Welcome Guest ( Log In | Register )

57 Pages « < 14 15 16 17 18 > » Bottom

Outline · [ Standard ] · Linear+

 It seems TM Unifi has finally implemented, transparent DNS proxy

views
     
kwss
post Sep 4 2024, 07:25 PM

Regular
******
Senior Member
1,208 posts

Joined: Aug 2018
Cross posting from Unifi thread for those who didn't go there. Running cost should be less than USD $0.60 per month

DNS wall climbing for beginner
This quick guide will teach you how to use CDN to front DoH server using Amazon CloudFront.
The benefit this provides over other method is the difficulty of the censor to block this kind of setup without blocking the whole CDN provider.

Requirements:
AWS Account
Browser / OS / resolver supporting DoH

Login to your AWS account and search for CloudFront. Create a new distribution.
Refer to the setting below and put in your desired DoH server:
user posted image

After you are done creating the distribution, wait for it to finish deploying:
user posted image

Put the address and the full path into your browser / OS / resolver:
user posted image

Finally test your resolver:
user posted image

DNS wall climbing stealth setup
This is a setup for people who are already using CloudFront for their business and wish to hide DoH inside it.
I am using ControlD here instead of Cloudflare DNS. The "/dns-query" in cloudflare is "/p0" in controld.

First add an Origin like below:
user posted image

Then add a Behavior:
user posted image

Wait for it to finish deploying. You will access it via https://mydomain.com/bkaj41f

For people wondering what is my "DoH-fronting" policy, here is it:
user posted image
failed.hashcheck
post Sep 4 2024, 07:31 PM

Neighborhood plant pathologist
*******
Senior Member
2,096 posts

Joined: Aug 2009
From: Shithole Klang
QUOTE(kwss @ Sep 4 2024, 07:25 PM)
Cross posting from Unifi thread for those who didn't go there. Running cost should be less than USD $0.60 per month

DNS wall climbing for beginner
This quick guide will teach you how to use CDN to front DoH server using Amazon CloudFront.
The benefit this provides over other method is the difficulty of the censor to block this kind of setup without blocking the whole CDN provider.

Requirements:
AWS Account
Browser / OS / resolver supporting DoH

Login to your AWS account and search for CloudFront. Create a new distribution.
Refer to the setting below and put in your desired DoH server:
user posted image

After you are done creating the distribution, wait for it to finish deploying:
user posted image

Put the address and the full path into your browser / OS / resolver:
user posted image

Finally test your resolver:
user posted image

DNS wall climbing stealth setup
This is a setup for people who are already using CloudFront for their business and wish to hide DoH inside it.
I am using ControlD here instead of Cloudflare DNS. The "/dns-query" in cloudflare is "/p0" in controld.

First add an Origin like below:
user posted image

Then add a Behavior:
user posted image

Wait for it to finish deploying. You will access it via https://mydomain.com/bkaj41f

For people wondering what is my "DoH-fronting" policy, here is it:
user posted image
*
if like this its much cheaper and easier to just buy nat vps in sg and set up wireguard blink.gif
kwss
post Sep 4 2024, 07:33 PM

Regular
******
Senior Member
1,208 posts

Joined: Aug 2018
QUOTE(failed.hashcheck @ Sep 4 2024, 07:31 PM)
if like this its much cheaper and easier to just buy nat vps in sg and set up wireguard  blink.gif
*
It is...
Actually my USD $0.60 calculation involved some very serious usage.
My current bill for this setup is only USD $0.01
seiferalmercy
post Sep 4 2024, 07:35 PM

Getting Started
**
Junior Member
135 posts

Joined: May 2010


sigh, now cannot access my research database anymore
vapanel
post Sep 4 2024, 07:39 PM

Regular
******
Senior Member
1,075 posts

Joined: Oct 2022


So this is not nationwide?

I can still access everything
SUSraynman
post Sep 4 2024, 07:39 PM

Look at all my stars!!
*******
Senior Member
4,333 posts

Joined: Jan 2003


QUOTE(seiferalmercy @ Sep 4 2024, 07:35 PM)
sigh, now cannot access my research database anymore
*
No choice have to use a VPN
soonwai
post Sep 4 2024, 07:47 PM


********
All Stars
11,459 posts

Joined: Oct 2007
From: KL


QUOTE(vapanel @ Sep 4 2024, 07:39 PM)
So this is not nationwide?

I can still access everything
*
Mostly Klang Valley for now and not all parts but Kajang for sure. Penang, Negeri & JB still ok. Where you?
JohnL77
post Sep 4 2024, 07:48 PM

Regular
******
Senior Member
1,887 posts

Joined: Mar 2013


QUOTE(loserguy @ Sep 4 2024, 07:07 PM)
It is also possible to self host your own DNS server.

The problem is, once you start something like this, the majority of people will be too lazy to do anything.

Kalau dulu 10000 pipu layan blocked website, vs 10 pipu layan blocked website, u sked or not?
*
Honestly, I oso will give up if they go so extreme. If they don't want honest feedback from the rakyat then go ahead just censor us all la. What's the point of sharing information that the majority doesn't have anyway? See I shared information during COVID but you all hate me call me antivax, tried to doxx me, tried to get me arrested.

Fuck la study until Cambridge oso come back here and toe the party like. They are all the same.
soul78
post Sep 4 2024, 07:48 PM

Enthusiast
*****
Junior Member
937 posts

Joined: Jul 2005


https://www.mysterium.network

for those who wanna go down decentralized vpns
JohnL77
post Sep 4 2024, 07:51 PM

Regular
******
Senior Member
1,887 posts

Joined: Mar 2013


QUOTE(seiferalmercy @ Sep 4 2024, 07:35 PM)
sigh, now cannot access my research database anymore
*
People laughed when I said I don't stream.

The painful part is one of my nuclear codes drive died shortly before they started implementing Great Firewall. Not sure if I'll have the chance to recollect everything.
Skylinestar
post Sep 4 2024, 07:52 PM

Mega Duck
********
All Stars
10,478 posts

Joined: Jan 2003
From: Sarawak
QUOTE(soonwai @ Sep 4 2024, 06:39 PM)
Just go https://8.8.8.8 (https://google.dns)
user posted image
If you're not affected.

Nothing to do with DNS.
*
what does it mean? i just visited this website. icon_question.gif
soonwai
post Sep 4 2024, 07:55 PM


********
All Stars
11,459 posts

Joined: Oct 2007
From: KL


QUOTE(Skylinestar @ Sep 4 2024, 07:52 PM)
what does it mean? i just visited this website. icon_question.gif
*
You can still connect to the real Google DNS server. So means your area not affected yet. Where are you?


This post has been edited by soonwai: Sep 4 2024, 07:56 PM
syahpian
post Sep 4 2024, 08:01 PM

Enthusiast
*****
Junior Member
814 posts

Joined: Jul 2008
From: Kota Kinabalu <-> Kuala Lumpur


QUOTE(soul78 @ Sep 4 2024, 07:48 PM)
https://www.mysterium.network

for those who wanna go down decentralized vpns
*
sentinel better, they have free app and telegram bot biggrin.gif
Oltromen Ripot
post Sep 4 2024, 08:01 PM

👍 999999 person Likes this member
*******
Senior Member
4,034 posts

Joined: Dec 2019
QUOTE(Skylinestar @ Sep 4 2024, 07:52 PM)
what does it mean? i just visited this website. icon_question.gif
*
https website needs valid certificate
- valid issuing authority
- valid owning organisation
- valid certificate's start and expiry dates
- certificate name matches the name of respurce being accessed

if you can browse https://dns.google without issue, that means everything is hunky dory.

but if you tried to browse it and get presented with a invalid certificate, and your system clock is correct, it's probably another non-Google entity pretending to be Google, without access to valid Google-owned certificate.

OR, if you can't load it at all and you are certain your internet connection is up, highly likely it is blocked altogether to prevent DoH.

(DNS-over-HTTPS uses tcp/443 just like any other default SSL web hosting.)

This post has been edited by Oltromen Ripot: Sep 4 2024, 08:02 PM
JimbeamofNRT
post Sep 4 2024, 08:05 PM

the Original Lanji@_ Chicken Rice Shop Since 2002
******
Senior Member
1,902 posts

Joined: Sep 2012

QUOTE(soonwai @ Sep 4 2024, 07:55 PM)
You can still connect to the real Google DNS server. So means your area not affected yet. Where are you?
*
muahahaha

all your base are belong to us

user posted image

This post has been edited by JimbeamofNRT: Sep 4 2024, 08:07 PM
loserguy
post Sep 4 2024, 08:30 PM

On my way
****
Junior Member
500 posts

Joined: Dec 2019
QUOTE(JohnL77 @ Sep 4 2024, 07:48 PM)
Honestly, I oso will give up if they go so extreme. If they don't want honest feedback from the rakyat then go ahead just censor us all la. What's the point of sharing  information that the majority doesn't have anyway? See I shared information during COVID but you all hate me call me antivax, tried to doxx me, tried to get me arrested.

Fuck la study until Cambridge oso come back here and toe the party like. They are all the same.
*
I think there should be a balance between free speech and moderation.

All the while we believe in self policing and society self correcting the fringe. Just leave unpopular opinions alone, so that people can see and make up their own minds. I may disagree with what you say, but I will absolutely defend your right to say it. But that was a different time, where passersby can just ignore the crazy person shouting in a corner. Nowadays, via social media, everybody has a global reach.

A lot of people, myself included, got pretty nervous looking at what happened in the UK.

Is the current DNS hijacking overkill? Maybe. But looking at the wild wild west in most social media sites (Facebook, TikTok), I sometimes do wish there would be some form of moderation there.

JohnL77
post Sep 4 2024, 08:31 PM

Regular
******
Senior Member
1,887 posts

Joined: Mar 2013


QUOTE(loserguy @ Sep 4 2024, 08:30 PM)
I think there should be a balance between free speech and moderation.

All the while we believe in self policing and society self correcting the fringe. Just leave unpopular opinions alone, so that people can see and make up their own minds. I may disagree with what you say, but I will absolutely defend your right to say it. But that was a different time, where passersby can just ignore the crazy person shouting in a corner. Nowadays, via social media, everybody has a global reach.

A lot of people, myself included, got pretty nervous looking at what happened in the UK.

Is the current DNS hijacking overkill? Maybe. But looking at the wild wild west in most social media sites (Facebook, TikTok), I sometimes do wish there would be some form of moderation there.
*
Apa sarahan iHerb?
loserguy
post Sep 4 2024, 08:34 PM

On my way
****
Junior Member
500 posts

Joined: Dec 2019
QUOTE(JohnL77 @ Sep 4 2024, 08:31 PM)
Apa sarahan iHerb?
*
Is the current DNS hijacking overkill? Maybe.
Quantum Geist
post Sep 4 2024, 08:40 PM

Getting Started
**
Junior Member
109 posts

Joined: May 2013


QUOTE(loserguy @ Sep 4 2024, 08:30 PM)
I think there should be a balance between free speech and moderation.

All the while we believe in self policing and society self correcting the fringe. Just leave unpopular opinions alone, so that people can see and make up their own minds. I may disagree with what you say, but I will absolutely defend your right to say it. But that was a different time, where passersby can just ignore the crazy person shouting in a corner. Nowadays, via social media, everybody has a global reach.

A lot of people, myself included, got pretty nervous looking at what happened in the UK.

Is the current DNS hijacking overkill? Maybe. But looking at the wild wild west in most social media sites (Facebook, TikTok), I sometimes do wish there would be some form of moderation there.
*
It's a slippery slope, if the current government doesn't abuse the blocking mechanism (which is arguable), then what about the next one, and the one after that and so on. Frankly putting the blocking mechanism in place just opens up a can of worms instead of closing (censoring) it.
poooky
post Sep 4 2024, 08:53 PM

Enthusiast
*****
Junior Member
844 posts

Joined: Sep 2011
is there a simple solution around this? or need to us VPN?

57 Pages « < 14 15 16 17 18 > » Top
 

Change to:
| Lo-Fi Version
0.0247sec    1.03    6 queries    GZIP Disabled
Time is now: 18th December 2025 - 04:26 AM