Re: [?]IP Blacklist

From: Karl Levinson [x y] mvp (levinson_k_at_despammed.com)
Date: 03/31/04


Date: Tue, 30 Mar 2004 20:32:43 -0500


"Mike Burgess" <winhelp2002@spamthis.com> wrote in message
news:#UxKJjqFEHA.3324@TK2MSFTNGP09.phx.gbl...

> > blocked unlike a HOST file becuase a HOST file only blocks outgoing"
> The HOSTS file blocks both directions, however you can not add IP
> addresses to the file. For that it's best to add them to your Firewall.

I believe it to be the opposite... you can add IP addresses to the hosts
file, but it will only block outbound connections, and only if the
connection is made via a regular name lookup and not via IP address. [A
user who looks up the name to IP address mapping can then access the site by
IP address... or that user may also be able to use an anonymizing proxy
server to access the site.]

For example, if the DoD wanted to do a SYN scan of your computer, adding DoD
to your hosts file would not prevent your computer from sending back a
response.

AFAIK it is true that you cannot add IP address *ranges* to the hosts file,
such as to block the entire DoD network.