Welcome Guest ( Log In | Register )

Outline · [ Standard ] · Linear+

 Time and Maxis started to hijack dns query

views
     
laihuhng
post Aug 9 2024, 06:45 PM

On my way
****
Junior Member
603 posts

Joined: Jun 2005


QUOTE(QuantumEdge @ Aug 9 2024, 02:50 PM)
user posted image
Lets go, but I think most Tplink router users wont have such luck?
*
This will not slow down the internet, right?
laihuhng
post Aug 9 2024, 09:07 PM

On my way
****
Junior Member
603 posts

Joined: Jun 2005


QUOTE(QuantumEdge @ Aug 9 2024, 02:50 PM)
user posted image
Lets go, but I think most Tplink router users wont have such luck?
*
user posted image

Let me know if I've configured it correctly. I disabled my ipv6. Thus, I didn't include the ipv6 address. Thanks.
laihuhng
post Aug 9 2024, 11:17 PM

On my way
****
Junior Member
603 posts

Joined: Jun 2005


QUOTE(kwss @ Aug 9 2024, 09:30 PM)
Based on my nmap scan, the domain should be:
dns.adguard.com
EDIT:
If you connect without SNI it will serve you certificate with dns.adguard.com.
With SNI it will serve certificate with dns.adguard-dns.com.
So both works.

Prevent client auto DoH must be set to off. Otherwise Encrypted Client Hello won't work. You want ECH to work on a highly censored network because it prevent the censor from snooping on your SNI.

Unknown:
Did anyone actually MITM or pen test this thing? Given the recent development of TM where they MITM DoH and DoT, the router must absolutely verify the certificate properly.
On Mikrotik, none of this is done!
*
I've set Prevent Client auto DoH to NO. Thanks.


 

Change to:
| Lo-Fi Version
0.0176sec    0.92    7 queries    GZIP Disabled
Time is now: 9th December 2025 - 12:25 PM