HOTS Hosts is an open-source Windows utility for managing the system hosts file, parental controls, application blocking, DNS configuration, and privacy-related Windows settings.
Because some features make system-level changes and require Administrator privileges, security issues are taken seriously.
The source code is publicly available in this repository.
If you believe you have found a security vulnerability in HOTS Hosts, please do not disclose sensitive details publicly before contacting the maintainer.
Please report security issues privately by email:
Where possible, include:
- HOTS Hosts version
- Windows version
- affected feature or component
- clear description of the issue
- steps to reproduce
- expected and actual behavior
- screenshots, logs, or proof-of-concept information if relevant
Please do not include passwords, personal data, or other sensitive information that is not necessary to reproduce the issue.
Examples of security issues include:
- unintended privilege escalation
- arbitrary code execution
- bypasses of parental-control restrictions
- unauthorized modification of protected files or registry settings
- unsafe handling of Administrator privileges
- insecure file or configuration handling
- vulnerabilities that could allow another local application or user to abuse HOTS Hosts
General bugs, usability problems, false positives from diagnostic heuristics, and feature requests can be reported through GitHub Issues instead.
HOTS Hosts performs legitimate system-level operations because that is required for several of its features.
The application is not designed to defend a system against a user or attacker who already has unrestricted Administrator privileges.
In particular, parental-control features are intended primarily to reduce casual or inexperienced bypass attempts. They should not be considered an enterprise-grade security boundary.
Security fixes are primarily intended for the latest released version.
| Version | Security support |
|---|---|
| Latest release | Supported |
| Older releases | Best effort |
| Development versions | Not guaranteed |
Users are encouraged to update to the latest release.
Depending on which features are enabled, HOTS Hosts may modify:
- the Windows
hostsfile - DNS configuration
- Windows Firewall rules
- Windows Services
- Windows Scheduled Tasks
- Windows Registry policies
- file-system ACLs
- Image File Execution Options (IFEO)
- Windows System Restore configuration
To do this, the application calls built-in Windows tools: powershell.exe (file ACLs), netsh.exe (firewall rules and DNS configuration), sc.exe (services) and net.exe. Program settings are stored per user in %APPDATA%\HOTS Hosts; the state of feature toggles that must survive a reinstall (hosts file lock, application blocking, restore-point blocking) is kept in %ProgramData%\HOTS Hosts.
These operations are intentional parts of the application.
Users should review the documentation and source code before enabling system-level features they do not need.
HOTS Hosts does not require an online account for normal operation.
The application is designed primarily to operate locally.
Features that can involve network communication include, depending on the action performed:
- the built-in update checker, which contacts GitHub Releases to look for newer versions — by default it runs automatically at startup and can be switched off on the About page
- the domain-existence diagnostic, which sends the host names from your
hostsfile as DNS queries to a public resolver (Google Public DNS,8.8.8.8); before the scan it also tests connectivity with short TCP connections to public DNS servers (1.1.1.1,8.8.8.8,1.0.0.1, port 53) - DNS configuration changes when the user enables Cloudflare Family DNS: the app points the network adapter's DNS servers to Cloudflare's filtered resolvers (
1.1.1.3/1.0.0.3) instead of the previous servers, which sends future DNS lookups from that device to Cloudflare - any network activity initiated by Windows or third-party components affected by the user's configuration
This project does not claim that every network request generated by Windows itself can be attributed to HOTS Hosts.
The application writes a local diagnostic log (error.log) to %APPDATA%\HOTS Hosts. It stays on your computer and is not sent anywhere. Please review it before attaching it to a public issue.
Where a feature supports rollback, HOTS Hosts may save the previous state before applying a change.
Users should still maintain independent system backups and should consider creating a Windows System Restore point before making substantial configuration changes.
Since this update, uninstalling HOTS Hosts first shows an "Are you sure?" prompt reminding you that installing a newer version does not require uninstalling first (just run the new installer directly — it updates the program in place without touching your settings, password or blocklists). This prompt, and the password check that follows if startup password protection is enabled (three attempts; no changes are made if verification fails or is cancelled), are both shown in whichever language the application is currently set to.
After that, a small wizard lets you choose what to do with the changes HOTS Hosts made to your system. Some cleanup always happens regardless of your choices, because leaving it undone would break the system rather than just leave a preference in place; everything else is optional and off unless the wizard says otherwise.
Always removed, regardless of your choices in the wizard:
- the hosts file lock (the deny-write ACL entry for the Users group on the
hostsfile) - the file-lock ACL entries and Image File Execution Options (IFEO) redirection created by application blocking, VPN client blocking, and the System Restore block
- the application's registry keys, including the stored password hash
This runs unconditionally because an orphaned ACL lock or an IFEO entry pointing at a deleted executable would leave the system broken, not just "still configured".
Optional, selected individually in the uninstall wizard (unchecked options are left as they are):
- Domain-blocking configuration — removes only the hosts entries HOTS Hosts itself added (matched by internal markers; entries you or another program added manually are never touched), lifts the DNS-over-HTTPS Group Policy override for Chrome, Edge, Brave and Firefox, and restores the network adapter's original DNS servers if Cloudflare Family DNS was enabled. Checked by default.
- Windows privacy settings — reverts whichever Privacy-tools changes are currently active (services, scheduled tasks, the three
HOTS_AntiSpy_*firewall rules, registry policy values) back to their previous state. Unchecked by default, since some users want to keep these hardened regardless of whether the app is still installed. - Saved configuration — deletes the application's data folders (
%ProgramData%\HOTS Hostsand%APPDATA%\HOTS Hosts). Checked by default. - Custom domain list — deletes
custom_domains.txt(the list typed in under "Block your own domains"), which lives next to thehostsfile indrivers\etc. Unchecked by default: the application promises that this list survives uninstalling, so you can reuse it after reinstalling. Removing the domain blocks from thehostsfile does not delete this list. - Hosts file backups — deletes the automatic backups HOTS Hosts created in the same folder as the
hostsfile (hosts.bak_*). Checked by default when any exist.
Anything left unchecked stays on the computer after HOTS Hosts is removed — for example, if you leave "Domain-blocking configuration" unchecked, the blocked domains keep being blocked by the hosts file even with the app gone, until you remove them yourself.
Running the installer over an existing installation (whether to update or repair) first asks Windows to close any running instance of HOTS Hosts, then deletes the entire installation folder before copying the new files. This is intentional: the installation folder never contains user data (settings, password, blocklists and backups all live outside it, in %ProgramData% and %APPDATA%, and are never touched by this), and it avoids leaving orphaned files behind from older versions (for example, a renamed or removed DLL from a previous build).
Please allow reasonable time for investigation and remediation before publicly disclosing a confirmed vulnerability.
Security reports help improve HOTS Hosts and are appreciated.