Welcome Guest ( Log In | Register )

Outline · [ Standard ] · Linear+

 Time and Maxis started to hijack dns query

views
     
Anime4000
post Aug 16 2024, 01:28 PM

Look at all my stars!!
*******
Senior Member
2,399 posts

Joined: Jul 2009
From: /dev/null


it will happen if ISP started to Blackhole 1.1.1.1/32 or any dns/32 address route?

like this need create own DNS server?
Anime4000
post Aug 16 2024, 02:04 PM

Look at all my stars!!
*******
Senior Member
2,399 posts

Joined: Jul 2009
From: /dev/null


QUOTE(kwss @ Aug 16 2024, 01:36 PM)
The most censorship resistant method is to CDN whatever DNS or proxy you use.
The censor can block individual VPS, but they cannot afford to block CDN.
*
If hosting own BIND9 and connecting to Root Server, this method also being poisoned?

I wondering Malaysia blocking Root Server to prevent hosting own BIND9 at home
Anime4000
post Aug 16 2024, 02:34 PM

Look at all my stars!!
*******
Senior Member
2,399 posts

Joined: Jul 2009
From: /dev/null


QUOTE(kwss @ Aug 16 2024, 02:13 PM)
Your method won't work if they redirect port 53. Reason is root server / authoritative server lookup only works on plaintext DNS.
Celcom is using this exact method of blocking. However you can still bypass it by telling your recursive resolver to use TCP.

It is not authenticated / encrypted and I no longer recommend this. I see no benefit of running a recursive resolver other than for lab purpose. You can find many third party resolver with QNAME Minimization.
Resolver logging you is a question but ISP snooping and tampering with your DNS query is now happening.
*
welp Root Server also not safe.
I just DoH via WG to my friend server then,

this way no one know that DoH being tunnel
Anime4000
post Sep 7 2024, 11:18 AM

Look at all my stars!!
*******
Senior Member
2,399 posts

Joined: Jul 2009
From: /dev/null


Just in case, I could transport my whole Home LAN to Friend BGP, making like I staying in SG Data Centre

user posted image

speed I get via 2Gbps is using Wireguard on RB5009, CPU under 70% usage

 

Change to:
| Lo-Fi Version
0.0218sec    0.36    7 queries    GZIP Disabled
Time is now: 2nd December 2025 - 08:27 PM