it will happen if ISP started to Blackhole 1.1.1.1/32 or any dns/32 address route?
like this need create own DNS server?
Time and Maxis started to hijack dns query
Time and Maxis started to hijack dns query
|
|
Aug 16 2024, 01:28 PM
Return to original view | IPv6 | Post
#1
|
![]() ![]() ![]() ![]() ![]() ![]() ![]()
Senior Member
2,399 posts Joined: Jul 2009 From: /dev/null |
it will happen if ISP started to Blackhole 1.1.1.1/32 or any dns/32 address route?
like this need create own DNS server? |
|
|
|
|
|
Aug 16 2024, 02:04 PM
Return to original view | IPv6 | Post
#2
|
![]() ![]() ![]() ![]() ![]() ![]() ![]()
Senior Member
2,399 posts Joined: Jul 2009 From: /dev/null |
QUOTE(kwss @ Aug 16 2024, 01:36 PM) The most censorship resistant method is to CDN whatever DNS or proxy you use. If hosting own BIND9 and connecting to Root Server, this method also being poisoned?The censor can block individual VPS, but they cannot afford to block CDN. I wondering Malaysia blocking Root Server to prevent hosting own BIND9 at home |
|
|
Aug 16 2024, 02:34 PM
Return to original view | IPv6 | Post
#3
|
![]() ![]() ![]() ![]() ![]() ![]() ![]()
Senior Member
2,399 posts Joined: Jul 2009 From: /dev/null |
QUOTE(kwss @ Aug 16 2024, 02:13 PM) Your method won't work if they redirect port 53. Reason is root server / authoritative server lookup only works on plaintext DNS. welp Root Server also not safe.Celcom is using this exact method of blocking. However you can still bypass it by telling your recursive resolver to use TCP. It is not authenticated / encrypted and I no longer recommend this. I see no benefit of running a recursive resolver other than for lab purpose. You can find many third party resolver with QNAME Minimization. Resolver logging you is a question but ISP snooping and tampering with your DNS query is now happening. I just DoH via WG to my friend server then, this way no one know that DoH being tunnel |
|
|
Sep 7 2024, 11:18 AM
Return to original view | IPv6 | Post
#4
|
![]() ![]() ![]() ![]() ![]() ![]() ![]()
Senior Member
2,399 posts Joined: Jul 2009 From: /dev/null |
Just in case, I could transport my whole Home LAN to Friend BGP, making like I staying in SG Data Centre ![]() speed I get via 2Gbps is using Wireguard on RB5009, CPU under 70% usage dev/numb and hasmidzul_jojo liked this post
|
| Change to: | 0.0218sec
0.36
7 queries
GZIP Disabled
Time is now: 2nd December 2025 - 08:27 PM |