Page 3 of 5

Re: cant block updates on router level

Posted: Sat Nov 26, 2016 8:06 pm
by sectroyer
You know what you have to do to block updates :)

Re: cant block updates on router level

Posted: Sat Nov 26, 2016 11:58 pm
by Zamzung
sectroyer wrote:You know what you have to do to block updates :)
Well I've screwed it up too :cry:
Blocked the four domains on my Avm-Fritz router before first powering on the tv (tested with browser - no access) and stayed on 1412 almost one year.
Don't know if recently updated user manual triggered it or something else, but unattended tv updated itself to 1460...
Tested further the blacklist function on my router and it still is doing dns for blocked domains, they are still pingable and traceroute for them is also possible. :(

Don't know if my router manufactor will fix the issue in the next firmware version (mailed them about only blocking port 80), but until then I've added a subnet (router cascading) with another very old router which is blocking everything for forbidden domains.

So DON'T TRUST THE CORRECT BLOCKING OF YOUR ROUTER only by checking it with a browser, test it at least with a computer doing ping and tracert for example!

Correct blocking results with an error message if you are trying to update your samsung manually via menu.

Re: cant block updates on router level

Posted: Sun Nov 27, 2016 8:59 pm
by oto
sectroyer wrote:You know what you have to do to block updates :)
But I use it for IPTV so would like to still use Internet :cry: . I am not sure that even unplugging the cord will help to avoid it and it won't update trough bluetooth or other dark links :o

Re: cant block updates on router level

Posted: Mon Nov 28, 2016 12:46 am
by notengo13
try this if you are able to download the file

Code: Select all

wget http://az43064.vo.msecnd.net/firmware/tv/267/SWU-OU_T-MST14DEUC-2800-151209/OUItem_1.dat
this is my output

Code: Select all

ag750jz@error404:~> wget http://az43064.vo.msecnd.net/firmware/tv/267/SWU-OU_T-MST14DEUC-2800-151209/OUItem_1.dat
--2016-11-28 00:39:25--  http://az43064.vo.msecnd.net/firmware/tv/267/SWU-OU_T-MST14DEUC-2800-151209/OUItem_1.dat
Resolving az43064.vo.msecnd.net (az43064.vo.msecnd.net)... 0.0.0.0, 2606:2800:133:672:1e5f:2264:1854:1189
Connecting to az43064.vo.msecnd.net (az43064.vo.msecnd.net)|0.0.0.0|:80... failed: Connection refused.
Connecting to az43064.vo.msecnd.net (az43064.vo.msecnd.net)|2606:2800:133:672:1e5f:2264:1854:1189|:80... failed: Network is unreachable.

Re: cant block updates on router level

Posted: Mon Nov 28, 2016 3:08 pm
by Borygo77
Guys use OpenDNS to block unwanted stuff like sammy updates ;)

Re: cant block updates on router level

Posted: Mon Nov 28, 2016 4:06 pm
by sectroyer
Borygo77 wrote:Guys use OpenDNS to block unwanted stuff like sammy updates ;)
From my experience it might not be enough...

Re: cant block updates on router level

Posted: Mon Nov 28, 2016 4:09 pm
by Borygo77
I didn't mention turning off OTN in service menu as this is obvious ;)

Re: cant block updates on router level

Posted: Mon Nov 28, 2016 5:10 pm
by zoelechat
Right, sectroyer should disable OTN ASAP :lol:

Well, blocking whole Internet access is definitely not a solution anyway, let's not make our TVs less smart than they already are.
It's possible that the (2) 2 years old (from H) known domains to block are simply not enough or not relevant anymore for J/K, either since Samsung is watching us, or just because they changed host.
Based on infos given by my router, some netstat, and traffic analysis from here, I tried to make some up-to-date "list of doubtful hosts".
For info, I use Tomato firmware on my router (available for shitloads models) which allows to block "URLs containing string", no idea which trick it uses internally then, I'm not expert but I just know it's very handy and efficient. No need to ask me about other router firmwares: I don't know :)

Let's share, I assume URLs are not only updates related, could be survey, ads, harmless or even needed by stuff I don't use, so the list is not exhaustive but only given as reference.
Here is strings list I currently block here (K series TV), and between brackets the remaining part of URL/domain it's supposed to block:

Code: Select all

(*.) msecnd (.net)
(*.) samsungotn (.net) 
otnprd (*.samsungcloudsolution.net/.com)
otnstg (*.samsungcloudsolution.net/.com)
(*.) samsungad (*.*)
(*.) deploy.akamaitechnologies (.com)
prderrordumphsm.samsungcloudsolution (.net/.com)
rmdev.samsungcloudsolution (.net/.com)
(*.) samsungelectronics (.com)
(*.) samsungrm (.net)
(*.) samsungacr (.com)
(*.) smartthings (.com)
104.20.21.219
104.20.22.219
Of course everybody's free to share his own experience and correct list if any URL is problematic or missing. I also do not guarantee that forced updates couldn't still occur, it's just my own blocklist (from which I removed Netflix/Amazon/Microsoft/... related crap). Have fun :)

Re: cant block updates on router level

Posted: Sat Dec 03, 2016 10:06 am
by Borygo77
Time to update some settings ;) thanks zoele! :)

Re: cant block updates on router level

Posted: Sat Dec 03, 2016 1:53 pm
by Zamzung
zoelechat wrote: [...] list if any URL is problematic or missing. [...]
Yeah thanks very much, I've added them to my blocking.
After my (unwanted :( ) update I found a new ip-adress being blocked: 62.157.140.133
Don't have any clue yet, if it might be harmful or if it's something app-related...

Edit: It seems to be a special service from my internet-provider, unresolvable dns queries are answered with this adress. Still can't explain why these are in my log for blocked sites... :o