Welcome Guest ( Log In | Register )

Bump Topic Topic Closed RSS Feed
495 Pages « < 254 255 256 257 258 > » Bottom

Outline · [ Standard ] · Linear+

Unifi Official TM UniFi High Speed Broadband Thread V42, READ 1ST PAGE FOR RELEVANT WIFI INFO!

views
     
The.Lucas.DaY
post Sep 3 2024, 10:33 PM

On my way
****
Junior Member
671 posts

Joined: May 2019

QUOTE(soonwai @ Sep 3 2024, 09:33 PM)
Ya weird, maybe caching. But here Quad9 working with ml.iherb.com. IP addresses should 172.64.149.245 & 104.18.38.11.

wai57 try a bit later, see if you access https://ml.iherb.com.
*
Btw, why is actually a pharmacy online shop need to be blocked? confused.gif
soonwai
post Sep 3 2024, 10:34 PM


********
All Stars
11,459 posts

Joined: Oct 2007
From: KL


QUOTE(PRSXFENG @ Sep 3 2024, 10:27 PM)
So that's how Quad9 got by unaffected tongue.gif
*
now u jinxed it. :-)

Anyway:
Cleanbrowsing-Family kena kaw kaw.
Cleanbrowsing-Adult only 1 of 2 IPs kena.
Cleanbrowsing-Security not affected.
dev/numb
post Sep 3 2024, 10:35 PM

On my way
****
Junior Member
691 posts

Joined: Nov 2021
Heads up for anyone using free NextDNS accounts for ad/tracker blocking. Remember to tick the 3 boxes in the Performance sub-section under the Settings tab. Especially the Cache Boost option, because without that you will likely reach your 300k query limit sooner than you realize. Also, the anexia-kul and premiumdrp-kul are (historically) the best local servers for us wrt latency.


QUOTE(The.Lucas.DaY @ Sep 3 2024, 10:33 PM)
Btw, why is actually a pharmacy online shop need to be blocked?   confused.gif
*
Pharmianaga cartel. Go check the prices of your basic vitamin supplements on iHerb and compare with the daylight robbery you’re charged at your local pharmacy. Of course, their excuse “for your safety”. Just like how all this DNS blocking/redirecting is “for your safety. Topkek, first time you hear that bareback DNS is safer. Next they’ll ask you to fuck without condoms.

This post has been edited by dev/numb: Sep 3 2024, 10:46 PM
countingcrows
post Sep 3 2024, 10:49 PM

Getting Started
**
Junior Member
260 posts

Joined: Feb 2023
QUOTE(dev/numb @ Sep 3 2024, 10:35 PM)
Pharmianaga cartel. Go check the prices of your basic vitamin supplements on iHerb and compare with the daylight robbery you’re charged at your local pharmacy.]
It's not blocked for me.

Using naked non-DOH plain jane 8.8.8.8 can still access iherb no problem.

soonwai
post Sep 3 2024, 10:52 PM


********
All Stars
11,459 posts

Joined: Oct 2007
From: KL


QUOTE(Quantum Geist @ Sep 3 2024, 10:33 PM)
Yours getting hijacked? How does it look like? dns respond from tm server instead of cleanbrowsing when tracert? or the browser drop the dns answers because dnssec not matching?
*
At the moment, I'm just looking at the answers, if 175.139.142.25, the IP that TM returns for blocked sites then confirm the DNS has been hijacked.

For CleanBrowsing-Adult, the DNS IPs are 185.228.168.10 & 185.228.168.11. 10 is hijacked and 11 is not. (Of course, don't test with adult sites since they are blocked by this DNS)

10 has a ping of 4ms while 11 has a ping of 70ms. I bet a traceroute will show that 10 never goes out of TM's network. 11 goes to SG, I think.

This post has been edited by soonwai: Sep 3 2024, 10:52 PM
dev/numb
post Sep 3 2024, 10:56 PM

On my way
****
Junior Member
691 posts

Joined: Nov 2021
QUOTE(countingcrows @ Sep 3 2024, 10:49 PM)
It's not blocked for me.

Using naked non-DOH plain jane 8.8.8.8 can still access iherb no problem.
*
They just don’t deem it “evil” enough to hijack/redirect 8.8.8.8 queries. Not “evil” like Uncle Murray who they deem enemy of the state for some reason.. You can try turning off 8.8.8.8 and using ISP DNS and see if it loads. I know during the height of Covid it wouldn’t load under TM’s own DNS. But after iHerb created a ml.iherb domain for us I’m not sure if any alternative DNS was ever truly needed.

This post has been edited by dev/numb: Sep 3 2024, 10:57 PM
soonwai
post Sep 3 2024, 11:08 PM


********
All Stars
11,459 posts

Joined: Oct 2007
From: KL


QUOTE(countingcrows @ Sep 3 2024, 10:49 PM)
It's not blocked for me.

Using naked non-DOH plain jane 8.8.8.8 can still access iherb no problem.
*
Are you in a location other Klang Valley? TNG55 in Penang not affected. Seems like only certain regions for now.

Anyway for me, Kajang:
dig ml.iherb.com @8.8.8.8
returns
175.139.142.25

Legit IPs should be:
172.64.149.245
104.18.38.11

QUOTE(dev/numb @ Sep 3 2024, 10:56 PM)
They just don’t deem it “evil” enough to hijack/redirect 8.8.8.8 queries. Not “evil” like Uncle Murray who they deem enemy of the state for some reason.. You can try turning off 8.8.8.8 and using ISP DNS and see if it loads. I know during the height of Covid it wouldn’t load under TM’s own DNS. But after iHerb created a ml.iherb domain for us I’m not sure if any alternative DNS was ever truly needed.
*
TM not just hijacking DNS queries though. They're rerouting & NATting 8.8.8.8 to their own server. Go to https://8.8.8.8 and you can see their dns.tm.net.my SSL cert.

This post has been edited by soonwai: Sep 3 2024, 11:21 PM
biatche
post Sep 3 2024, 11:11 PM

Regular
******
Senior Member
1,649 posts

Joined: Jan 2003
anyone facing severe lag in games, particularly at night?
Epic_winner091
post Sep 3 2024, 11:31 PM

Casual
***
Junior Member
342 posts

Joined: Mar 2010
From: Shah Alam


user posted image

No problems with DoH here, on Chrome.
countingcrows
post Sep 3 2024, 11:34 PM

Getting Started
**
Junior Member
260 posts

Joined: Feb 2023
QUOTE(soonwai @ Sep 3 2024, 11:08 PM)
Are you in a location other Klang Valley?
Anyway for me, Kajang:
dig ml.iherb.com @8.8.8.8
returns
175.139.142.25

Legit IPs should be:
172.64.149.245
104.18.38.11
Ya, PJ, Klang Valley.

104.18.38.11
PJng
post Sep 3 2024, 11:38 PM

10k Club
********
All Stars
12,061 posts

Joined: Oct 2017


QUOTE(PRSXFENG @ Sep 3 2024, 10:27 PM)
So that's how Quad9 got by unaffected tongue.gif
*
just know got another DNS, so far i tested now, before this all the time using 1.1.1.1 DNS, cannot load murray site, DNS leak test all show TM
i change to quad9 DNS, can load murray site and above iherb, and DNS leak test

user posted image

yes i using windows 11, ON auto template DNS over HTTPS (this what you all say DoH right?)
soonwai
post Sep 3 2024, 11:45 PM


********
All Stars
11,459 posts

Joined: Oct 2007
From: KL


QUOTE(PJng @ Sep 3 2024, 11:38 PM)
just know got another DNS, so far i tested now, before this all the time using 1.1.1.1 DNS, cannot load murray site, DNS leak test all show TM
i change to quad9 DNS, can load murray site and above iherb, and DNS leak test

user posted image

yes i using windows 11, ON auto template DNS over HTTPS (this what you all say DoH right?)
*
Yup, same as me. I use Q9. I suspect Quad9 also will be gone soon.
PJng
post Sep 3 2024, 11:47 PM

10k Club
********
All Stars
12,061 posts

Joined: Oct 2017


QUOTE(soonwai @ Sep 3 2024, 11:45 PM)
Yup, same as me. I use Q9. I suspect Quad9 also will be gone soon.
*
sadly cannot set on router, using tp link ax20
issac99289928
post Sep 3 2024, 11:52 PM

Getting Started
**
Junior Member
291 posts

Joined: Sep 2016
From: muar, johor


the authority is just dealing with non sophisticated internet users . if you are not using any of these dns , you are probably OK. the sophisticated internet users use other DNS not seen in the image.

user posted image

This post has been edited by issac99289928: Sep 3 2024, 11:56 PM
soonwai
post Sep 3 2024, 11:58 PM


********
All Stars
11,459 posts

Joined: Oct 2007
From: KL


Another way to check is to go to https://dns.google. Nothing to do with DNS queries here.

If All your 8888s are belongs to TM, you'll see this:
user posted image
You can also click Advanced to look at the SSL cert.

If A-OK then:
user posted image

*Using Firefox.

This post has been edited by soonwai: Sep 3 2024, 11:59 PM
countingcrows
post Sep 4 2024, 12:00 AM

Getting Started
**
Junior Member
260 posts

Joined: Feb 2023
QUOTE(issac99289928 @ Sep 3 2024, 11:52 PM)
the authority is just dealing with non sophisticated internet users . if you are not using any of these dns , you are probably OK. the sophisticated internet users other DNS not seen in the image.
Let's hope they employ the 80/20 rule

Block 80% with only 20% effort 👍 😉


Q9 seems fine. ~10ms.

user posted image
soonwai
post Sep 4 2024, 12:06 AM


********
All Stars
11,459 posts

Joined: Oct 2007
From: KL


QUOTE(countingcrows @ Sep 3 2024, 11:34 PM)
Ya, PJ, Klang Valley.

104.18.38.11
*
So far we got:

Kajang ❌❌
Kuching ✅
Penang ✅
PJ ✅✅

This post has been edited by soonwai: Sep 4 2024, 01:18 AM
karenzayn
post Sep 4 2024, 12:11 AM

Getting Started
**
Junior Member
98 posts

Joined: Sep 2019
From: Kuching
QUOTE(soonwai @ Sep 4 2024, 12:06 AM)
So far we got:

Kajang ❌❌
Penang ✅
PJ ✅
*
Uh, quick question
Do i run dig on a DoH or non-DoH enviroment?
Pip_X
post Sep 4 2024, 12:11 AM

Got miao miao jor.
*******
Senior Member
2,465 posts

Joined: Jan 2003
From: Bukit Jalil, migrated to Paldea.



QUOTE(soonwai @ Sep 3 2024, 10:01 PM)
DoH in Chrome/Edge with which server?

Update:
LOL, TM hijacked cleanbrowsing DNS also. Looks like when they needed a guide on what to hijack, they looked at Chrome's Settings. hahaha

Chrome has Google, OpenDNS, Cloudflare and CleanBrowsing as predefined options for DoH.
*
Adguard's https://dns.adguard-dns.com/dns-query
blackbox14
post Sep 4 2024, 12:18 AM

Casual
***
Junior Member
349 posts

Joined: Jul 2012
So given what they are doing blocks even DoH, will that Amazon AWS wall climbing method still work even when using cloudflare-dns.com or dns.google as the origin?

495 Pages « < 254 255 256 257 258 > » Top
Topic ClosedOptions
 

Change to:
| Lo-Fi Version
0.0197sec    0.33    6 queries    GZIP Disabled
Time is now: 22nd December 2025 - 08:00 AM