Finally! A way to prune off useless TK domain blocks.I will have an new update tomorrow 2012-02-15 here:
http://securemecca.com/public/Changes4Hosts/2012-02-15.7zhttp://securemecca.com/public/Changes4Hosts/2012-02-15.7z.sigThere is a file in it that shows how to test the bad TK domain host
URLs for whether they are still bad. But I also put it here:
http://www.securemecca.com/Analysis/TK-Host-Test.txtThe Analysis folder is not open via the home page, but
everybody knows where the Analysis folder is at and what
is in it. There is nothing wrong with others knowing about it.
It really does answer how to test the TK domain hosts. But
with all of the stuff in the way like the following in the way
with Windows:
1. ISP - (Comcast Anti-Bot service)
2. Browser protection (and did you really turn it all off?)
3. AV protection - Kaspersky blocked the URLs I tested).
4. Internal Microsoft protection?
There is no guarantee that a block some place is not
skewing the tests. I think I have pretty well moved the
ISP out of the way (at least for these), and the others are
not even a problem on Linux. Even so I also did tests on
Windows and proved to my satisfaction the TK domain
wasn't doing OS detection and routing Windows people
one way and everybody else another way. We all go the
same way.
After all, the TK domain people don't want malware through
their redirection service either. They just want some money
for URLs that look like a domain when in fact they go to
something rather long some place else.
So you really need to run the script on Linux / Unix. No
C programs need to be written. You will want some
folder like the following:
drwxrwxrwt 10 root root 4096 2012-02-12 09:50 /home/tmp
I think it is all self explanatory. That does not mean that the
URLs stuffed into the BadTKs.txt are all bad. But we do have two
ways of finding the ones that are okay with just two simple grep
commands. More may be added in the future. Just remember,
I block searchdiscovered.com not because it has given malware,
but just because it is a tracker / park host. It has never given me
malware. In fact the tracking is so slight I may remove the block
of searchdiscovered.com. Also, all of the hot URLs at the TK domain
have never gone through searchdiscovered.com. The malware links
go many other places but not through there.
Finally! A way to prune off useless TK domain blocks.Good Enough? If not email me and I will fill in the gaps.