Welcome Guest ( Log In | Register )

Outline · [ Standard ] · Linear+

 TM Hijacking DNS and injecting ads!

views
     
TSDrewkk
post Sep 13 2018, 02:47 AM, updated 8y ago

New Member
*
Newbie
7 posts

Joined: Sep 2018
I noticed today that unresolved domains and 404 errors on websites without SSL/TLS are getting hijacked by ads!!!!

https://imgur.com/a/6FDuBgc

WTH?

The site behind the ads is http://www.zygy.com which boasts TM as a customer.

This post has been edited by Drewkk: Sep 13 2018, 02:55 AM
SilentVampire
post Sep 13 2018, 02:56 AM

Networking Enthusiast
*******
Senior Member
5,714 posts

Joined: Mar 2007



Change DNS to Google DNS, Cloudflare DNS, or OpenDNS. Everyone who knows how TM works have not used TM DNS for a long time.

They have been doing this shit for a long time.

This post has been edited by SilentVampire: Sep 13 2018, 02:57 AM
TSDrewkk
post Sep 13 2018, 02:57 AM

New Member
*
Newbie
7 posts

Joined: Sep 2018
QUOTE(SilentVampire @ Sep 13 2018, 02:56 AM)
Change DNS to Google DNS, Cloudflare DNS, or OpenDNS. No one who knows TM uses TM DNS anymore.

They have been doing this shit for a long time.
*
Doesn't work. I already use CloudFlare 1.1.1.1 also tried Google 8.8.8.8 and 8.8.4.4

This post has been edited by Drewkk: Sep 13 2018, 02:58 AM
SilentVampire
post Sep 13 2018, 02:58 AM

Networking Enthusiast
*******
Senior Member
5,714 posts

Joined: Mar 2007



QUOTE(Drewkk @ Sep 13 2018, 02:57 AM)
Doesn't work. I already use CloudFlare 1.1.1.1 also tried Google 8.8.8.8 and 8.8.4.4
*
You sure? Changed both on WAN page and DHCP page? What router are you using?
TSDrewkk
post Sep 13 2018, 02:59 AM

New Member
*
Newbie
7 posts

Joined: Sep 2018
QUOTE(SilentVampire @ Sep 13 2018, 02:58 AM)
You sure? Changed both on WAN page and DHCP page? What router are you using?
*
Ubiquiti USG
Only thing that bypassed it is using a VPN either to Australia, America or KL office which is TIME.
soonwai
post Sep 13 2018, 03:04 AM


********
All Stars
11,456 posts

Joined: Oct 2007
From: KL


QUOTE(Drewkk @ Sep 13 2018, 02:47 AM)
I noticed today that unresolved domains and 404 errors on websites without SSL/TLS are getting hijacked by ads!!!!

https://imgur.com/a/6FDuBgc

WTH?

The site behind the ads is http://www.zygy.com which boasts TM as a customer.
*
LOL, you're right. Every DNS query to 1.9.1.9 for a non-existent domain returns 202.71.99.195.

Never noticed it as I wasn't using TM's DNS. Good find.
Anime4000
post Sep 13 2018, 03:09 AM

Look at all my stars!!
*******
Senior Member
2,399 posts

Joined: Jul 2009
From: /dev/null


on my test, TM do Hijack DNS query.

Attached Image

but... on Windows 10, dont have, maybe DNSSEC ?

it is allowed to Hijack customer traffic ? like replace HTTPS to HTTP ?

This post has been edited by Anime4000: Sep 13 2018, 03:11 AM
faizyunus
post Sep 13 2018, 07:31 AM

Casual
***
Junior Member
443 posts

Joined: Feb 2014
QUOTE(Drewkk @ Sep 13 2018, 02:57 AM)
Doesn't work. I already use CloudFlare 1.1.1.1 also tried Google 8.8.8.8 and 8.8.4.4
*
Try run DNS Leak Test to see if your DNS requests are being intercepted/leaked.
https://www.dnsleaktest.com/
TSDrewkk
post Sep 13 2018, 10:47 AM

New Member
*
Newbie
7 posts

Joined: Sep 2018
This seems pretty recent too, maybe in the last week or so they started doing this.

What for pay them 300rm each month just to get ads?
jbmsia
post Sep 13 2018, 11:02 AM

New Member
*
Junior Member
37 posts

Joined: Aug 2017
QUOTE(Drewkk @ Sep 13 2018, 02:57 AM)
Doesn't work. I already use CloudFlare 1.1.1.1 also tried Google 8.8.8.8 and 8.8.4.4
*
Are you using the router provided by TM?


TSDrewkk
post Sep 13 2018, 11:15 AM

New Member
*
Newbie
7 posts

Joined: Sep 2018
QUOTE(jbmsia @ Sep 13 2018, 11:02 AM)
Are you using the router provided by TM?
*
No, I'm using a Ubiquiti USG.
SilentVampire
post Sep 13 2018, 12:59 PM

Networking Enthusiast
*******
Senior Member
5,714 posts

Joined: Mar 2007



QUOTE(Drewkk @ Sep 13 2018, 11:15 AM)
No, I'm using a Ubiquiti USG.
*
My router is not doing that. You are still on TM DNS, otherwise, you won't be affected by it. Check your device and see if they are on TM DNS. I suspect that they are, as I am not getting this message.
Anime4000
post Sep 13 2018, 01:45 PM

Look at all my stars!!
*******
Senior Member
2,399 posts

Joined: Jul 2009
From: /dev/null


QUOTE(SilentVampire @ Sep 13 2018, 12:59 PM)
My router is not doing that. You are still on TM DNS, otherwise, you won't be affected by it. Check your device and see if they are on TM DNS. I suspect that they are, as I am not getting this message.
*
doesn't matter if TM DNS, they still modify Unprotected DNS Query. need DNSSEC compatible router
miloaisdino
post Sep 13 2018, 02:06 PM

Regular
******
Senior Member
1,418 posts

Joined: Jul 2015
Or just flash custom firmware on yr router with dnssec. Or worse case get a spare pc/raspberry pi run private dns relay..

Or maybe the 'parental control' settings, block the ip 202.71.99.195

This post has been edited by miloaisdino: Sep 13 2018, 02:07 PM
SilentVampire
post Sep 13 2018, 02:27 PM

Networking Enthusiast
*******
Senior Member
5,714 posts

Joined: Mar 2007



QUOTE(Anime4000 @ Sep 13 2018, 01:45 PM)
doesn't matter if TM DNS, they still modify Unprotected DNS Query. need DNSSEC compatible router
*
True, forgot about that bangwall.gif DNSSEC is still the way to go, for ‘secure’ DNS queries.
Anime4000
post Sep 13 2018, 09:57 PM

Look at all my stars!!
*******
Senior Member
2,399 posts

Joined: Jul 2009
From: /dev/null


QUOTE(SilentVampire @ Sep 13 2018, 02:27 PM)
True, forgot about that  bangwall.gif DNSSEC is still the way to go, for ‘secure’ DNS queries.
*
yeah, OP said only works on VPN, I pretty sure his router dont have DNSSEC, nowadays DNS also work in TCP
LeonTan
post Sep 14 2018, 10:50 AM

**SHINE**
*******
Senior Member
2,157 posts

Joined: Jul 2006
From: Kuala Lumpur



no wonder sometimes I thought why recently so many ads rclxub.gif
pcbase
post Sep 15 2018, 10:52 AM

Regular
******
Senior Member
1,411 posts

Joined: Dec 2004
From: Batu Pahat


after force to reduce unifi price, TM found a way to make money.
Hezegroth
post Sep 15 2018, 12:09 PM

Miqo'te
****
Senior Member
570 posts

Joined: May 2009



Yeah hope they can now reduce streamyx price.
GOPI56
post Sep 15 2018, 12:13 PM

Regular
******
Senior Member
1,494 posts

Joined: Dec 2012
Use Cloud Flare DNS or Google DNS to solve this problem. TM is earning side money by injecting ads.

2 Pages  1 2 >Top
 

Change to:
| Lo-Fi Version
0.0191sec    0.49    6 queries    GZIP Disabled
Time is now: 3rd December 2025 - 07:46 PM