up your browser with limited rights.
If it doesn't work then it's possible your browser is not installed in the default location. If so edit the shortcut settings to point to the correct location for your browser.

Browsing with limited rights is not really any different to browsing normally except that it's way safer. Some operations that require admin rights may not work but if you run into these problems then you can start your normal browser with full admin rights to complete whatever operation you were attempting. That's a small price to pay for avoiding infection.

D. Running other internet facing applications using DropMyRights
The procedure for running your email program, IM client, media player and other internet based applications using DropMyRights is essentially the same as that for your browser that I outlined in section C above.

What differs is the command line you use in step 5.

The exact command line you use is different for every program but there's an easy way to work out what that command line is for any program. You do this by using the shortcut or program icon you use to launch the program.

For a hostile website to install malware on your PC the malware must have access to full "administrator" rights on your PC. That's not normally a problem as most Windows users operate with full administrative privileges; its the default setup for users in all Windows systems prior to Vista.

By denying malware access to administrator rights you can prevent it from installing. The easiest way to do this is to use a limited rights Windows user account rather than one full administrator privileges.

It sounds like a great idea but there are many practical problems using a limited user account. For example lots of simple routine tasks like changing the system clock, plugging in a USB drive, running a defragger and updating software can't be carried out in a limited user account.

An alternative approach and more practical is to adopt the converse policy, that is, to routinely use an administrator account with full rights but reduce the privileges just of your web browser and other risky programs. It's a strategy that offers fewer inconveniences than running a limited user account at the cost of a slightly lower level of security.

Several free tools are available that allow you run your browser and other specified programs with reduced privileges. Best known is Microsoft's own DropMyRights which works with Windows XP and above.

Using DropMyRights is quite easy. In essence you use the program to create a desktop shortcut to a special version of your browser that operates with limited privileges. To surf safely you just click the desktop icon.  If you want to use your browser normally with full administrator privileges then just start your browser the normal way.

The instructions for installing and using DropMyRights with Internet Explorer on the author's site are a bit cryptic for beginners so I've created a fuller version below:

1. Download DropMyRights from here It's only a tiny 164KB file so it should download in just a few seconds.

2. Locate the downloaded file DropMyRights.msi and double click it to start the install. Accept the EULA and click "Next"

3. When asked the location of the installation folder cut and paste the following line into the box and then click "Next" and then "Close."

C:\Program Files\DropMyRights

4. Right click on your Desktop and select New / Shortcut

5. In the first screen of the shortcut wizard cut and paste one of the following lines into the blank box headed "Type the location of the item:"

Cut and paste the following line if you use Firefox as your browser:

"C:\Program Files\DropMyRights\DropMyRights.exe" "C:\Program Files\Mozilla Firefox\firefox.exe"

Cut and paste the following line if you use Internet Explorer as your browser:

"C:\Program Files\DropMyRights\DropMyRights.exe" "C:\program files\internet explorer\iexplore.exe"

6. Click "Next" and enter an appropriate name for your Shortcut for example "Safe Firefox" or "Limited User Internet Explorer" then click "Finish."

That's it. You now should have a desktop shortcut that when clicked starts up your browser with limited rights.
If it doesn't work then it's possible your browser is not installed in the default location. If so edit the shortcut settings to point to the correct location for your browser.

Browsing with limited rights is not really any different to browsing normally except that it's way safer. Some operations that require admin rights may not work but if you run into these problems then you can start your normal browser with full admin rights to complete whatever operation you were attempting. That's a small price to pay for avoiding infection.

D. Running other internet facing applications using DropMyRights

The procedure for running your email program, IM client, media player and other internet based applications using DropMyRights is essentially the same as that for your browser that I outlined in section C above.

What differs is the command line you use in step 5.
The exact command line you use is different for every program but there's an easy way to work out what that command line is for any program. You do this by using the shortcut or program icon you use to launch the program.


5. In the Target box you will see an entry similar to the following:
"C:\Program Files\Outlook Express\msimn.exe"
This is the name and location of the actual Outlook Express program. What we need to do is prefix this with the command that runs the DropMyRights program.  Here's the command below. Copy it now and in the next step we will paste it.

"C:\Program Files\DropMyRights\DropMyRights.exe"

6. Left Click on the very first position in the Target box, just to the left of the "C:\... and paste the DropMyRights command you copied in the last step.  Make sure there is exactly one space between the line you pasted and the original contents of the target box.  If done correctly your Target box line should now look like this:

"C:\Program Files\DropMyRights\DropMyRights.exe" "C:\Program Files\Outlook Express\msimn.exe"
Note the space between " "

7. Click "Apply" then "OK" and the window should close.

8. One last step. Rename the copied desktop icon to something like "Safe Outlook Express" or "Outlook Express - Limited User."
9 That's it. Your copied icon when clicked will now launch Outlook Express with the restricted rights of a Windows limited user.  In the future collect your mail by using this safe version of Outlook Express and you'll be much better protected from email borne infections.


This example uses the icon for Outlook Express but the same approach can be used to create safe versions of all your applications that use the internet.