Welcome Guest ( Log In | Register )

12 Pages < 1 2 3 4 > » Bottom

Outline · [ Standard ] · Linear+

 Time and Maxis started to hijack dns query

views
     
laihuhng
post Aug 9 2024, 11:17 PM

On my way
****
Junior Member
603 posts

Joined: Jun 2005


QUOTE(kwss @ Aug 9 2024, 09:30 PM)
Based on my nmap scan, the domain should be:
dns.adguard.com
EDIT:
If you connect without SNI it will serve you certificate with dns.adguard.com.
With SNI it will serve certificate with dns.adguard-dns.com.
So both works.

Prevent client auto DoH must be set to off. Otherwise Encrypted Client Hello won't work. You want ECH to work on a highly censored network because it prevent the censor from snooping on your SNI.

Unknown:
Did anyone actually MITM or pen test this thing? Given the recent development of TM where they MITM DoH and DoT, the router must absolutely verify the certificate properly.
On Mikrotik, none of this is done!
*
I've set Prevent Client auto DoH to NO. Thanks.

Kadaj
post Aug 10 2024, 12:11 AM

On my way
****
Junior Member
586 posts

Joined: Mar 2006
QUOTE(kwss @ Aug 9 2024, 09:30 PM)
Did anyone actually MITM or pen test this thing? Given the recent development of TM where they MITM DoH and DoT, the router must absolutely verify the certificate properly.
On Mikrotik, none of this is done!
*
Did you miss anything and caused the dns leak? maybe check the firewall rules.
https://youtu.be/w4erB0VzyIE
kwss
post Aug 10 2024, 12:25 AM

Regular
******
Senior Member
1,207 posts

Joined: Aug 2018
QUOTE(Kadaj @ Aug 10 2024, 12:11 AM)
Did you miss anything and caused the dns leak? maybe check the firewall rules.
https://youtu.be/w4erB0VzyIE
*
Nope, it is how Mikrotik works.
You can read about the solution here:
https://forum.mikrotik.com/viewtopic.php?f=...=160243#p787643

I continue to have problem where I cannot import Amazon Root CA for my DoH. I have since turned off Mikrotik DNS resolver and stick to tried and true systemd-resolved for my laptop and stubby for my home server.

I use DoH exclusively for browser due to it being a requirement for ECH to work.

My point being, I don't know if any of those router aka IoT device do security properly. To the user they are doing DoT / DoH but behind the scene they might fall apart from actual attack.

UPDATE:
I give it another go but this time I download the certificates from
https://www.amazontrust.com/repository/

It works!
Not sure why the download from browser view certificate didn't works.

This post has been edited by kwss: Aug 10 2024, 12:47 AM
kwss
post Aug 10 2024, 02:31 AM

Regular
******
Senior Member
1,207 posts

Joined: Aug 2018
I play a bit with Celcom's implementation. Basically they catch all UDP port 53 on IPv4 and IPv6

Test with fc00:: which is a non-routable local address
CODE

dig @fc00:: pornhub.com

; <<>> DiG 9.18.28 <<>> @fc00:: pornhub.com
; (1 server found)
;; global options: +cmd
;; Got answer:
;; ->>HEADER<<- opcode: QUERY, status: NOERROR, id: 29836
;; flags: qr aa rd ra; QUERY: 1, ANSWER: 1, AUTHORITY: 0, ADDITIONAL: 1

;; OPT PSEUDOSECTION:
; EDNS: version: 0, flags:; udp: 1232
;; QUESTION SECTION:
;pornhub.com.   IN A

;; ANSWER SECTION:
pornhub.com.  3600 IN A 175.139.142.25

;; Query time: 37 msec
;; SERVER: fc00::#53(fc00::) (UDP)
;; WHEN: Sat Aug 10 02:16:04 +08 2024
;; MSG SIZE  rcvd: 56


Test with 10.10.10.10 which is also non-routable:
CODE

dig @10.10.10.10 pornhub.com

; <<>> DiG 9.18.28 <<>> @10.10.10.10 pornhub.com
; (1 server found)
;; global options: +cmd
;; Got answer:
;; ->>HEADER<<- opcode: QUERY, status: NOERROR, id: 28827
;; flags: qr aa rd ra; QUERY: 1, ANSWER: 1, AUTHORITY: 0, ADDITIONAL: 1

;; OPT PSEUDOSECTION:
; EDNS: version: 0, flags:; udp: 1232
;; QUESTION SECTION:
;pornhub.com.   IN A

;; ANSWER SECTION:
pornhub.com.  3600 IN A 175.139.142.25

;; Query time: 44 msec
;; SERVER: 10.10.10.10#53(10.10.10.10) (UDP)
;; WHEN: Sat Aug 10 02:16:19 +08 2024
;; MSG SIZE  rcvd: 56


Using non-routable IPv6 address but with TCP:
CODE

dig @fc00:: pornhub.com +tcp
;; Connection to fc00::#53(fc00::) for pornhub.com failed: host unreachable.
;; no servers could be reached

;; Connection to fc00::#53(fc00::) for pornhub.com failed: host unreachable.
;; no servers could be reached

;; Connection to fc00::#53(fc00::) for pornhub.com failed: host unreachable.
;; no servers could be reached



Using non-routable IPv4 address but with TCP:
CODE

dig @10.10.10.10 pornhub.com +tcp
;; Connection to 10.10.10.10#53(10.10.10.10) for pornhub.com failed: timed out.
;; no servers could be reached

;; Connection to 10.10.10.10#53(10.10.10.10) for pornhub.com failed: timed out.
;; no servers could be reached

;; Connection to 10.10.10.10#53(10.10.10.10) for pornhub.com failed: timed out.
;; no servers could be reached


This means that using TCP should work, even if it is plain text. Yes it does!
CODE

dig @1.1.1.1 pornhub.com +tcp

; <<>> DiG 9.18.28 <<>> @1.1.1.1 pornhub.com +tcp
; (1 server found)
;; global options: +cmd
;; Got answer:
;; ->>HEADER<<- opcode: QUERY, status: NOERROR, id: 48352
;; flags: qr rd ra; QUERY: 1, ANSWER: 1, AUTHORITY: 0, ADDITIONAL: 1

;; OPT PSEUDOSECTION:
; EDNS: version: 0, flags:; udp: 1232
;; QUESTION SECTION:
;pornhub.com.   IN A

;; ANSWER SECTION:
pornhub.com.  14400 IN A 66.254.114.41

;; Query time: 69 msec
;; SERVER: 1.1.1.1#53(1.1.1.1) (TCP)
;; WHEN: Sat Aug 10 02:20:20 +08 2024
;; MSG SIZE  rcvd: 56


However, I found that they block by IP address too for pornhub.com and xvideos.com. murrayhunter.substack.com didn't have their IP blocked so it is not quite consistent.
Reason is murrayhunter.substack.com uses Cloudflare CDN. They cannot block the CDN without blocking everyone else.

This post has been edited by kwss: Aug 10 2024, 02:44 AM
BladeRider88
post Aug 12 2024, 02:44 PM

On my way
****
Junior Member
554 posts

Joined: Nov 2006


so few people discuss about this...am i being paranoid over this matter or they just don't care?

Btw, i already onboard with DoT/DoH, now all my devices are protected
dev/numb
post Aug 12 2024, 03:20 PM

On my way
****
Junior Member
691 posts

Joined: Nov 2021
QUOTE(BladeRider88 @ Aug 12 2024, 02:44 PM)
so few people discuss about this...am i being paranoid over this matter or they just don't care?
*
Most Malaysians don’t care about privacy or security. With the Google Pixel 9 being announced for Malaysia, I visited all the Pixel related threads in the Mobile Phone and Kopitiam sections on this forum and entered “GrapheneOS” in the search box. Not a single hit.
JLA
post Aug 12 2024, 04:02 PM

Look at all my stars!!
*******
Senior Member
2,777 posts

Joined: May 2008
QUOTE(kwss @ Aug 10 2024, 02:31 AM)
I play a bit with Celcom's implementation. Basically they catch all UDP port 53 on IPv4 and IPv6
*
celcom axiata mobile long time already block xxx website
canot bypass with dns
Dont visit xxx so not a problem
BladeRider88
post Aug 12 2024, 05:01 PM

On my way
****
Junior Member
554 posts

Joined: Nov 2006


QUOTE(dev/numb @ Aug 12 2024, 03:20 PM)
Most Malaysians don’t care about privacy or security. With the Google Pixel 9 being announced for Malaysia, I visited all the Pixel related threads in the Mobile Phone and Kopitiam sections on this forum and entered “GrapheneOS” in the search box. Not a single hit.
*
duh... rclxub.gif shocking.gif doh.gif

Guess, we are the "paranoid" one.


Alpha_Tay
post Aug 12 2024, 11:06 PM

Beware The Spammer Star!
******
Senior Member
1,725 posts

Joined: Jan 2003
Cloudflare WARP work?
TSaxxer
post Aug 13 2024, 12:13 AM

Banned
******
Validating
1,822 posts

Joined: Jul 2010
From: Yesterday, 01:25 AM
QUOTE(Alpha_Tay @ Aug 12 2024, 11:06 PM)
Cloudflare WARP work?
*
It should. Cloudflare warp is doh. Cloudflare warp+ is vpn+doh.
Alpha_Tay
post Aug 13 2024, 01:28 AM

Beware The Spammer Star!
******
Senior Member
1,725 posts

Joined: Jan 2003
QUOTE(axxer @ Aug 13 2024, 12:13 AM)
It should. Cloudflare warp is doh. Cloudflare warp+ is vpn+doh.
*
thx. how about Cloudflare WARP Windows Software 1.1.1.1 DNS Protocol HTTPS and TLS, 1.1.1.1 with WARP DNS Protocol HTTPS and TLS and WARP, all of these work? unifi fibre keep getting website facebook reddit etc loading or half loading issues since around weeks ago. and strange that Google Chrome incognito Mode doesnt have website loading or half loading issues.

UPDATE: Such issues doesnt happen again since 14 August 2024

This post has been edited by Alpha_Tay: Aug 14 2024, 10:50 PM
alpha
post Aug 13 2024, 08:35 AM

On my way
****
Junior Member
562 posts

Joined: Jan 2003
do we need to install extra program for windows or android in order to use encrypted dns? or just simply change 1.1.1.1 to those with encrypted dns will be enough, or how do we check the dns we are using is encrypted?


sorry I am rookie.... TQ

This post has been edited by alpha: Aug 13 2024, 08:37 AM
Kadaj
post Aug 13 2024, 08:51 AM

On my way
****
Junior Member
586 posts

Joined: Mar 2006
QUOTE(alpha @ Aug 13 2024, 08:35 AM)
do we need to install extra program for windows or android in order to use encrypted dns? or just simply change 1.1.1.1 to those with encrypted dns will be enough, or how do we check the dns we are using is encrypted?
sorry I am rookie.... TQ
*
There are several ways to do it.

1. Firefox & Chrome web browsers
https://imap.sinarproject.org/news/internet...lic-dns-servers

2. Windows 11
https://www.howtogeek.com/765940/how-to-ena...-on-windows-11/

3. Android
https://blog.cloudflare.com/enable-private-...-android-9-pie/

To test if you're using Cloudflare secure dns (DoH or DoT):
https://one.one.one.one/help/
https://www.cloudflare.com/ssl/encrypted-sni/
Kadaj
post Aug 13 2024, 09:02 AM

On my way
****
Junior Member
586 posts

Joined: Mar 2006
Calling help for collecting data to test for Transparent DNS Proxies.
https://imap.sinarproject.org/news/guide-on...ent-dns-proxies

If you're not using Linux, you can create a Linux bootable USB drive and run the commands. You can use USB tethering or wifi hotspot from mobile phone to connect to internet and test your mobile network.
haya
post Aug 13 2024, 10:24 AM

Sarawakian first!
*******
Senior Member
2,067 posts

Joined: Jan 2003

QUOTE(kwss @ Aug 10 2024, 02:31 AM)
I play a bit with Celcom's implementation. Basically they catch all UDP port 53 on IPv4 and IPv6

Test with fc00:: which is a non-routable local address
CODE

dig @fc00:: pornhub.com

; <<>> DiG 9.18.28 <<>> @fc00:: pornhub.com
; (1 server found)
;; global options: +cmd
;; Got answer:
;; ->>HEADER<<- opcode: QUERY, status: NOERROR, id: 29836
;; flags: qr aa rd ra; QUERY: 1, ANSWER: 1, AUTHORITY: 0, ADDITIONAL: 1

;; OPT PSEUDOSECTION:
; EDNS: version: 0, flags:; udp: 1232
;; QUESTION SECTION:
;pornhub.com.   IN A

;; ANSWER SECTION:
pornhub.com.  3600 IN A 175.139.142.25

;; Query time: 37 msec
;; SERVER: fc00::#53(fc00::) (UDP)
;; WHEN: Sat Aug 10 02:16:04 +08 2024
;; MSG SIZE  rcvd: 56


Test with 10.10.10.10 which is also non-routable:
CODE

dig @10.10.10.10 pornhub.com

; <<>> DiG 9.18.28 <<>> @10.10.10.10 pornhub.com
; (1 server found)
;; global options: +cmd
;; Got answer:
;; ->>HEADER<<- opcode: QUERY, status: NOERROR, id: 28827
;; flags: qr aa rd ra; QUERY: 1, ANSWER: 1, AUTHORITY: 0, ADDITIONAL: 1

;; OPT PSEUDOSECTION:
; EDNS: version: 0, flags:; udp: 1232
;; QUESTION SECTION:
;pornhub.com.   IN A

;; ANSWER SECTION:
pornhub.com.  3600 IN A 175.139.142.25

;; Query time: 44 msec
;; SERVER: 10.10.10.10#53(10.10.10.10) (UDP)
;; WHEN: Sat Aug 10 02:16:19 +08 2024
;; MSG SIZE  rcvd: 56


Using non-routable IPv6 address but with TCP:
CODE

dig @fc00:: pornhub.com +tcp
;; Connection to fc00::#53(fc00::) for pornhub.com failed: host unreachable.
;; no servers could be reached

;; Connection to fc00::#53(fc00::) for pornhub.com failed: host unreachable.
;; no servers could be reached

;; Connection to fc00::#53(fc00::) for pornhub.com failed: host unreachable.
;; no servers could be reached

Using non-routable IPv4 address but with TCP:
CODE

dig @10.10.10.10 pornhub.com +tcp
;; Connection to 10.10.10.10#53(10.10.10.10) for pornhub.com failed: timed out.
;; no servers could be reached

;; Connection to 10.10.10.10#53(10.10.10.10) for pornhub.com failed: timed out.
;; no servers could be reached

;; Connection to 10.10.10.10#53(10.10.10.10) for pornhub.com failed: timed out.
;; no servers could be reached


This means that using TCP should work, even if it is plain text. Yes it does!
CODE

dig @1.1.1.1 pornhub.com +tcp

; <<>> DiG 9.18.28 <<>> @1.1.1.1 pornhub.com +tcp
; (1 server found)
;; global options: +cmd
;; Got answer:
;; ->>HEADER<<- opcode: QUERY, status: NOERROR, id: 48352
;; flags: qr rd ra; QUERY: 1, ANSWER: 1, AUTHORITY: 0, ADDITIONAL: 1

;; OPT PSEUDOSECTION:
; EDNS: version: 0, flags:; udp: 1232
;; QUESTION SECTION:
;pornhub.com.   IN A

;; ANSWER SECTION:
pornhub.com.  14400 IN A 66.254.114.41

;; Query time: 69 msec
;; SERVER: 1.1.1.1#53(1.1.1.1) (TCP)
;; WHEN: Sat Aug 10 02:20:20 +08 2024
;; MSG SIZE  rcvd: 56


However, I found that they block by IP address too for pornhub.com and xvideos.com. murrayhunter.substack.com didn't have their IP blocked so it is not quite consistent.
Reason is murrayhunter.substack.com uses Cloudflare CDN. They cannot block the CDN without blocking everyone else.
*
Interesting that Celcom(Digi) is now hijacking all DNS53. What about things like Quad9dns? If Quad9dns blocks a malicious domain, and Celcom(Digi) is now hijacking all DNS53 packets to them, will Celcom(Digi) resolve the domain blocked by Quad9dns?
The.Lucas.DaY
post Aug 13 2024, 10:36 AM

On my way
****
Junior Member
670 posts

Joined: May 2019

What should i worry about, as a normal user, if i don't use DoT/DoH?
OKLY
post Aug 13 2024, 12:39 PM

The Penguin Vader
Group Icon
Staff
12,089 posts

Joined: Dec 2004
From: Malaysia


QUOTE(The.Lucas.DaY @ Aug 13 2024, 10:36 AM)
What should i worry about, as a normal user, if i don't use DoT/DoH?
*
For normal users, you will more likely be concerned with censorship from the government. e.g. if one day government decides to block a certain news portal, all ISPs will be instructed to hijack DNS requests for that site making user unable to access it.
PRSXFENG
post Aug 13 2024, 04:48 PM

Look at all my stars!!
*******
Senior Member
2,608 posts

Joined: Nov 2020


For those using Quad9, Quad9 has provided a few ways to check what protocol you're using and check for hijacks

https://docs.quad9.net/FAQs/
kwss
post Aug 13 2024, 04:53 PM

Regular
******
Senior Member
1,207 posts

Joined: Aug 2018
QUOTE(haya @ Aug 13 2024, 10:24 AM)
Interesting that Celcom(Digi) is now hijacking all DNS53. What about things like Quad9dns? If Quad9dns blocks a malicious domain, and Celcom(Digi) is now hijacking all DNS53 packets to them, will Celcom(Digi) resolve the domain blocked by Quad9dns?
*
From my testing with Celcom (AS10030), all DNS is hijacked, including microsoft.com, lowyat.net, etc. They all resolved via some non-routable IP address.
kwss
post Aug 13 2024, 04:55 PM

Regular
******
Senior Member
1,207 posts

Joined: Aug 2018
QUOTE(The.Lucas.DaY @ Aug 13 2024, 10:36 AM)
What should i worry about, as a normal user, if i don't use DoT/DoH?
*
Maybe like one day when Ergodan is unhappy Meta removed his post, he went and block Instagram nationwide.

12 Pages < 1 2 3 4 > » Top
 

Change to:
| Lo-Fi Version
0.2358sec    0.37    6 queries    GZIP Disabled
Time is now: 4th December 2025 - 05:38 PM