Welcome Guest ( Log In | Register )

57 Pages « < 48 49 50 51 52 > » Bottom

Outline · [ Standard ] · Linear+

 It seems TM Unifi has finally implemented, transparent DNS proxy

views
     
SUSlurkingaround
post Sep 6 2024, 11:36 PM

Rule of Law
*******
Senior Member
7,066 posts

Joined: Sep 2019
From: South Klang Valley suburb




QUOTE((mhyug @ Sep 6 2024 @ 10:33 PM)
NEWS FLASH: suddenly all has been unblocked. BUT dont know perma or somethng else brewing

QUOTE(JohnL77 @ Sep 6 2024, 11:13 PM)
Why didn't they announce it before doing it? Would have saved businesses from the financial losses.
*
.
Officially, it was TM Unfi Fibre who unilaterally imposed additional DoH and DoT hijacking of the common Public DNS servers, eg Google8888, Cloudflare1111 and Quad9999, 2 days ago, not MCMC, who only mandated/ordered the ISPs to impose Tansparent DNS Proxy blocking, as per .......

https://www.malaymail.com/news/malaysia/202...roviders/146480 - 2024 Aug 9 - MCMC responds to allegations of DNS tampering by Malaysian internet service providers
KUALA LUMPUR, Aug 9 — The Malaysian Communications and Multimedia Commission (MCMC) has issued a statement following recent reports that Malaysian internet service providers (ISP) had quietly forced all internet traffic to their local DNS servers. As reported earlier, several ISPs have implemented Transparent DNS Proxy, which prevents Malaysian users from accessing blocked sites even if they use alternative DNS such as Google Public DNS and Cloudflare. ...

Following the report by Sinar Project, we verified the claims by testing several blocked websites on several ISPs while using Google and Cloudflare DNS. We noticed that the forced redirection to local DNS was in effect for Time, Maxis, U Mobile, CelcomDigi and Unifi. ....


It's likely that TM Unifi Fibre has realized their mistake and inadvertent negative impact on many businesses/enterprises = undo their DoH/DoT hijacking.

In the first place, why did TM Unifi Fibre did all that and U-Turned, when the other ISPs did not.?, ie imposed DoH/DoT hijacking.
....... Will TM Unifi Fibre do it again by a certain date after informing all their Business subscribers of their intention to impose DoH/DoT hijacking.?

.
P S - This reminds me of the Crowdstrike fiasco.
.

This post has been edited by lurkingaround: Sep 6 2024, 11:37 PM
naTTan
post Sep 7 2024, 12:01 AM

Regular
******
Senior Member
1,138 posts

Joined: Sep 2005


QUOTE(lurkingaround @ Sep 6 2024, 11:36 PM)
.
Officially, it was TM Unfi Fibre who unilaterally imposed additional DoH and DoT hijacking of the common Public DNS servers, eg Google8888, Cloudflare1111 and Quad9999, 2 days ago, not MCMC, who only mandated/ordered the ISPs to impose Tansparent DNS Proxy blocking, as per .......

https://www.malaymail.com/news/malaysia/202...roviders/146480 - 2024 Aug 9 - MCMC responds to allegations of DNS tampering by Malaysian internet service providers
KUALA LUMPUR, Aug 9 — The Malaysian Communications and Multimedia Commission (MCMC) has issued a statement following recent reports that Malaysian internet service providers (ISP) had quietly forced all internet traffic to their local DNS servers. As reported earlier, several ISPs have implemented Transparent DNS Proxy, which prevents Malaysian users from accessing blocked sites even if they use alternative DNS such as Google Public DNS and Cloudflare. ...

Following the report by Sinar Project, we verified the claims by testing several blocked websites on several ISPs while using Google and Cloudflare DNS. We noticed that the forced redirection to local DNS was in effect for Time, Maxis, U Mobile, CelcomDigi and Unifi. ....


It's likely that TM Unifi Fibre has realized their mistake and inadvertent negative impact on many businesses/enterprises = undo their DoH/DoT hijacking.

In the first place, why did TM Unifi Fibre did all that and U-Turned, when the other ISPs did not.?, ie imposed DoH/DoT hijacking.
....... Will TM Unifi Fibre do it again by a certain date after informing all their Business subscribers of their intention to impose DoH/DoT hijacking.?

.
P S - This reminds me of the Crowdstrike fiasco.
.
*
Sorry can explain it in more layman terms. I thought the original plan mmg was to block public DNS

olivur
post Sep 7 2024, 12:09 AM

ollie ollie oxen free
******
Senior Member
1,282 posts

Joined: Jul 2011
QUOTE(Wedchar2912 @ Sep 6 2024, 09:59 PM)
from what I understand, just need the vpn to visit the site for torrent to get the torrent seed file...

after that, can just go back to without vpn... cos it is P2P of all the computers sharing the actual "movie" files.
*
holup have y'all really been downloading torrents bareback

wild if true bro
JohnL77
post Sep 7 2024, 12:11 AM

Regular
******
Senior Member
1,887 posts

Joined: Mar 2013


QUOTE(olivur @ Sep 7 2024, 12:09 AM)
holup have y'all really been downloading torrents bareback

wild if true bro
*
Yep.
soonwai
post Sep 7 2024, 12:11 AM


********
All Stars
11,459 posts

Joined: Oct 2007
From: KL


QUOTE(JohnL77 @ Sep 6 2024, 06:55 PM)
Can we all overload their servers until explode?
*
Dun know what you did but thanks. smile.gif TM's server really exploded.

Quote here first in case got investigation.
SUSlurkingaround
post Sep 7 2024, 12:32 AM

Rule of Law
*******
Senior Member
7,066 posts

Joined: Sep 2019
From: South Klang Valley suburb




QUOTE(naTTan @ Sep 7 2024, 12:01 AM)
Sorry can explain it in more layman terms. I thought the original plan mmg was to block public DNS
*
.
CHRONOLOGY: .......

- since PM6 Najib era - MCMC mandated all the ISPs to block blacklisted or undesirable (eg prawn) websites through their DNS servers which are the default DNS servers for their subscribers. This blocking could be bypassed by tech-savvy subscribers manually selecting their own Public DNS server, either in their OS or browser Setting, eg Google8888, Cloudflare1111, etc. Alternately tech-savvy subscribers could encrypt their DNS traffic by manually selecting Secure DNS (= DoH or DNS over HTTPS) for privacy and security purposes. ISPs can't see encrypted/Secure Public DNS servers.
....... IT admins could even set up their own Secure Private DNS server.

- Early Aug 2024 - PMX's MCMC quietly mandated all the ISPs to impose Transparent DNS Proxy blocking (= DNS blocking) to stop subscribers from using their own (unencrypted) common Public DNS server, eg Google8888, Cloudflare1111, etc. DoH and DoT (= DNS over TLS) were unaffected by this type of blocking. Eg .......
https://imap.sinarproject.org/news/internet...lic-dns-servers - Internet Censorship Update: Transparent DNS Proxy Implemented by Malaysian ISPs on Cloudflare and Google Public DNS Servers
Transparent DNS Proxy Implemented by Malaysian ISPs on Cloudflare and Google Public DNS Servers
6th August 2024 - how to bypass the blocking with DoH


- 2 days ago - TM Unifi Fibre quietly started to impose additional (IP) blocking by hijacking the IP addresses of the commonly used encrypted/Secure Public DNS servers of DoH and DoT, eg Google8888, Cloudflare1111, Quad9999 and Adguard. This was done by TM region by region starting with Klang Valley. Yesterday night, more regions were affected. This sudden move by TM negatively affected many Business subscribers who employ tech-savvy IT admins, eg to secure their DNS servers with DoH or DoT from Cloudflare1111.

- Last night, ie around 10.30pm Friday 06 Sep, TM U-Turned and undid their additional IP blocking of the common Public DNS servers of DoH and DoT. ....
.

This post has been edited by lurkingaround: Sep 7 2024, 01:56 AM
Wedchar2912
post Sep 7 2024, 12:36 AM

Look at all my stars!!
*******
Senior Member
3,684 posts

Joined: Apr 2019
QUOTE(olivur @ Sep 7 2024, 12:09 AM)
holup have y'all really been downloading torrents bareback

wild if true bro
*
why wild? they are just movies and tv series...
vapanel
post Sep 7 2024, 12:37 AM

Regular
******
Senior Member
1,075 posts

Joined: Oct 2022


QUOTE(mhyug @ Sep 6 2024, 10:33 PM)
NEWS FLASH: suddenly all has been unblocked. BUT dont know perma or somethng else brewing
*
kek, those bought VPN must be double kek
PleaseEnterYourName
post Sep 7 2024, 12:38 AM

Casual
***
Junior Member
386 posts

Joined: Jan 2006
From: between 0 and 1


Do gomen knows that gambling sites uses dynamic url to evade blocking? Useless.
PJng
post Sep 7 2024, 12:49 AM

10k Club
********
All Stars
12,054 posts

Joined: Oct 2017


Already? Still cannot access 1337
cypher
post Sep 7 2024, 12:52 AM

CYPHER - CRAPPY SPEAKER
*******
Senior Member
2,118 posts

Joined: Jan 2003
From: Malaysia



so company user unable to access website. We just tell them to call MCMC?
UFO
post Sep 7 2024, 12:54 AM

Getting Started
**
Junior Member
50 posts

Joined: Jan 2003
From: G-Block @ DeadMan WonderLand



Funny, I think we have won they actually press hand brake U-Turn isit ?
I can now access now dns normally already.
cypher
post Sep 7 2024, 12:56 AM

CYPHER - CRAPPY SPEAKER
*******
Senior Member
2,118 posts

Joined: Jan 2003
From: Malaysia



very long time ago, home internet have some blocking, but business internet line no blocking.

they gonna get back fire from business sector.
solarmystic
post Sep 7 2024, 12:57 AM

Getting Started
**
Junior Member
271 posts

Joined: Jun 2009
QUOTE(UFO @ Sep 7 2024, 12:54 AM)
Funny, I think we have won they actually press hand brake U-Turn isit ?
I can now access now dns normally already.
*
According to the TM Unifi thread, it seems like TM has reversed the DNS hijacking since around 10:25pm earlier Friday night.

https://forum.lowyat.net/topic/5424552/+6060#

Could be temporary though.

This post has been edited by solarmystic: Sep 7 2024, 12:58 AM
cypher
post Sep 7 2024, 01:00 AM

CYPHER - CRAPPY SPEAKER
*******
Senior Member
2,118 posts

Joined: Jan 2003
From: Malaysia



QUOTE(solarmystic @ Sep 7 2024, 12:57 AM)
According to the TM Unifi thread, it seems like TM has reversed the DNS hijacking since around 10:25pm earlier Friday night.

https://forum.lowyat.net/topic/5424552/+6060#

Could be temporary though.
*
getting too many support call...
olivur
post Sep 7 2024, 01:20 AM

ollie ollie oxen free
******
Senior Member
1,282 posts

Joined: Jul 2011
QUOTE(JohnL77 @ Sep 7 2024, 12:11 AM)
Yep.
*
QUOTE(Wedchar2912 @ Sep 7 2024, 12:36 AM)
why wild? they are just movies and tv series...
*
we banking on our isps not caring that much or ..

user posted image

This post has been edited by olivur: Sep 7 2024, 01:21 AM
JohnL77
post Sep 7 2024, 01:30 AM

Regular
******
Senior Member
1,887 posts

Joined: Mar 2013


QUOTE(olivur @ Sep 7 2024, 01:20 AM)
we banking on our isps not caring that much or ..

user posted image
*
Well, until recently...
soonwai
post Sep 7 2024, 02:05 AM


********
All Stars
11,459 posts

Joined: Oct 2007
From: KL


Shit, it's back...
tanjinpang P
post Sep 7 2024, 02:48 AM

New Member
*
Probation
0 posts

Joined: Mar 2022


QUOTE(PleaseEnterYourName @ Sep 7 2024, 12:38 AM)
Do gomen knows that gambling sites uses dynamic url to evade blocking? Useless.
*
This just show their intention is not to block those scam or gambling site, but to do network surveillance.
vapanel
post Sep 7 2024, 02:48 AM

Regular
******
Senior Member
1,075 posts

Joined: Oct 2022


QUOTE(soonwai @ Sep 7 2024, 02:05 AM)
Shit, it's back...
*
Here in northern state still fine

57 Pages « < 48 49 50 51 52 > » Top
 

Change to:
| Lo-Fi Version
0.0199sec    1.09    6 queries    GZIP Disabled
Time is now: 19th December 2025 - 02:35 PM