  lilhurricane Crunchin' For Cures Premium,Mod join:2003-01-11 Purple Zone clubs: 
·Comcast
Host: TV over IP Software RCN Inside Insight Team Discovery
| reply to redrebel Re: Kerio Personall Firewall v2.1.5 & KB951748? Kerio forum?
said by redrebel :I'm one of the minority that still uses KPF v2.1.5 (desktop and laptop) You aren't the "only" one 
This plus BlitzenZeus 's ruleset work well for me..multiple browsers..
No issues as yet  -- ~Safe Hex~ Team Discovery ~ Project Hope ~ Like A Hurricane~ |
|
  NetFixer Freedom is NOT Free Premium join:2004-06-24 Murfreesboro, TN
·Vonage
·AT&T Southeast
·Cingular Wireless
·AT&T CallVantage
| reply to Curiosity said by Curiosity :Why is changing the local port range going to make DNS more secure? What is the idea behind that? Try doing a Google or Yahoo! search for DNS spoofing and you will find a lot of answers to your question. Here is a sample link from such a search, I hope some of the results you get will match your technical knowledge level, since I don't know exactly how high or low to shoot.
From SANS Internet Storm Center: Multiple Vendors DNS Spoofing Vulnerability -- We can never have enough of nature. We need to witness our own limits transgressed, and some life pasturing freely where we never wander. Test your firewall. |
|
 Curiosity
join:2001-10-01 Dawson Creek, BC
| reply to redrebel said by redrebel :I'm one of the minority that still uses KPF v2.1.5 (desktop and laptop) and yes when I installed the dreaded KB951748 it knocked out IE and Firefox for me. Looking at my logs it was using highports for DNS resolution. I had it specifically set to only use the range of 1024-5000. Made the change to allow highports (1024-65535) and it works fine (desktop only). Why is changing the local port range going to make DNS more secure? What is the idea behind that? |
|
  antdude A Ninja Ant Premium,VIP join:2001-03-25
1 edit | reply to redrebel said by redrebel :I'm one of the minority that still uses KPF v2.1.5 (desktop and laptop) and yes when I installed the dreaded KB951748 it knocked out IE and Firefox for me. Looking at my logs it was using highports for DNS resolution. I had it specifically set to only use the range of 1024-5000. Made the change to allow highports (1024-65535) and it works fine (desktop only). On the laptop I said forget it and uninstalled the patch and will wait to figure out what happens next. Hmm, DNS? I wonder if Explorer is calling out even though I use hosts and my old Netgear RT311 router (firmware from 2002 or so). I do use LAN file sharing with a Linux/Debian box (Samba). What's the rule called for this DNS resolution? -- Ant @ »antfarm.ma.cx and »aqfl.net. Please do not IM/e-mail me for technical support. Use the forum! Disclaimer: The views expressed in this posting are mine, and do not necessarily reflect the views of my employer |
|
 redrebel
join:2001-12-06 Oxnard, CA
1 edit | reply to antdude I'm one of the minority that still uses KPF v2.1.5 (desktop and laptop) and yes when I installed the dreaded KB951748 it knocked out IE and Firefox for me. Looking at my logs it was using highports for DNS resolution. I had it specifically set to only use the range of 1024-5000. Made the change to allow highports (1024-65535) and it works fine (desktop only). On the laptop I said forget it and uninstalled the patch and will wait to figure out what happens next. |
|