Welcome Guest ( Log In | Register )

Bump Topic Topic Closed RSS Feed
495 Pages « < 294 295 296 297 298 > » Bottom

Outline · [ Standard ] · Linear+

Unifi Official TM UniFi High Speed Broadband Thread V42, READ 1ST PAGE FOR RELEVANT WIFI INFO!

views
     
HayateAyakasi8
post Sep 6 2024, 03:59 PM

On my way
****
Junior Member
651 posts

Joined: Jun 2014


QUOTE(kwss @ Sep 6 2024, 03:48 PM)
Your DNS trick cannot defeat BGP.

You need Anime4000 method where someone else provide him IP Transit to bypass that.
Or just VPN
*
Ah does this means that AWS trick won't work for this then?
dev/numb
post Sep 6 2024, 04:00 PM

On my way
****
Junior Member
691 posts

Joined: Nov 2021
QUOTE(solarmystic @ Sep 6 2024, 02:37 PM)
The conspiracy-tard in me doesn't think it's a coincidence that these "free upgrades" are being given out just as they're imposing more tighter controls to block public access to sites that would traditionally consume a lot of bandwidth lol.

hmm.gif
*
Are you out of contract already? Maybe these so called free upgrades have some small print stating you’ll be tied to a new contract.
blacktubi
post Sep 6 2024, 04:02 PM

-
Group Icon
Elite
8,421 posts

Joined: Jul 2008

QUOTE(yenchenje @ Sep 6 2024, 03:58 PM)
Currently TM's BGP has fully blocked those?

So no matter what DNS I use currently I can't access any of these, only way to access it is to let BGP route my traffic via non TM's gateway/IP correct?
*
DNS job is to just resolve domain name into IP.

dns.google resolves to 8.8.8.8 and 8.8.4.4

Both IP addresses are hijacked on BGP level.

Just VPN, it's easier.
kingkingyyk
post Sep 6 2024, 04:04 PM

10k Club
Group Icon
Elite
15,694 posts

Joined: Mar 2008
QUOTE(HayateAyakasi8 @ Sep 6 2024, 03:59 PM)
Ah does this means that AWS trick won't work for this then?
*
It works. wink.gif They are just sending your requests that are meant to reach well known DNS server (identified by IP address) to their server instead.

In AWS you will get dynamic IP address and they will not be able to ban since you can easily switch to different IP and life continues as usual, and this is just not practical for them to do for personal service.

This post has been edited by kingkingyyk: Sep 6 2024, 04:05 PM
PRSXFENG
post Sep 6 2024, 04:04 PM

Look at all my stars!!
*******
Senior Member
2,614 posts

Joined: Nov 2020


QUOTE(HayateAyakasi8 @ Sep 6 2024, 03:59 PM)
Ah does this means that AWS trick won't work for this then?
*
It works by

You're not asking the DNS servers directly
Instead you're asking your own Amazon server
And then that asks for you and returns the info to you

rrrobot
post Sep 6 2024, 04:04 PM

New Member
*
Junior Member
8 posts

Joined: Jan 2020
QUOTE(kwss @ Sep 6 2024, 03:51 PM)
They are using Imperva for their website.
No way they can do the same for DNS server,
*
I thought my joke was pretty funny ;(
yenchenje
post Sep 6 2024, 04:06 PM

Enthusiast
*****
Junior Member
932 posts

Joined: Dec 2019
QUOTE(blacktubi @ Sep 6 2024, 04:02 PM)
DNS job is to just resolve domain name into IP.

dns.google resolves to 8.8.8.8 and 8.8.4.4

Both IP addresses are hijacked on BGP level.

Just VPN, it's easier.
*
Okay that makes a lot more sense, guess that's the extent that I can do for now, VPN we go next tongue.gif
kwss
post Sep 6 2024, 04:06 PM

Regular
******
Senior Member
1,208 posts

Joined: Aug 2018
QUOTE(HayateAyakasi8 @ Sep 6 2024, 03:59 PM)
Ah does this means that AWS trick won't work for this then?
*
Won't work.
See blacktubi answer.

But unless your job requires access to dns.google or one.one.one.one, I won't be too into it.
But here's the thing, I am sensing the government is trying to break the internet slowly.
Someday they will break all the VPN.

EDIT:
Clarification:
Amazon can bypass DNS block.
Amazon won't bypass BGP hijack.

This post has been edited by kwss: Sep 6 2024, 04:11 PM
smallcrab
post Sep 6 2024, 04:07 PM

Getting Started
**
Junior Member
140 posts

Joined: Jul 2007
From: Puchong


QUOTE(annoymous1234 @ Sep 6 2024, 03:55 PM)
I thought a few reported that this method doesn't work anymore?
*
Oops, was actually using maxis wired broadband, not Unifi.
blacktubi
post Sep 6 2024, 04:07 PM

-
Group Icon
Elite
8,421 posts

Joined: Jul 2008

QUOTE(kingkingyyk @ Sep 6 2024, 04:04 PM)
It works. wink.gif They are just sending your requests that are meant to reach well known DNS server (identified by IP address) to their server instead.

In AWS you will get dynamic IP address and they will not be able to ban since you can easily switch to different IP and life continues as usual, but this is just not practical to do for personal service.
*
No, that AWS trick is just sorting out the DNS resolve part.

But, the IP itself is hijacked on BGP now.

You can't bypass that without the use of a VPN.
kingkingyyk
post Sep 6 2024, 04:09 PM

10k Club
Group Icon
Elite
15,694 posts

Joined: Mar 2008
QUOTE(blacktubi @ Sep 6 2024, 04:07 PM)
No, that AWS trick is just sorting out the DNS resolve part.

But, the IP itself is hijacked on BGP now.

You can't bypass that without the use of a VPN.
*
Was talking about just the DNS resolve part. biggrin.gif
XeactorZ
post Sep 6 2024, 04:09 PM

♥ PandaDog ♥
*********
All Stars
31,612 posts

Joined: Aug 2010
QUOTE(overfloe @ Sep 6 2024, 12:21 PM)
I just received this sms:

"Hi. Do you know we've upgraded your account xxx@unifi to a higher speed for FREE? Your profile will be updated soon. Enjoy your new speed!"

This legit?

I am not aware Unifi is offering free upgrade recently. I can't test coz not at home at the moment.
*
QUOTE(cyberic @ Sep 6 2024, 12:24 PM)
received the same sms but no change in speed or plan name.
*
same, back home only test the speed

but then unifi website super lousy, keep login and said cannot retrieve my account info, please try again later sweat.gif
eddie_lim
post Sep 6 2024, 04:12 PM

You Never Walk Alone
Group Icon
Elite
4,026 posts

Joined: Jan 2003
From: In the deepest part of your heart !




DNS poisoning is ISP work
SSL hijacking from gomen is a very serious act of cyber security

i am making sure every transaction i query go through SSL tunnels
monitoring via tcpdump
Attached Image

This post has been edited by eddie_lim: Sep 6 2024, 04:14 PM
blackbox14
post Sep 6 2024, 04:14 PM

Casual
***
Junior Member
349 posts

Joined: Jul 2012
QUOTE(kwss @ Sep 6 2024, 04:06 PM)
Won't work.
See blacktubi answer.

But unless your job requires access to dns.google or one.one.one.one, I won't be too into it.
But here's the thing, I am sensing the government is trying to break the internet slowly.
Someday they will break all the VPN.

EDIT:
Clarification:
Amazon can bypass DNS block.
Amazon won't bypass BGP hijack.
*
Very strange that they ask the data centers to invest and operate here then. Also, what are they so scared of that they are going this far?

Btw, I asked this earlier in the morning when people were reporting more places kena: Which VPNS are affected so far besides Nord? Someone earlier posted that they couldn't download the client.
kwss
post Sep 6 2024, 04:15 PM

Regular
******
Senior Member
1,208 posts

Joined: Aug 2018
QUOTE(rrrobot @ Sep 6 2024, 04:04 PM)
I thought my joke was pretty funny ;(
*
Aiks... Sorry bro. Really didn't get it

QUOTE(XeactorZ @ Sep 6 2024, 04:09 PM)
same, back home only test the speed

but then unifi website super lousy, keep login and said cannot retrieve my account info, please try again later sweat.gif
*
Disable adblocker.

QUOTE(eddie_lim @ Sep 6 2024, 04:12 PM)
DNS poisoning is ISP work
SSL hijacking from gomen is a very serious act of cyber security
*
100% agree!
Amaru
post Sep 6 2024, 04:16 PM

Regular
******
Senior Member
1,050 posts

Joined: Nov 2007
IPv6 Google DNS still seems to be working for me. Unifi does not seem to be blocking the *ahem* websites.
maxpudding
post Sep 6 2024, 04:16 PM

Getting Started
**
Junior Member
165 posts

Joined: Mar 2007
QUOTE(eddie_lim @ Sep 6 2024, 04:12 PM)
DNS poisoning is ISP work
SSL hijacking from gomen is a very serious act of cyber security

i am making sure every transaction i query go through SSL tunnels
monitoring via tcpdump
Attached Image
*
what are they scared of? this seem to be too extreme already
Raki
post Sep 6 2024, 04:16 PM

Casual
***
Junior Member
311 posts

Joined: Jan 2009


My office in Klang was affected today
QUOTE
[2.7.2-RELEASE][root@office.internal]/root: traceroute 8.8.8.8
traceroute to 8.8.8.8 (8.8.8.8), 64 hops max, 40 byte packets
1  180.75.19.254 (180.75.19.254)  19.390 ms  1.148 ms  4.002 ms
2  10.55.51.29 (10.55.51.29)  7.584 ms * *
3  10.55.52.54 (10.55.52.54)  6.120 ms
    10.55.52.90 (10.55.52.90)  7.401 ms
    10.55.52.54 (10.55.52.54)  7.571 ms
4  10.19.129.65 (10.19.129.65)  29.452 ms  29.680 ms  30.643 ms
5  dns.google (8.8.8.8)  7.272 ms  9.369 ms  27.925 ms
Anime4000's diagram gave me an idea to use our existing Site to Site VPN to tunnel to route just 8.8.8.8 and 8.8.4.4
QUOTE
[2.7.2-RELEASE][root@office.internal]/root: traceroute 8.8.8.8
traceroute to 8.8.8.8 (8.8.8.8), 64 hops max, 40 byte packets
1  172.16.245.1 (172.16.245.1)  5.878 ms  3.512 ms  4.023 ms
2 * * *
3  103.2.80.9 (103.2.80.9)  4.302 ms  4.792 ms  3.939 ms
4  google.myix.my (218.100.44.92)  4.025 ms  12.943 ms  3.374 ms
5  192.178.98.231 (192.178.98.231)  8.419 ms
    192.178.99.63 (192.178.99.63)  4.364 ms
    192.178.98.151 (192.178.98.151)  5.334 ms
6  72.14.234.89 (72.14.234.89)  6.079 ms
    216.239.48.121 (216.239.48.121)  5.579 ms
    142.250.56.103 (142.250.56.103)  4.283 ms
7  dns.google (8.8.8.8)  3.421 ms  5.332 ms  3.625 ms
at least, I still get sub 10ms response

This post has been edited by Raki: Sep 6 2024, 04:19 PM
dev/numb
post Sep 6 2024, 04:20 PM

On my way
****
Junior Member
691 posts

Joined: Nov 2021
QUOTE(Anime4000 @ Sep 6 2024, 01:55 PM)
If your router has Wireguard support, just WG join

because DNS only can be access via Wireguard
*
Sorry bang, I tak paham.

So the WireGuard tunnel is only for DNS queries but the rest (eg: loading site assets) of the packets are moving outside the tunnel?
solarmystic
post Sep 6 2024, 04:26 PM

Getting Started
**
Junior Member
271 posts

Joined: Jun 2009
QUOTE(dev/numb @ Sep 6 2024, 04:00 PM)
Are you out of contract already? Maybe these so called free upgrades have some small print stating you’ll be tied to a new contract.
*
Good point! I'm actually not contracted anymore, haven't been for the past 4 years.

Kept on getting those calls from telemarketers to get tied to a new one but i just ended up ignoring them after awhile, i like having the flexibility to bail out if necessary.



495 Pages « < 294 295 296 297 298 > » Top
Topic ClosedOptions
 

Change to:
| Lo-Fi Version
0.0215sec    0.75    6 queries    GZIP Disabled
Time is now: 20th December 2025 - 12:14 AM