Welcome Guest ( Log In | Register )

Outline · [ Standard ] · Linear+

 Time and Maxis started to hijack dns query

views
     
PRSXFENG
post Sep 6 2024, 03:43 PM

Look at all my stars!!
*******
Senior Member
2,608 posts

Joined: Nov 2020


Spoke too soon, it's coming to TIME

Email sent to business customers

Image stolen from other places on the internet

user posted image

PRSXFENG
post Sep 6 2024, 04:50 PM

Look at all my stars!!
*******
Senior Member
2,608 posts

Joined: Nov 2020


QUOTE(blackbox14 @ Sep 6 2024, 04:43 PM)
How come Maxis business allows DoT and DoH then? Is it really just up to the ISP company?

Probably need to check that Maxis Business FAQ section because it might be changed soon.
*
I'm guessing the bare minimum is blocking people from using other DNS servers and force usage of ISP servers

Maxis gently nudge you in the direction to use DoH/DoT

Time just "kindly request" you to change, not "demand"

But based on Maxis thread, it seems like home users will not be treated so kindly, and DoH/DoT May be blocked

So far on my side... Things are still ok.
It remains to be seen how does time implement their block
PRSXFENG
post Sep 6 2024, 05:21 PM

Look at all my stars!!
*******
Senior Member
2,608 posts

Joined: Nov 2020


QUOTE(Epic_winner091 @ Sep 6 2024, 05:17 PM)
Source of them going after VPNs? That's a leap too far IMO.
*
From the Unifi
There is some mentioning of Cloudflare WARP being blocked
Though some others don't have that problem

Another post was someone having issues attempting to download and install NordVPN
PRSXFENG
post Sep 6 2024, 05:36 PM

Look at all my stars!!
*******
Senior Member
2,608 posts

Joined: Nov 2020


Oh the twitter hidden replies...

user posted image
PRSXFENG
post Sep 6 2024, 06:36 PM

Look at all my stars!!
*******
Senior Member
2,608 posts

Joined: Nov 2020


https://www.freemalaysiatoday.com/category/...irection-order/

QUOTE
“The rationale (behind the DNS redirection) is that we want to prevent access to harmful sites, especially pornography and many online gambling websites.

We do not intend to restrict freedom of speech, he told reporters after launching Astro Radio’s KITAfm in Shah Alam today
The problem I have with this is.

Ok, feel free to block those websites on ISP DNS

BUT IF THE USER HAS MADE A CONSCIOUS CHOICE TO CHANGE THEIR DNS TO SOMETHING ELSE

YOU DONT HIJACK IT BACK

AND CERTAINLY NOT MESS WITH ENCRYPTED DNS
PRSXFENG
post Sep 6 2024, 11:59 PM

Look at all my stars!!
*******
Senior Member
2,608 posts

Joined: Nov 2020


QUOTE(dev/numb @ Sep 6 2024, 11:52 PM)
I see no signs of this, so far at least.

Grabbed an older router with no encrypted DNS setting, set bareback legacy DNS (Cloudflare IPv4, didn’t bother with IPv6) and tested to ensure it was being redirected to TM’s std infested endpoints. Removed DoT condom on Android phone. Installed Warp from Play store. Enabled Warp+. Tested. Works.

Removed DoH profile from MacOS. Visited NordVPN website. Not blocked by TM’s roadside hooker DNS. Successfully downloaded pkg file. Spun up a Ubuntu VM. Successfully ran the Nord Linux install.sh script. No Windows system in my home, so cannot test that. Also didn’t actually try to launch NordVPN (because I don’t use shithole VPNs) so cannot confirm if their VPN endpoints are blocked, but I doubt it.
*
for now, it seems like the blocking has been paused for now
PRSXFENG
post Sep 7 2024, 07:39 AM

Look at all my stars!!
*******
Senior Member
2,608 posts

Joined: Nov 2020


QUOTE(BladeRider88 @ Sep 7 2024, 07:30 AM)
Now Time cannot access dns.google & 1.1.1.1 verify lol
*
hmm still works on my side
what's your setup
PRSXFENG
post Sep 7 2024, 07:42 AM

Look at all my stars!!
*******
Senior Member
2,608 posts

Joined: Nov 2020


QUOTE(BladeRider88 @ Sep 7 2024, 07:41 AM)
The usual cf, google, Adguard free dns
Suddenly cannot visit 1.1.1.1/help or cf website, and dns.google
I am using Adguard Home thou
*
check that none of your lists block attempts to visit those, I know i myself have dns.google intentionally blocked to avoid bypasses

PRSXFENG
post Sep 7 2024, 08:10 AM

Look at all my stars!!
*******
Senior Member
2,608 posts

Joined: Nov 2020


QUOTE(kwss @ Sep 7 2024, 08:07 AM)
Actually all looks fine. The slight difference in output is expected depending on which server you hit.
The only thing nmap cannot tell is the certificate signature and issuer.
*
maybe try a

CODE
openssl s_client --connect dns.google:443


and see?
PRSXFENG
post Sep 7 2024, 03:01 PM

Look at all my stars!!
*******
Senior Member
2,608 posts

Joined: Nov 2020


Hmm

https://www.reddit.com/r/malaysia/comments/..._there_will_be/
PRSXFENG
post Sep 7 2024, 03:24 PM

Look at all my stars!!
*******
Senior Member
2,608 posts

Joined: Nov 2020


Looks like Celcom (Tunetalk) is blanket hijacking port 53

any DNS Server, including niche ones, are all being hijacked and responds the TM Blackhole IP

for U Mobile it seems like just some of the major ones are hijacked
PRSXFENG
post Sep 8 2024, 12:20 PM

Look at all my stars!!
*******
Senior Member
2,608 posts

Joined: Nov 2020


Ok need to post here also

UTurn UTurn UTurn!

https://x.com/fahmi_fadzil/status/1832628152570679401

QUOTE
Isu jenayah dalam talian termasuk akses ke laman-laman web perjudian, persundalan, pornografi dan seumpamanya amat membimbangkan dan memerlukan usaha penyelesaian yang menyeluruh.

Kerajaan tidak akan berkompromi dalam hal ini, demi menjamin keselamatan dalam talian buat rakyat Malaysia, khususnya kanak-kanak dan keluarga.

Namun, mengambil kira pandangan yang disampaikan melalui siri libat urus @MCMC_RASMI
serta daripada khalayak umum, saya telah meminta MCMC agak tidak meneruskan pelaksanaan kaedah penghalaan pengurusan Domain Name System (DNS).

Pada masa sama, MCMC akan meneruskan siri libat urus bersama semua pemegang taruh untuk memperoleh pandangan, cadangan dan saranan bagi memastikan objektif internet yang lebih selamat dapat dicapai bersama.
PRSXFENG
post Sep 9 2024, 02:12 PM

Look at all my stars!!
*******
Senior Member
2,608 posts

Joined: Nov 2020


QUOTE(glorious @ Sep 9 2024, 02:01 PM)
i ask whether he knows not because i do not know

then the low capability center trash come and do what they does best that is to make a presentation out of rudimentary stuff

earlier another communicator trash talked nonsense like a pro
*
we were talking about encrypting dns for security and privacy reasons
and to prevent ISP from hijacking it

you're the one who barged in saying whats the point if big tech tracks you anyways and that it's pointless and "trash"

might as well not lock your house doors because someone could lockpick it
PRSXFENG
post Sep 9 2024, 02:18 PM

Look at all my stars!!
*******
Senior Member
2,608 posts

Joined: Nov 2020


Anyways, ignoring the above, someone did join the event earlier today

https://x.com/khairizulfadhli/status/1832779318897901918

it was... terrible

user posted image
PRSXFENG
post Sep 9 2024, 04:57 PM

Look at all my stars!!
*******
Senior Member
2,608 posts

Joined: Nov 2020


https://x.com/MCMC_RASMI/status/1833059990808199253

PRSXFENG
post Sep 9 2024, 06:21 PM

Look at all my stars!!
*******
Senior Member
2,608 posts

Joined: Nov 2020


QUOTE(PRSXFENG @ Sep 9 2024, 04:57 PM)
Andddd it got deleted

Reupload from twitter embed

user posted image
PRSXFENG
post Sep 9 2024, 10:16 PM

Look at all my stars!!
*******
Senior Member
2,608 posts

Joined: Nov 2020


It appears that CelcomDigi has turned off their Port 53 hijack

However, U Mobile is still hijacking well known providers
PRSXFENG
post Sep 10 2024, 10:59 AM

Look at all my stars!!
*******
Senior Member
2,608 posts

Joined: Nov 2020


QUOTE(GameSky @ Sep 10 2024, 10:47 AM)
plain or encrypted?
*
Just plain old DNS

DoH/DoT works fine
PRSXFENG
post Sep 12 2024, 09:09 AM

Look at all my stars!!
*******
Senior Member
2,608 posts

Joined: Nov 2020


Got the attention of the man himself, Louis Rossmann

https://www.youtube.com/watch?v=itj3Z43QAf8
PRSXFENG
post Sep 12 2024, 04:02 PM

Look at all my stars!!
*******
Senior Member
2,608 posts

Joined: Nov 2020


TIME sent another email to Business Customers

The U Turn

This post has been edited by PRSXFENG: Sep 12 2024, 04:02 PM


Attached thumbnail(s)
Attached Image

3 Pages < 1 2 3 >Top
 

Change to:
| Lo-Fi Version
0.0329sec    0.53    7 queries    GZIP Disabled
Time is now: 5th December 2025 - 01:39 PM