Outline ·
[ Standard ] ·
Linear+
Unifi Official TM UniFi High Speed Broadband Thread V42, READ 1ST PAGE FOR RELEVANT WIFI INFO!
|
HayateAyakasi8
|
Sep 6 2024, 03:59 PM
|
|
QUOTE(kwss @ Sep 6 2024, 03:48 PM) Your DNS trick cannot defeat BGP. You need Anime4000 method where someone else provide him IP Transit to bypass that. Or just VPN Ah does this means that AWS trick won't work for this then?
|
|
|
|
|
|
dev/numb
|
Sep 6 2024, 04:00 PM
|
|
QUOTE(solarmystic @ Sep 6 2024, 02:37 PM) The conspiracy-tard in me doesn't think it's a coincidence that these "free upgrades" are being given out just as they're imposing more tighter controls to block public access to sites that would traditionally consume a lot of bandwidth lol.  Are you out of contract already? Maybe these so called free upgrades have some small print stating you’ll be tied to a new contract.
|
|
|
|
|
|
blacktubi
|
Sep 6 2024, 04:02 PM
|
-
|
QUOTE(yenchenje @ Sep 6 2024, 03:58 PM) Currently TM's BGP has fully blocked those? So no matter what DNS I use currently I can't access any of these, only way to access it is to let BGP route my traffic via non TM's gateway/IP correct? DNS job is to just resolve domain name into IP. dns.google resolves to 8.8.8.8 and 8.8.4.4 Both IP addresses are hijacked on BGP level. Just VPN, it's easier.
|
|
|
|
|
|
kingkingyyk
|
Sep 6 2024, 04:04 PM
|
10k Club
|
QUOTE(HayateAyakasi8 @ Sep 6 2024, 03:59 PM) Ah does this means that AWS trick won't work for this then? It works.  They are just sending your requests that are meant to reach well known DNS server (identified by IP address) to their server instead. In AWS you will get dynamic IP address and they will not be able to ban since you can easily switch to different IP and life continues as usual, and this is just not practical for them to do for personal service. This post has been edited by kingkingyyk: Sep 6 2024, 04:05 PM
|
|
|
|
|
|
PRSXFENG
|
Sep 6 2024, 04:04 PM
|
|
QUOTE(HayateAyakasi8 @ Sep 6 2024, 03:59 PM) Ah does this means that AWS trick won't work for this then? It works by You're not asking the DNS servers directly Instead you're asking your own Amazon server And then that asks for you and returns the info to you
|
|
|
|
|
|
rrrobot
|
Sep 6 2024, 04:04 PM
|
New Member
|
QUOTE(kwss @ Sep 6 2024, 03:51 PM) They are using Imperva for their website. No way they can do the same for DNS server, I thought my joke was pretty funny ;(
|
|
|
|
|
|
yenchenje
|
Sep 6 2024, 04:06 PM
|
|
QUOTE(blacktubi @ Sep 6 2024, 04:02 PM) DNS job is to just resolve domain name into IP. dns.google resolves to 8.8.8.8 and 8.8.4.4 Both IP addresses are hijacked on BGP level. Just VPN, it's easier. Okay that makes a lot more sense, guess that's the extent that I can do for now, VPN we go next
|
|
|
|
|
|
kwss
|
Sep 6 2024, 04:06 PM
|
|
QUOTE(HayateAyakasi8 @ Sep 6 2024, 03:59 PM) Ah does this means that AWS trick won't work for this then? Won't work. See blacktubi answer. But unless your job requires access to dns.google or one.one.one.one, I won't be too into it. But here's the thing, I am sensing the government is trying to break the internet slowly. Someday they will break all the VPN. EDIT: Clarification: Amazon can bypass DNS block. Amazon won't bypass BGP hijack. This post has been edited by kwss: Sep 6 2024, 04:11 PM
|
|
|
|
|
|
smallcrab
|
Sep 6 2024, 04:07 PM
|
Getting Started

|
QUOTE(annoymous1234 @ Sep 6 2024, 03:55 PM) I thought a few reported that this method doesn't work anymore? Oops, was actually using maxis wired broadband, not Unifi.
|
|
|
|
|
|
blacktubi
|
Sep 6 2024, 04:07 PM
|
-
|
QUOTE(kingkingyyk @ Sep 6 2024, 04:04 PM) It works.  They are just sending your requests that are meant to reach well known DNS server (identified by IP address) to their server instead. In AWS you will get dynamic IP address and they will not be able to ban since you can easily switch to different IP and life continues as usual, but this is just not practical to do for personal service. No, that AWS trick is just sorting out the DNS resolve part. But, the IP itself is hijacked on BGP now. You can't bypass that without the use of a VPN.
|
|
|
|
|
|
kingkingyyk
|
Sep 6 2024, 04:09 PM
|
10k Club
|
QUOTE(blacktubi @ Sep 6 2024, 04:07 PM) No, that AWS trick is just sorting out the DNS resolve part. But, the IP itself is hijacked on BGP now. You can't bypass that without the use of a VPN. Was talking about just the DNS resolve part.
|
|
|
|
|
|
XeactorZ
|
Sep 6 2024, 04:09 PM
|
|
QUOTE(overfloe @ Sep 6 2024, 12:21 PM) I just received this sms: "Hi. Do you know we've upgraded your account xxx@unifi to a higher speed for FREE? Your profile will be updated soon. Enjoy your new speed!"This legit? I am not aware Unifi is offering free upgrade recently. I can't test coz not at home at the moment. QUOTE(cyberic @ Sep 6 2024, 12:24 PM) received the same sms but no change in speed or plan name. same, back home only test the speed but then unifi website super lousy, keep login and said cannot retrieve my account info, please try again later
|
|
|
|
|
|
eddie_lim
|
Sep 6 2024, 04:12 PM
|
You Never Walk Alone
|
DNS poisoning is ISP work SSL hijacking from gomen is a very serious act of cyber security i am making sure every transaction i query go through SSL tunnels monitoring via tcpdump
This post has been edited by eddie_lim: Sep 6 2024, 04:14 PM
|
|
|
|
|
|
blackbox14
|
Sep 6 2024, 04:14 PM
|
|
QUOTE(kwss @ Sep 6 2024, 04:06 PM) Won't work. See blacktubi answer. But unless your job requires access to dns.google or one.one.one.one, I won't be too into it. But here's the thing, I am sensing the government is trying to break the internet slowly. Someday they will break all the VPN. EDIT: Clarification: Amazon can bypass DNS block. Amazon won't bypass BGP hijack. Very strange that they ask the data centers to invest and operate here then. Also, what are they so scared of that they are going this far? Btw, I asked this earlier in the morning when people were reporting more places kena: Which VPNS are affected so far besides Nord? Someone earlier posted that they couldn't download the client.
|
|
|
|
|
|
kwss
|
Sep 6 2024, 04:15 PM
|
|
QUOTE(rrrobot @ Sep 6 2024, 04:04 PM) I thought my joke was pretty funny ;( Aiks... Sorry bro. Really didn't get it QUOTE(XeactorZ @ Sep 6 2024, 04:09 PM) same, back home only test the speed but then unifi website super lousy, keep login and said cannot retrieve my account info, please try again later  Disable adblocker. QUOTE(eddie_lim @ Sep 6 2024, 04:12 PM) DNS poisoning is ISP work SSL hijacking from gomen is a very serious act of cyber security 100% agree!
|
|
|
|
|
|
Amaru
|
Sep 6 2024, 04:16 PM
|
|
IPv6 Google DNS still seems to be working for me. Unifi does not seem to be blocking the *ahem* websites.
|
|
|
|
|
|
maxpudding
|
Sep 6 2024, 04:16 PM
|
Getting Started

|
QUOTE(eddie_lim @ Sep 6 2024, 04:12 PM) DNS poisoning is ISP work SSL hijacking from gomen is a very serious act of cyber security i am making sure every transaction i query go through SSL tunnels monitoring via tcpdump
what are they scared of? this seem to be too extreme already
|
|
|
|
|
|
Raki
|
Sep 6 2024, 04:16 PM
|
|
My office in Klang was affected today QUOTE [2.7.2-RELEASE][root@office.internal]/root: traceroute 8.8.8.8 traceroute to 8.8.8.8 (8.8.8.8), 64 hops max, 40 byte packets 1 180.75.19.254 (180.75.19.254) 19.390 ms 1.148 ms 4.002 ms 2 10.55.51.29 (10.55.51.29) 7.584 ms * * 3 10.55.52.54 (10.55.52.54) 6.120 ms 10.55.52.90 (10.55.52.90) 7.401 ms 10.55.52.54 (10.55.52.54) 7.571 ms 4 10.19.129.65 (10.19.129.65) 29.452 ms 29.680 ms 30.643 ms 5 dns.google (8.8.8.8) 7.272 ms 9.369 ms 27.925 ms Anime4000's diagram gave me an idea to use our existing Site to Site VPN to tunnel to route just 8.8.8.8 and 8.8.4.4 QUOTE [2.7.2-RELEASE][root@office.internal]/root: traceroute 8.8.8.8 traceroute to 8.8.8.8 (8.8.8.8), 64 hops max, 40 byte packets 1 172.16.245.1 (172.16.245.1) 5.878 ms 3.512 ms 4.023 ms 2 * * * 3 103.2.80.9 (103.2.80.9) 4.302 ms 4.792 ms 3.939 ms 4 google.myix.my (218.100.44.92) 4.025 ms 12.943 ms 3.374 ms 5 192.178.98.231 (192.178.98.231) 8.419 ms 192.178.99.63 (192.178.99.63) 4.364 ms 192.178.98.151 (192.178.98.151) 5.334 ms 6 72.14.234.89 (72.14.234.89) 6.079 ms 216.239.48.121 (216.239.48.121) 5.579 ms 142.250.56.103 (142.250.56.103) 4.283 ms 7 dns.google (8.8.8.8) 3.421 ms 5.332 ms 3.625 ms at least, I still get sub 10ms response This post has been edited by Raki: Sep 6 2024, 04:19 PM
|
|
|
|
|
|
dev/numb
|
Sep 6 2024, 04:20 PM
|
|
QUOTE(Anime4000 @ Sep 6 2024, 01:55 PM) If your router has Wireguard support, just WG join because DNS only can be access via Wireguard Sorry bang, I tak paham. So the WireGuard tunnel is only for DNS queries but the rest (eg: loading site assets) of the packets are moving outside the tunnel?
|
|
|
|
|
|
solarmystic
|
Sep 6 2024, 04:26 PM
|
Getting Started

|
QUOTE(dev/numb @ Sep 6 2024, 04:00 PM) Are you out of contract already? Maybe these so called free upgrades have some small print stating you’ll be tied to a new contract. Good point! I'm actually not contracted anymore, haven't been for the past 4 years. Kept on getting those calls from telemarketers to get tied to a new one but i just ended up ignoring them after awhile, i like having the flexibility to bail out if necessary.
|
|
|
|
|