Welcome Guest ( Log In | Register )

Outline · [ Standard ] · Linear+

 Time and Maxis started to hijack dns query

views
     
dev/numb
post Aug 9 2024, 06:36 PM

On my way
****
Junior Member
691 posts

Joined: Nov 2021
At this rate, everyone will be using v2ray in a couple of years.
dev/numb
post Aug 12 2024, 03:20 PM

On my way
****
Junior Member
691 posts

Joined: Nov 2021
QUOTE(BladeRider88 @ Aug 12 2024, 02:44 PM)
so few people discuss about this...am i being paranoid over this matter or they just don't care?
*
Most Malaysians don’t care about privacy or security. With the Google Pixel 9 being announced for Malaysia, I visited all the Pixel related threads in the Mobile Phone and Kopitiam sections on this forum and entered “GrapheneOS” in the search box. Not a single hit.
dev/numb
post Aug 15 2024, 06:03 PM

On my way
****
Junior Member
691 posts

Joined: Nov 2021
Question; visiting https://www.ssllabs.com/ssltest/index.html and inputting dns.adguard-dns.com as an example, which one of the two SHA256 lines I’ve pointed at with the red arrow in this screenshot would be the equivalent of the SPKI fingerprint needed in order to do certificate pinning?

This post has been edited by dev/numb: Aug 15 2024, 06:05 PM
dev/numb
post Sep 1 2024, 07:55 PM

On my way
****
Junior Member
691 posts

Joined: Nov 2021
QUOTE(GameSky @ Sep 1 2024, 07:02 PM)
any good router that can support adguard home?
i got mi4a gigabit but can only run dns over https proxy due to limited storage
*
Any newer (AX or later) Asus router that is supported by Merlin should be able to run AdGuard Home. You can do a web search for “AdGuard Home Asus Merlin” to find relevant projects/instructions on Github and discussions on SmallNetBuilder forums. Not really needed though since Asus Merlin has amtm which lets you use Diversion and Skynet, which do an equally good job but are much lighter on resources.

A couple of GL.iNet routers (Flint and Flint2) come installed with AdGuard Home, but buying them in MY is a bit of a hassle. I don’t know of any local resellers in MY. Shopee and Lazada stores will ship them from Hong Kong or Taiwan, so your delivery might be held by customs due to the Sirim requirements and whatnot.

Probably any OpenWRT compatible router with sufficient RAM can also install AdGuard Home via opkg and LuCi quite easily. The hard part would be getting OpenWRT installed on that router in the first place.

Mikrotik routers probably compatible also, likely via containers (I have zero experience with this brand so just an assumption here, please don’t quote me on this).

This post has been edited by dev/numb: Sep 1 2024, 07:57 PM
dev/numb
post Sep 6 2024, 11:52 PM

On my way
****
Junior Member
691 posts

Joined: Nov 2021
QUOTE(PRSXFENG @ Sep 6 2024, 05:21 PM)
From the Unifi
There is some mentioning of Cloudflare WARP being blocked
Though some others don't have that problem

Another post was someone having issues attempting to download and install NordVPN
*
I see no signs of this, so far at least.

Grabbed an older router with no encrypted DNS setting, set bareback legacy DNS (Cloudflare IPv4, didn’t bother with IPv6) and tested to ensure it was being redirected to TM’s std infested endpoints. Removed DoT condom on Android phone. Installed Warp from Play store. Enabled Warp+. Tested. Works.

Removed DoH profile from MacOS. Visited NordVPN website. Not blocked by TM’s roadside hooker DNS. Successfully downloaded pkg file. Spun up a Ubuntu VM. Successfully ran the Nord Linux install.sh script. No Windows system in my home, so cannot test that. Also didn’t actually try to launch NordVPN (because I don’t use shithole VPNs) so cannot confirm if their VPN endpoints are blocked, but I doubt it.

This post has been edited by dev/numb: Sep 6 2024, 11:53 PM
dev/numb
post Sep 7 2024, 12:03 AM

On my way
****
Junior Member
691 posts

Joined: Nov 2021
QUOTE(axxer @ Sep 6 2024, 10:55 PM)
What these morons didn't know is that some android phone will auto set private dns setting to "Automatic", it'll be using dns.google by default. Not sure whether got fallback or not but if doesn't, in this situation then whole phone internet will be down since systemwide dns is failing since its not trusting the bogus cert it got.

Being a telco cs this upcoming few days should be fun, dealing with cursing users angry about their downed internet. Talk about doing stupid shit without further thinking 🤦🤦
*
If not mistaken, Android’s automatic setting in Private DNS a kind of opportunistic implementation (meaning not strict) and will fallback to legacy DNS whenever. Only the custom option where you input your preferred provider is strict. Very strict in fact. So strict that it will override your VPN’s DNS also, but thankfully the queries happen within the encrypted tunnel.

This post has been edited by dev/numb: Sep 7 2024, 12:06 AM
dev/numb
post Sep 7 2024, 12:17 AM

On my way
****
Junior Member
691 posts

Joined: Nov 2021
QUOTE(PRSXFENG @ Sep 6 2024, 11:59 PM)
for now, it seems like the blocking has been paused for now
*
Fwiw, I actually performed this test last night when I saw that Windows “unable to resolve” error screenshot, not just now after TM realized they screwed up by blocking that art website and unblocked everything.
dev/numb
post Sep 17 2024, 09:39 PM

On my way
****
Junior Member
691 posts

Joined: Nov 2021
QUOTE(PRSXFENG @ Sep 17 2024, 06:52 PM)
“global threat” laugh.gif

 

Change to:
| Lo-Fi Version
0.0193sec    0.19    7 queries    GZIP Disabled
Time is now: 7th December 2025 - 12:04 PM