Welcome Guest ( Log In | Register )

12 Pages  1 2 3 > » Bottom

Outline · [ Standard ] · Linear+

 Time and Maxis started to hijack dns query

views
     
TSaxxer
post Aug 8 2024, 11:35 AM, updated 2y ago

Banned
******
Validating
1,822 posts

Joined: Jul 2010
From: Yesterday, 01:25 AM
Previously malaysian telcos already hijack dns query when we're using their default dns server, its no secret. When trying to access gov sanctioned sites like p0rn or sarawak today etc, instead of replying with correct dns record they'll route our query to mcmc block page. But now they've taken a step further by hijacking our query even when we're using either google dns or cloudflare dns.

Source 1
Source 2

I guess this is possible if we're only using the cleartext dns of both google dns and cloudflare dns ie

google dns:
CODE

8.8.8.8
8.8.4.4
2001:4860:4860::8888
2001:4860:4860::8844


cloudflare dns:
CODE

1.1.1.1
1.0.0.1
1.1.1.2
1.0.0.2
1.1.1.3
1.0.0.3
2606:4700:4700::1111
2606:4700:4700::1001
2606:4700:4700::1112
2606:4700:4700::1002
2606:4700:4700::1113
2606:4700:4700::1003


Haven't tested myself but I'm 100% sure the
CODE
8.8.8.8
and
CODE
1.1.1.1
are hijacked since both are the popular dns ip for google dns and cloudflare dns. Others on the list might be hijacked too depending on telco network admins.

But basically people, its high time we should stop using cleartext dns. Its unsecured and hijackable. Start using encrypted dns everywhere.

Theres plenty of them listed here. You'd want to use either the dns-over-https aka doh or dns-over-tls aka dot.

Modern system already support using those encrypted dns protocol ie android natively via setting. Should be listed as
CODE
Private DNS
in phone setting. You should add a dns-over-tls server here, omit the
CODE
tls://
from uri if you copy paste from the list above.

Ios and mac is native too via dns profile. If prefer app can use dnsecure.

Linux can natively too if install any local forwarding dns server like bind9 or dnsmasq. If prefer gui, theres technitium dns server and adguardhome.

Windows can use yoga dns server.

Ty for attending my ted talk lmao.

This post has been edited by axxer: Aug 8 2024, 11:53 AM
Sam Leong
post Aug 8 2024, 06:47 PM

On my way
****
Junior Member
665 posts

Joined: Mar 2016


TIME Home Fibre (No Hijack on my side) :

user posted image

user posted image

Digi 4/5G (Hijacking IPV4:53 , IPV6:53 normal) :

user posted image

Maxis 4/5G (Hijacking Google DNS IPV4 / IPV6 :53, other DNS server normal) :

user posted image

user posted image

acbc
post Aug 8 2024, 07:01 PM

Look at all my stars!!
*******
Senior Member
9,041 posts

Joined: Jan 2003
Thanks a bunch. Now using FreeDNS via DoH.
PRSXFENG
post Aug 8 2024, 09:11 PM

Look at all my stars!!
*******
Senior Member
2,607 posts

Joined: Nov 2020


MCMC Statment

https://x.com/Soya_Cincau/status/1821520438973116758

So, they say it's for "safety"

But the thing is

Ok, sure, feel free to block on TM/Maxis/TIME DNS

But if the user has made a conscious effort to CHANGE their DNS to CF/Google/etc
DON'T HIJACK IT BACK
annoymous1234
post Aug 8 2024, 09:17 PM

Look at all my stars!!
*******
Senior Member
7,614 posts

Joined: Mar 2009

For windows must install software? Can it be done in settings or something?
PRSXFENG
post Aug 8 2024, 09:25 PM

Look at all my stars!!
*******
Senior Member
2,607 posts

Joined: Nov 2020


QUOTE(annoymous1234 @ Aug 8 2024, 09:17 PM)
For windows must install software? Can it be done in settings or something?
*
If windows 11, yes, can enter DNS Over HTTPS address into the DNS settings

If older, then installing YogaDNS is a good choice
kwss
post Aug 9 2024, 12:11 AM

Regular
******
Senior Member
1,207 posts

Joined: Aug 2018
QUOTE(PRSXFENG @ Aug 8 2024, 09:11 PM)
MCMC Statment

https://x.com/Soya_Cincau/status/1821520438973116758

So, they say it's for "safety"

But the thing is

Ok, sure, feel free to block on TM/Maxis/TIME DNS

But if the user has made a conscious effort to CHANGE their DNS to CF/Google/etc
DON'T HIJACK IT BACK
*
Papa said don't try to climb walls. It's bad for you, your family and your kids. Pretty good advice overall.
Big brother don't want you to land in hospital je....
Kadaj
post Aug 9 2024, 09:02 AM

On my way
****
Junior Member
584 posts

Joined: Mar 2006
QUOTE(kwss @ Aug 9 2024, 12:11 AM)
Papa said don't try to climb walls. It's bad for you, your family and your kids. Pretty good advice overall.
Big brother don't want you to land in hospital je....
*
If you don't listen to Papa then you're a bad boy, Papa will ask police to arrest you.
awol
post Aug 9 2024, 09:09 AM

Enthusiast
*****
Junior Member
910 posts

Joined: Jun 2007
From: Selangor
change DNS in router so that any device connected will be adblock ready.
QuantumEdge
post Aug 9 2024, 02:50 PM

Regular
******
Senior Member
1,593 posts

Joined: Jan 2016


user posted image
Lets go, but I think most Tplink router users wont have such luck?
Jjuggler
post Aug 9 2024, 03:00 PM

Narcissistic Genius
******
Senior Member
1,341 posts

Joined: Dec 2016
I already configure two Windows 11-based laptop and a android phone of mine use DoH by default. Of course I am using Google DNS.

This post has been edited by Jjuggler: Aug 9 2024, 03:06 PM
moiskyrie
post Aug 9 2024, 03:05 PM

Look at all my stars!!
*******
Senior Member
3,217 posts

Joined: Dec 2006
From: City of Neko~~Nyaa~
I using tm provide router....
Got way to unblock?
The white router.....az-tech I think...
ChenKaiWen
post Aug 9 2024, 03:38 PM

Casual
***
Junior Member
364 posts

Joined: May 2019


QUOTE(moiskyrie @ Aug 9 2024, 03:05 PM)
I using tm provide router....
Got way to unblock?
The white router.....az-tech I think...
*
Host adguard on a pc or raspberry pi. Set upstream server to use DoT or DoH. Make the router use the adguard as main DNS.
PRSXFENG
post Aug 9 2024, 04:25 PM

Look at all my stars!!
*******
Senior Member
2,607 posts

Joined: Nov 2020


QUOTE(QuantumEdge @ Aug 9 2024, 02:50 PM)
user posted image
Lets go, but I think most Tplink router users wont have such luck?
*
Suprisingly, TP-Link does have DoH/DoT

But only on an extremely limited selection of models
1 AX model and a few AC models

https://community.tp-link.com/en/home/forum/topic/617138


dev/numb
post Aug 9 2024, 06:36 PM

On my way
****
Junior Member
691 posts

Joined: Nov 2021
At this rate, everyone will be using v2ray in a couple of years.
laihuhng
post Aug 9 2024, 06:45 PM

On my way
****
Junior Member
603 posts

Joined: Jun 2005


QUOTE(QuantumEdge @ Aug 9 2024, 02:50 PM)
user posted image
Lets go, but I think most Tplink router users wont have such luck?
*
This will not slow down the internet, right?
kwss
post Aug 9 2024, 08:00 PM

Regular
******
Senior Member
1,207 posts

Joined: Aug 2018
QUOTE(laihuhng @ Aug 9 2024, 06:45 PM)
This will not slow down the internet, right?
*
Based on my testing using Control D, encrypted and unencrypted DNS has the same resolution time.
However, the first lookup will be much slower at 112ms vs 20ms unencrypted due to the need to establish the secure connection.

I do recommend prioritizing security over pure speed as DNS poisoning is one of the many ways to install malware on your device.

The performance penalty only happen once during connection establishment, it is not critical.
TSaxxer
post Aug 9 2024, 08:29 PM

Banned
******
Validating
1,822 posts

Joined: Jul 2010
From: Yesterday, 01:25 AM
QUOTE(laihuhng @ Aug 9 2024, 06:45 PM)
This will not slow down the internet, right?
*
It wouldn't. Technically encrypted dns is slower than cleartext dns due to the encryption but its negligible on modern hardware you wouldn't even notice. Hell if you use adblocking dns server its faster since you wouldn't load all the ads and craps. I've been blocking ads via dns since 10+ years and vanilla internet without adblock is unuseable to me now.
laihuhng
post Aug 9 2024, 09:07 PM

On my way
****
Junior Member
603 posts

Joined: Jun 2005


QUOTE(QuantumEdge @ Aug 9 2024, 02:50 PM)
user posted image
Lets go, but I think most Tplink router users wont have such luck?
*
user posted image

Let me know if I've configured it correctly. I disabled my ipv6. Thus, I didn't include the ipv6 address. Thanks.
kwss
post Aug 9 2024, 09:30 PM

Regular
******
Senior Member
1,207 posts

Joined: Aug 2018
QUOTE(laihuhng @ Aug 9 2024, 09:07 PM)
user posted image

Let me know if I've configured it correctly. I disabled my ipv6. Thus, I didn't include the ipv6 address. Thanks.
*
Based on my nmap scan, the domain should be:
dns.adguard.com
EDIT:
If you connect without SNI it will serve you certificate with dns.adguard.com.
With SNI it will serve certificate with dns.adguard-dns.com.
So both works.

Prevent client auto DoH must be set to off. Otherwise Encrypted Client Hello won't work. You want ECH to work on a highly censored network because it prevent the censor from snooping on your SNI.

Unknown:
Did anyone actually MITM or pen test this thing? Given the recent development of TM where they MITM DoH and DoT, the router must absolutely verify the certificate properly.
On Mikrotik, none of this is done!

This post has been edited by kwss: Aug 9 2024, 09:41 PM

12 Pages  1 2 3 > » Top
 

Change to:
| Lo-Fi Version
0.0230sec    0.55    6 queries    GZIP Disabled
Time is now: 1st December 2025 - 08:56 PM