Welcome Guest ( Log In | Register )

57 Pages « < 7 8 9 10 11 > » Bottom

Outline · [ Standard ] · Linear+

 It seems TM Unifi has finally implemented, transparent DNS proxy

views
     
zerorating
post Sep 3 2024, 10:57 PM

Miskin Adab
*****
Senior Member
977 posts

Joined: Aug 2007
From: Lokap Polis


QUOTE(kmrdeva @ Sep 3 2024, 10:25 PM)
What connection are you on?

On my Win11 PCs, I've enabled secure DNS (in Edge browser) and adguard (Edge extension) - websites load just fine.
*
TM proxy implementation is by stages.
they cant have a single server cluster handles the task of hijacking every users dns requests.
kmrdeva
post Sep 3 2024, 11:02 PM

Look at all my stars!!
*******
Senior Member
4,792 posts

Joined: Jan 2003
QUOTE(zerorating @ Sep 3 2024, 10:57 PM)
TM proxy implementation is by stages.
they cant have a single server cluster handles the task of hijacking every users dns requests.
*
I'm on time fibre though. remember reading that time had implemented this way before tm.
zerorating
post Sep 3 2024, 11:08 PM

Miskin Adab
*****
Senior Member
977 posts

Joined: Aug 2007
From: Lokap Polis


QUOTE(kmrdeva @ Sep 3 2024, 11:02 PM)
I'm on time fibre though. remember reading that time had implemented this way before tm.
*
but time didnt cover DoH and DoT right?
hopefully SKMM didnt mandate those blocking lel.
Weisun79
post Sep 3 2024, 11:12 PM

New Member
*
Newbie
42 posts

Joined: Sep 2013
i tried.. Firefox... enable Increased Protection.. Chooose NextDNS as provider... it works....

or Use Safari...

user posted image
zerorating
post Sep 3 2024, 11:13 PM

Miskin Adab
*****
Senior Member
977 posts

Joined: Aug 2007
From: Lokap Polis


QUOTE(Weisun79 @ Sep 3 2024, 11:12 PM)
i tried.. Firefox... enable Increased Protection.. Chooose NextDNS as provider... it works....

or Use Safari...

user posted image
*
cloudflare and google dont work?

failed.hashcheck
post Sep 3 2024, 11:24 PM

Neighborhood plant pathologist
*******
Senior Member
2,096 posts

Joined: Aug 2009
From: Shithole Klang
QUOTE(Weisun79 @ Sep 3 2024, 11:12 PM)
i tried.. Firefox... enable Increased Protection.. Chooose NextDNS as provider... it works....

or Use Safari...

user posted image
*
or if you use win11, just use OS level DoH at network setting.
Attached Image

This post has been edited by failed.hashcheck: Sep 3 2024, 11:27 PM
zerorating
post Sep 3 2024, 11:29 PM

Miskin Adab
*****
Senior Member
977 posts

Joined: Aug 2007
From: Lokap Polis


QUOTE(failed.hashcheck @ Sep 3 2024, 11:24 PM)
or if you use win11, just use OS level DoH at network setting.
*
just read unifi thread, TM just reroute google dns or cloudflare to their TM dns resource. looks like TM use the most efficient method without provisioning tons of servers for transparent proxy. such evil.

failed.hashcheck
post Sep 3 2024, 11:37 PM

Neighborhood plant pathologist
*******
Senior Member
2,096 posts

Joined: Aug 2009
From: Shithole Klang
QUOTE(zerorating @ Sep 3 2024, 11:29 PM)
just read unifi thread, TM just reroute google dns or cloudflare to their TM dns resource. looks like TM use the most efficient method without provisioning tons of servers for transparent proxy. such evil.
*
that only for plaintext dns right?
Even with DoT they could only block at most.
If they could tamper DoH, like rerouting and return a valid response without hijacking browser certificate, I think we have global IT emergency right now since that means TLS 1.3 has been broken.
zerorating
post Sep 3 2024, 11:41 PM

Miskin Adab
*****
Senior Member
977 posts

Joined: Aug 2007
From: Lokap Polis


QUOTE(failed.hashcheck @ Sep 3 2024, 11:37 PM)
that only for plaintext dns right?
Even with DoT they could only block at most.
If they could tamper DoH, like rerouting and return a valid response without hijacking browser certificate, I think we have global IT emergency right now since that means TLS 1.3 has been broken.
*
IP level la boss, meaning plaintext, dot, doh all redirected.

doh will not work without valid cert.

anyway, i will move to "not widely" known public dns service, koff koff ans1.Singapore3.Level3.net,ans2.Singapore3.Level3.net
AIMS also have DNS server that not filtering ahem site. IP is 110.74.147.67

alibaba also (47.254.217.105), (may send data to CCP)

This post has been edited by zerorating: Sep 3 2024, 11:53 PM
failed.hashcheck
post Sep 3 2024, 11:57 PM

Neighborhood plant pathologist
*******
Senior Member
2,096 posts

Joined: Aug 2009
From: Shithole Klang
QUOTE(zerorating @ Sep 3 2024, 11:41 PM)
IP level la boss, meaning plaintext, dot, doh all redirected.

doh will not work without valid cert.

anyway, i will move to "not widely" known public dns service, koff koff ans1.Singapore3.Level3.net
AIMS also have DNS server that not filtering ahem site. IP is 110.74.147.67
*
kek so DoH simply stop working then

When that finally happen to me I'll just fire up unbound and spawn my own DNS server.
Finally got some real legit use for those Oracle Compute instances that I don't know what to do other than hosting hentai@home laugh.gif
soonwai
post Sep 4 2024, 01:03 AM


********
All Stars
11,460 posts

Joined: Oct 2007
From: KL


QUOTE(failed.hashcheck @ Sep 3 2024, 11:57 PM)
kek so DoH simply stop working then

When that finally happen to me I'll just fire up unbound and  spawn my own DNS server.
Finally got some real legit use for those Oracle Compute instances that I don't know what to do other than hosting hentai@home  laugh.gif
*
everything stop working. even Google dns website also they berani hantam. cos TM curi the whole 8.8.8.8 IP.

user posted image
Before

user posted image
After. You can also click Advanced to look at the SSL cert.


soonwai
post Sep 4 2024, 01:05 AM


********
All Stars
11,460 posts

Joined: Oct 2007
From: KL


Not all ppl affected though so means TM just testing je. So far:

Kajang ❌❌ me & raynman
Kuching ✅ karenzayn
Penang ✅ tng55
PJ ✅ countingcrows
cloudstrife07
post Sep 4 2024, 01:06 AM

I'm back, beaches!
*******
Senior Member
4,688 posts

Joined: Jan 2003
From: http://127.0.0.1


QUOTE(failed.hashcheck @ Sep 3 2024, 11:57 PM)
kek so DoH simply stop working then

When that finally happen to me I'll just fire up unbound and  spawn my own DNS server.
Finally got some real legit use for those Oracle Compute instances that I don't know what to do other than hosting hentai@home  laugh.gif
*
Wah masih lagi run h@h
brkli
post Sep 4 2024, 01:08 AM

On my way
****
Junior Member
592 posts

Joined: Oct 2018
QUOTE(zerorating @ Sep 3 2024, 11:29 PM)
just read unifi thread, TM just reroute google dns or cloudflare to their TM dns resource. looks like TM use the most efficient method without provisioning tons of servers for transparent proxy. such evil.
*
if using TLS, they cannot just simply reroute it just like that. unless they want to break the connection and functionality. reason being the decryption key only exist in google /cloudflare server. public only have the encryption key (public key) to encrypt the payload to send over, so yeah.
soonwai
post Sep 4 2024, 01:12 AM


********
All Stars
11,460 posts

Joined: Oct 2007
From: KL


QUOTE(brkli @ Sep 4 2024, 01:08 AM)
if using TLS, they cannot just simply reroute it just like that. unless they want to break the connection and functionality. reason being the decryption key only exist in google /cloudflare server. public only have the encryption key (public key) to encrypt the payload to send over, so yeah.
*
Already broken. TM's google, cloudflare, opendns & cleanbrowsing dun have DoH or DoT capabilities. No point since they dun have the cert.
zerorating
post Sep 4 2024, 01:13 AM

Miskin Adab
*****
Senior Member
977 posts

Joined: Aug 2007
From: Lokap Polis


QUOTE(brkli @ Sep 4 2024, 01:08 AM)
if using TLS, they cannot just simply reroute it just like that. unless they want to break the connection and functionality. reason being the decryption key only exist in google /cloudflare server. public only have the encryption key (public key) to encrypt the payload to send over, so yeah.
*
they just add static route,have a server that was assigned with IP 8.8.8.8,8.8.4.4, 1.1.1.1(not internet facing) with its job were redirecting all traffic meant for port 53,443 to their DNS server (dns.tm.net.my). totally blocks doh and dot service. tm dns dont support dot and doh, so it wont work at all.

anyway, the leftover workaround were just the alternative public dns, hopefully TM dont block it too.

This post has been edited by zerorating: Sep 4 2024, 02:36 AM
soonwai
post Sep 4 2024, 01:15 AM


********
All Stars
11,460 posts

Joined: Oct 2007
From: KL


take some, give some.

If using Cleanbrowsing-Adult DNS, (185.228.168.10 & 185.228.168.11) last time cannot access www.porno hammer.com.

Now with TM's "upgraded" Cleanbrowsing-Adult DNS (185.228.168.10), can.

TQ TM
zerorating
post Sep 4 2024, 01:25 AM

Miskin Adab
*****
Senior Member
977 posts

Joined: Aug 2007
From: Lokap Polis


QUOTE(soonwai @ Sep 4 2024, 01:15 AM)
take some, give some.

If using Cleanbrowsing-Adult DNS, (185.228.168.10 & 185.228.168.11) last time cannot access www.porno hammer.com.

Now with TM's "upgraded" Cleanbrowsing-Adult DNS (185.228.168.10), can.

TQ TM
*
TM have dns server that dont follow mcmc guideline.
175.139.1.45
175.139.156.45
failed.hashcheck
post Sep 4 2024, 01:30 AM

Neighborhood plant pathologist
*******
Senior Member
2,096 posts

Joined: Aug 2009
From: Shithole Klang
QUOTE(soonwai @ Sep 4 2024, 01:05 AM)
Not all ppl affected though so means TM just testing je. So far:

Kajang ❌❌ me & raynman
Kuching ✅ karenzayn
Penang ✅ tng55
PJ ✅ countingcrows
*
Hard to imagine they would make this standard. The stake is too damn high.
Right now Google have lots of their apps hardwired to their (cleartext) DNS, and it's not unreasonable to see they will go further with DoT in future.
Shit going to hit the fan really hard when that day finally come.

QUOTE(cloudstrife07 @ Sep 4 2024, 01:06 AM)
Wah masih lagi run h@h
*
At some point few years ago Oracle realized they are being stupidly generous offering a rather thicc instances for free (up to 4 micro instances with pooled 200gb storage and up to 24gb ram). And now they will terminate and reclaim those that they deemed underused for 7 consecutive days.

So I have to generate some CPU/ram and traffic to keep my holding, and apparently h@h is perfect for that 🤣
annoymous1234
post Sep 4 2024, 01:33 AM

Look at all my stars!!
*******
Senior Member
7,617 posts

Joined: Mar 2009

In other words, changing to DOH and DOT doesn't work anymore right?

This post has been edited by annoymous1234: Sep 4 2024, 01:34 AM

57 Pages « < 7 8 9 10 11 > » Top
 

Change to:
| Lo-Fi Version
0.0272sec    0.96    6 queries    GZIP Disabled
Time is now: 24th December 2025 - 04:06 PM