Welcome Guest ( Log In | Register )

3 Pages  1 2 3 >Bottom

Outline · [ Standard ] · Linear+

 It seems TM Unifi has finally implemented, transparent DNS proxy

views
     
SUSraynman
post Sep 2 2024, 05:23 AM, updated 2y ago

Look at all my stars!!
*******
Senior Member
4,333 posts

Joined: Jan 2003





My Cloudfare secure DNS on TM Unifi does not work anymore

After disabling Cloudflare secure DNS in my browser, most of my ahem websites are inaccessible.

Anyone facing the same problem?

It seems VPN is the only way out now
isr25
post Sep 2 2024, 05:32 AM

Regular
******
Senior Member
1,263 posts

Joined: Nov 2009
From: Johor Bahru



user posted image

Mine still working as normal

-edit- although maybe it’s because I enabled DNS over TLS on my router

This post has been edited by isr25: Sep 2 2024, 05:35 AM
kimochi ii
post Sep 2 2024, 05:32 AM

New Member
*
Junior Member
19 posts

Joined: Mar 2022
QUOTE(isr25 @ Sep 2 2024, 05:32 AM)
user posted image

Mine still working as normal
*
🤔
DarkAeon
post Sep 2 2024, 05:43 AM

Enthusiast
*****
Senior Member
774 posts

Joined: Nov 2010
they are preparing for plan b if the socmed don't apply for their license. block everyone. lol
SUSraynman
post Sep 2 2024, 05:48 AM

Look at all my stars!!
*******
Senior Member
4,333 posts

Joined: Jan 2003


QUOTE(DarkAeon @ Sep 2 2024, 05:43 AM)
they are preparing for plan b if the socmed don't apply for their license. block everyone. lol
*
I am quite sure the socmed giants will not apply for license.

They have sounded out earlier
DarkAeon
post Sep 2 2024, 05:51 AM

Enthusiast
*****
Senior Member
774 posts

Joined: Nov 2010
QUOTE(raynman @ Sep 2 2024, 05:48 AM)
I am quite sure the socmed giants will not apply for license.

They have sounded out earlier
*
yea, that's why they are focing all isp to do this now

but those in the know can defeat this easily
SUSraynman
post Sep 2 2024, 05:55 AM

Look at all my stars!!
*******
Senior Member
4,333 posts

Joined: Jan 2003


QUOTE(isr25 @ Sep 2 2024, 05:32 AM)
Mine still working as normal

-edit- although maybe it’s because I enabled DNS over TLS on my router
*
Which alternate DNS do you use? Cloudflare or Google?

isr25
post Sep 2 2024, 06:06 AM

Regular
******
Senior Member
1,263 posts

Joined: Nov 2009
From: Johor Bahru



QUOTE(raynman @ Sep 2 2024, 05:55 AM)
Which alternate DNS do you use? Cloudflare or Google?
*
My full DNS settings

user posted image
SUSraynman
post Sep 2 2024, 06:09 AM

Look at all my stars!!
*******
Senior Member
4,333 posts

Joined: Jan 2003


QUOTE(isr25 @ Sep 2 2024, 06:06 AM)
My full DNS settings

*
My router does not have this feature.

What brand/model is yours?

isr25
post Sep 2 2024, 06:13 AM

Regular
******
Senior Member
1,263 posts

Joined: Nov 2009
From: Johor Bahru



QUOTE(raynman @ Sep 2 2024, 06:09 AM)
My router does not have this feature.

What brand/model is yours?
*
Asus AX86U. Now replaced by Asus AX86U Pro
DarkNite
post Sep 2 2024, 06:24 AM

ФĻĐ ИΞШB!Ξ
********
All Stars
11,058 posts

Joined: Jun 2008
QUOTE(raynman @ Sep 2 2024, 06:09 AM)
My router does not have this feature.

What brand/model is yours?
*
What's brand/model?
beverlykho
post Sep 2 2024, 06:24 AM

On my way
****
Junior Member
501 posts

Joined: Dec 2007


QUOTE(DarkAeon @ Sep 2 2024, 05:43 AM)
they are preparing for plan b if the socmed don't apply for their license. block everyone. lol
*
Here comes the Great Internet Wall of Malaysia (GIWM) a.k.a Tembok Besar Internet Malaysia (TBIM).
dagnarus
post Sep 2 2024, 06:33 AM

Casual
***
Junior Member
328 posts

Joined: Jul 2008


Malaysia ke Aras kuada besar Dunia!
zerorating
post Sep 2 2024, 06:35 AM

Miskin Adab
*****
Senior Member
975 posts

Joined: Aug 2007
From: Lokap Polis


still working here.
user posted image

anyway unsecure DNS still working for me, will keep using it until the game is over
jonthebaptist
post Sep 2 2024, 06:46 AM

Regular
******
Senior Member
1,036 posts

Joined: Sep 2022
Didn't have to go through this shit under Bijan
pureawesomeness
post Sep 2 2024, 06:49 AM

Getting Started
**
Junior Member
191 posts

Joined: Oct 2021
Good la. It's for the benefit and safety of our own people.
poco loco
post Sep 2 2024, 06:51 AM

On my way
****
Junior Member
611 posts

Joined: Sep 2022
From: Last member of the tribe


so 8.8.8.8
8.8.4.4
will no longer work la?
smallbug
post Sep 2 2024, 06:57 AM

Enthusiast
*****
Senior Member
874 posts

Joined: Nov 2005


will affect torrenting or not?
jueiri
post Sep 2 2024, 06:59 AM

Getting Started
**
Junior Member
158 posts

Joined: Mar 2011
Last taim Mamak promised no internet censorship.
Quantum Geist
post Sep 2 2024, 07:00 AM

Getting Started
**
Junior Member
109 posts

Joined: May 2013


mine still ok, dnssec not complaining anything too

user posted image
novblaze
post Sep 2 2024, 07:00 AM

Casual
***
Junior Member
328 posts

Joined: Jan 2015
Unifi any good promo now?
I using expensive Internet now
moiskyrie
post Sep 2 2024, 07:01 AM

Look at all my stars!!
*******
Senior Member
3,217 posts

Joined: Dec 2006
From: City of Neko~~Nyaa~
Damn...
No wonder some of my manga can't loading.....
DarkAeon
post Sep 2 2024, 07:02 AM

Enthusiast
*****
Senior Member
774 posts

Joined: Nov 2010
QUOTE(poco loco @ Sep 2 2024, 06:51 AM)
so 8.8.8.8
8.8.4.4
will no longer work la?
*
google DNS over HTTPS (DoH) or DNS over TLS (DoT)
zerorating
post Sep 2 2024, 07:10 AM

Miskin Adab
*****
Senior Member
975 posts

Joined: Aug 2007
From: Lokap Polis


QUOTE(jonthebaptist @ Sep 2 2024, 06:46 AM)
Didn't have to go through this shit under Bijan
*
site blocking via dns were there since ages. it just step up the game now.
dest9116
post Sep 2 2024, 07:24 AM

Casual
***
Junior Member
495 posts

Joined: Apr 2019
Me OK je, boleh je access, which site cannot?
hyperwavedrift
post Sep 2 2024, 07:29 AM

Getting Started
**
Junior Member
89 posts

Joined: Mar 2017
QUOTE(isr25 @ Sep 2 2024, 06:06 AM)
My full DNS settings

user posted image
*
Is this router settings?
kmrdeva
post Sep 2 2024, 07:30 AM

Look at all my stars!!
*******
Senior Member
4,790 posts

Joined: Jan 2003
QUOTE(isr25 @ Sep 2 2024, 06:06 AM)
My full DNS settings

user posted image
*
Asus router FTW.
yushin
post Sep 2 2024, 07:31 AM

Look at all my stars!!
*******
Senior Member
3,329 posts

Joined: Jan 2003
From: Selangor


QUOTE(kmrdeva @ Sep 2 2024, 07:30 AM)
Asus router FTW.
*
Hmm.. Microtik routers should have similar thing too.
isr25
post Sep 2 2024, 07:32 AM

Regular
******
Senior Member
1,263 posts

Joined: Nov 2009
From: Johor Bahru



QUOTE(dest9116 @ Sep 2 2024, 07:24 AM)
Me OK je, boleh je access, which site cannot?
*
https://github.com/citizenlab/test-lists/bl...er/lists/my.csv
Search for POLR category e.g. https://murrayhunter.substack.com/

QUOTE(hyperwavedrift @ Sep 2 2024, 07:29 AM)
Is this router settings?
*
Asus Router, yes

This post has been edited by isr25: Sep 2 2024, 07:35 AM
SUSraynman
post Sep 2 2024, 07:34 AM

Look at all my stars!!
*******
Senior Member
4,333 posts

Joined: Jan 2003


QUOTE(smallbug @ Sep 2 2024, 06:57 AM)
will affect torrenting or not?
*
Most torrent sites are blocked by MCMC.

I can't find one which is still accessible, unless I use VPN
LamboSama
post Sep 2 2024, 07:40 AM

Enthusiast
*****
Junior Member
769 posts

Joined: Aug 2011
Cukuur puas successfully censor internet. Oh wai...
cms
post Sep 2 2024, 07:42 AM

Enthusiast
*****
Junior Member
763 posts

Joined: Jan 2003
QUOTE(jueiri @ Sep 2 2024, 06:59 AM)
Last taim Mamak promised no internet censorship.
*
He also promised W2020
Lancer07
post Sep 2 2024, 07:44 AM

On my way
****
Junior Member
599 posts

Joined: Jul 2021
My browser still fine, can access the ahen sites
dest9116
post Sep 2 2024, 07:44 AM

Casual
***
Junior Member
495 posts

Joined: Apr 2019
QUOTE(isr25 @ Sep 2 2024, 07:32 AM)
OK je me buka. I just set dns setting in my router the same place me key in user and password. No go anywhere advance also
SUSNihonmaru
post Sep 2 2024, 07:44 AM

Getting Started
**
Junior Member
206 posts

Joined: Aug 2021

Want to block socmed like sino
jibpek
post Sep 2 2024, 07:46 AM

Enthusiast
*****
Junior Member
708 posts

Joined: Jul 2012
tracert -d 8.8.8.8

Tracing route to 8.8.8.8 over a maximum of 30 hops

1 1 ms 1 ms 1 ms 192.168.0.1
2 4 ms 4 ms 5 ms [obscured]
3 4 ms 4 ms 5 ms [obscured]
4 5 ms 5 ms 4 ms 10.55.48.16 <- TMNUT proxy
5 6 ms 5 ms 5 ms 72.14.204.208
6 8 ms 7 ms 6 ms 216.239.63.159
7 7 ms 6 ms 6 ms 142.251.255.29
8 5 ms 6 ms 5 ms 8.8.8.8

Trace complete.
God Grid
post Sep 2 2024, 07:48 AM

New Member
*
Junior Member
35 posts

Joined: Aug 2021
we are anti-communist!!!!

we hate communist!!!!

but malaysia also became a communist country

hahahahahhaa fucking sei sohai people all

say anti-commie, but sendiri also commie

fuck you all la!
hyperwavedrift
post Sep 2 2024, 07:49 AM

Getting Started
**
Junior Member
89 posts

Joined: Mar 2017
QUOTE(isr25 @ Sep 2 2024, 06:13 AM)
Asus AX86U. Now replaced by Asus AX86U Pro
*
holy shit this thing is like rm 1.5k
SUSKaya Butter Toast
post Sep 2 2024, 07:50 AM

Casual
***
Junior Member
325 posts

Joined: Feb 2022

Fark madani
jibpek
post Sep 2 2024, 07:51 AM

Enthusiast
*****
Junior Member
708 posts

Joined: Jul 2012
QUOTE(hyperwavedrift @ Sep 2 2024, 07:49 AM)
holy shit this thing is like rm 1.5k
*
I boughted CNY 1140 during 8.8 VIP sales in Taobao
hyperwavedrift
post Sep 2 2024, 07:52 AM

Getting Started
**
Junior Member
89 posts

Joined: Mar 2017
QUOTE(Lancer07 @ Sep 2 2024, 07:44 AM)
My browser still fine, can access the ahen sites
*
what browser?
isr25
post Sep 2 2024, 07:55 AM

Regular
******
Senior Member
1,263 posts

Joined: Nov 2009
From: Johor Bahru



QUOTE(dest9116 @ Sep 2 2024, 07:44 AM)
OK je me buka. I just set dns setting in my router the same place me key in user and password. No go anywhere advance also
*
Yes, some are not yet implemented. Depends on location or package maybe.

QUOTE(hyperwavedrift @ Sep 2 2024, 07:49 AM)
holy shit this thing is like rm 1.5k
*
Can get around RM1.1k, but most users don’t need this. TP Link or Microtik is enough for most. I’m using it for other functions as well e.g. multiple OpenVPN routing for separate devices, OpenVPN server (VPN to home), adaptive QOS using automated speedtest, logging my internet usage and many more functions
Doomsday
post Sep 2 2024, 08:01 AM

keluarpattern dupe slayer
*******
Senior Member
2,491 posts

Joined: Dec 2004
From: initrd


QUOTE(God Grid @ Sep 2 2024, 07:48 AM)
we are anti-communist!!!!

we hate communist!!!!

but malaysia also became a communist country

hahahahahhaa fucking sei sohai people all

say anti-commie, but sendiri also commie

fuck you all la!
*
And they think Chin Peng ash is commie?

Look at now. CP must be rolling in his urn
Lancer07
post Sep 2 2024, 08:02 AM

On my way
****
Junior Member
599 posts

Joined: Jul 2021
QUOTE(hyperwavedrift @ Sep 2 2024, 07:52 AM)
what browser?
*
Opera
HikayatSalju
post Sep 2 2024, 08:05 AM

Enthusiast
*****
Junior Member
773 posts

Joined: Oct 2021
Good, country's laws must be enforced.
MR_alien
post Sep 2 2024, 08:06 AM

Mr.Alien on the loss
*******
Senior Member
3,582 posts

Joined: Oct 2007
From: everywhere in sabah



trust me when i say VPN sales is about to skyrocket
and this is only 1 of many reasons...more coming
Icehart
post Sep 2 2024, 08:11 AM

72.55.191.6
********
All Stars
14,901 posts

Joined: Apr 2005
From: Kuala Lumpur & Selangor


Hahaha madanon the ccp
ameliorate
post Sep 2 2024, 08:20 AM

Casual
***
Junior Member
370 posts

Joined: Jul 2010


KNN. All my prawn sites are blocked.

SUSraynman
post Sep 2 2024, 08:53 AM

Look at all my stars!!
*******
Senior Member
4,333 posts

Joined: Jan 2003


QUOTE(ameliorate @ Sep 2 2024, 08:20 AM)
KNN. All my prawn sites are blocked.
*
Using Unifi? When did this happen?
mcchin
post Sep 2 2024, 09:02 AM

SLAVA UKRAINI !
*******
Senior Member
3,902 posts

Joined: Jul 2005
From: Sin Lor, B'worth,Pg.
I think there is level of difference in the type of package your using

100mbps and below migrated to private IP right?


annoymous1234
post Sep 2 2024, 09:08 AM

Look at all my stars!!
*******
Senior Member
7,617 posts

Joined: Mar 2009

How to use DOH or DOT on android?
SUSraynman
post Sep 2 2024, 09:09 AM

Look at all my stars!!
*******
Senior Member
4,333 posts

Joined: Jan 2003


QUOTE(mcchin @ Sep 2 2024, 09:02 AM)
I think there is level of difference in the type of package your using

100mbps and below migrated to private IP right?
*
user posted image

My Unifi speed is 500 Mbps
fanlou
post Sep 2 2024, 09:13 AM

New Member
*
Junior Member
8 posts

Joined: Oct 2021


Kan most /k salary >20k/mth, get a vpn lar cheapskates shakehead.gif
andyng38
post Sep 2 2024, 09:14 AM

Look at all my stars!!
*******
Senior Member
2,402 posts

Joined: Jun 2007
We have been steadily entering the era of internet censorship for some time already. Turkey banned instagram, Brazil banned X, Bangladesh banned various social media platforms, and when various corporations DGAF about meeting Fahmi, I wonder what will his indignant wrath wreak.
Rusty Nail
post Sep 2 2024, 09:16 AM

Why am I still here?
*******
Senior Member
4,883 posts

Joined: Jan 2003
From: Petaling Jaya



Lol I've seen this coming when maxis did it
Lucky bought pfsense router just in time
Chobits
post Sep 2 2024, 09:16 AM

Cutest piece of technology on the planet
*****
Senior Member
721 posts

Joined: Jul 2007
From: Chii ?


this morning open my favorites sites all ok je?
no problem pon
kmrdeva
post Sep 2 2024, 09:48 AM

Look at all my stars!!
*******
Senior Member
4,790 posts

Joined: Jan 2003
QUOTE(annoymous1234 @ Sep 2 2024, 09:08 AM)
How to use DOH or DOT on android?
*
https://developers.cloudflare.com/1.1.1.1/setup/android/
SUSraynman
post Sep 2 2024, 09:51 AM

Look at all my stars!!
*******
Senior Member
4,333 posts

Joined: Jan 2003


user posted image


Instead of using a VPN, I use Cloudflare's DNS Over WARP.

WARP establishes a private tunnel that encrypts ALL data, preventing man-in-the-middle attacks

The bandwidth degradation is less than using a VPN.

Best of all, it is FREE!
SUSraynman
post Sep 2 2024, 10:13 AM

Look at all my stars!!
*******
Senior Member
4,333 posts

Joined: Jan 2003


user posted image

WARP activated
kmrdeva
post Sep 2 2024, 10:36 AM

Look at all my stars!!
*******
Senior Member
4,790 posts

Joined: Jan 2003
QUOTE(raynman @ Sep 2 2024, 10:13 AM)
user posted image

WARP activated
*
Used warp when I was on android.

Now on ios and ipados, I use a device mgmt profile instead.

user posted image
fantasy1989
post Sep 2 2024, 10:38 AM

Look at all my stars!!
*******
Senior Member
4,707 posts

Joined: May 2008



still can ah

» Click to show Spoiler - click again to hide... «

mcchin
post Sep 2 2024, 10:40 AM

SLAVA UKRAINI !
*******
Senior Member
3,902 posts

Joined: Jul 2005
From: Sin Lor, B'worth,Pg.
QUOTE(raynman @ Sep 2 2024, 09:09 AM)
user posted image

My Unifi speed is 500 Mbps
*
then i guess you started from low speed keep on free upgrade
so not true 500mbps

you get group together with the low speed one lor
SUSM4A1
post Sep 2 2024, 10:41 AM

[*#^♥SONE♥^#]
******
Senior Member
1,365 posts

Joined: Aug 2005



syukurrrrrrrrrr
thankyou
post Sep 2 2024, 10:42 AM

Regular
******
Senior Member
1,941 posts

Joined: Jan 2003
I think people who are on CGNAT kena first...

My DNS is still not restricted yet
SUSeds2
post Sep 2 2024, 10:45 AM

Getting Started
**
Junior Member
101 posts

Joined: Jul 2022
From: Kelantan

Sep 2 2024, 10:46 AM
This post has been deleted by raynman because: .

Seawater
post Sep 2 2024, 10:52 AM

New Member
*
Junior Member
10 posts

Joined: Feb 2023
QUOTE(moiskyrie @ Sep 2 2024, 07:01 AM)
Damn...
No wonder some of my manga can't loading.....
*
News said several manga sites have been taken down by lawsuits.
brkli
post Sep 2 2024, 10:54 AM

On my way
****
Junior Member
592 posts

Joined: Oct 2018
QUOTE(raynman @ Sep 2 2024, 05:23 AM)

My Cloudfare secure DNS on TM Unifi does not work anymore

After disabling Cloudflare secure DNS in my browser, most of my ahem websites are inaccessible.

Anyone facing the same problem?

It seems VPN is the only way out now
*
then enable back secure DNS.
wong_86
post Sep 2 2024, 10:58 AM

DUDE
****
Junior Member
565 posts

Joined: Oct 2007
From: MARS


kek, most of the rakyat not IT guys, they even didn't what happen right now.
h@ksam
post Sep 2 2024, 10:58 AM

@ is a
*******
Senior Member
3,460 posts

Joined: Nov 2009
From: KL
tutup internet jer

everyone back to using pos Malaysia and go outdoors to play games.
SUShamsterdam
post Sep 2 2024, 11:02 AM

New Member
*
Junior Member
15 posts

Joined: Feb 2023


Why you all complain? You should have seen this coming if you align yourself with communist CCP bloc, dare to do, dare to admit.
Brotherjoe
post Sep 2 2024, 11:25 AM

Look at all my stars!!
*******
Senior Member
2,216 posts

Joined: Jan 2003
From: Ipoh/Penang/PJ/Melaka
QUOTE(jibpek @ Sep 2 2024, 07:46 AM)
tracert -d 8.8.8.8

Tracing route to 8.8.8.8 over a maximum of 30 hops

  1    1 ms    1 ms    1 ms  192.168.0.1
  2    4 ms    4 ms    5 ms  [obscured]
  3    4 ms    4 ms    5 ms  [obscured]
  4    5 ms    5 ms    4 ms  10.55.48.16        <- TMNUT proxy
  5    6 ms    5 ms    5 ms  72.14.204.208
  6    8 ms    7 ms    6 ms  216.239.63.159
  7    7 ms    6 ms    6 ms  142.251.255.29
  8    5 ms    6 ms    5 ms  8.8.8.8

Trace complete.
*
How come you are on ipv4?
Mine showing ipv6.
ylyap
post Sep 2 2024, 11:56 AM

New Member
*
Junior Member
44 posts

Joined: Dec 2009


No wonder my old man call me said some bank website cannot access.
Why Madanion block bank(m2u) website though ???

This post has been edited by ylyap: Sep 2 2024, 12:14 PM
MegaCanonF
post Sep 2 2024, 12:02 PM

Enthusiast
*****
Junior Member
875 posts

Joined: Jan 2018
will telegram be affected by this?
anangryorc
post Sep 2 2024, 12:08 PM

On my way
****
Senior Member
597 posts

Joined: May 2006


VPN still works?
Zot
post Sep 2 2024, 12:14 PM

Look at all my stars!!
*******
Senior Member
7,938 posts

Joined: Mar 2014
I think SG all traffic go through govt proxy, right?

I think the one got blocked probably those with private IP. Mine just works without problem. hmm.gif
SUSraynman
post Sep 2 2024, 12:16 PM

Look at all my stars!!
*******
Senior Member
4,333 posts

Joined: Jan 2003


user posted image

Cornhub cannot access cool2.gif
billylks
post Sep 2 2024, 01:25 PM

Getting Started
**
Junior Member
180 posts

Joined: May 2010


Macam still okay, ayam using Time + android private dns
PJng
post Sep 2 2024, 01:55 PM

10k Club
********
All Stars
12,052 posts

Joined: Oct 2017


Removed

This post has been edited by PJng: Sep 2 2024, 05:56 PM
china_dude 02
post Sep 2 2024, 01:57 PM

On my way
****
Senior Member
633 posts

Joined: Jan 2011
What's the problem again, raynmann. Just came back from bora
SUSM4A1
post Sep 2 2024, 01:57 PM

[*#^♥SONE♥^#]
******
Senior Member
1,365 posts

Joined: Aug 2005



QUOTE(hamsterdam @ Sep 2 2024, 11:02 AM)
Why you all complain? You should have seen this coming if you align yourself with communist CCP bloc, dare to do, dare to admit.
*
cause this is the govt that ktard voted in laugh.gif
PJng
post Sep 2 2024, 01:59 PM

10k Club
********
All Stars
12,052 posts

Joined: Oct 2017


QUOTE(china_dude 02 @ Sep 2 2024, 01:57 PM)
What's the problem again, raynmann. Just came back from bora
*
only know ts free time is on those website
cubiclecarbonate
post Sep 2 2024, 01:59 PM

On my way
****
Junior Member
558 posts

Joined: Jul 2011


You guys required alternatives dns for what?
kmrdeva
post Sep 2 2024, 02:07 PM

Look at all my stars!!
*******
Senior Member
4,790 posts

Joined: Jan 2003
QUOTE(cubiclecarbonate @ Sep 2 2024, 01:59 PM)
You guys required alternatives dns for what?
*
Nothing, really. Just prefer to use google or cloudflare dns.
a_dot_el
post Sep 2 2024, 02:11 PM

Getting Started
**
Junior Member
195 posts

Joined: Sep 2010
QUOTE(DarkAeon @ Sep 2 2024, 05:43 AM)
they are preparing for plan b if the socmed don't apply for their license. block everyone. lol
*
They seems to be doing everything to bring down Ringgit and the economy down.
pgsiemkia
post Sep 2 2024, 02:23 PM

Casual
***
Junior Member
473 posts

Joined: Dec 2009
From: Timbuktoo
QUOTE(isr25 @ Sep 2 2024, 05:32 AM)
user posted image

Mine still working as normal

-edit- although maybe it’s because I enabled DNS over TLS on my router
*
Same. Still checking PH, torrents..

Ivan113
post Sep 2 2024, 02:37 PM

Enthusiast
*****
Senior Member
925 posts

Joined: Apr 2011
QUOTE(kmrdeva @ Sep 2 2024, 10:36 AM)
Used warp when I was on android.

Now on ios and ipados, I use a device mgmt profile instead.

user posted image
*
show us how to set this up please
kmrdeva
post Sep 2 2024, 02:55 PM

Look at all my stars!!
*******
Senior Member
4,790 posts

Joined: Jan 2003
QUOTE(Ivan113 @ Sep 2 2024, 02:37 PM)
show us how to set this up please
*
Just download the Secure DNS profile you want on your iDevice and install it.

https://github.com/paulmillr/encrypted-dns
redframelowyat
post Sep 2 2024, 02:58 PM

Getting Started
**
Junior Member
162 posts

Joined: Aug 2008
When madani is more pas than pas itself..
annoymous1234
post Sep 2 2024, 03:00 PM

Look at all my stars!!
*******
Senior Member
7,617 posts

Joined: Mar 2009

QUOTE(kmrdeva @ Sep 2 2024, 09:48 AM)
I'm using adguard for dns. Is there other way?
TruboXL
post Sep 2 2024, 03:02 PM

Keep on keeping on! 👍
******
Senior Member
1,050 posts

Joined: Jan 2016
From: Land of floods, Kota Tinggi


QUOTE(isr25 @ Sep 2 2024, 06:06 AM)
My full DNS settings

user posted image
*
why you stop update oil price?
Weisun79
post Sep 2 2024, 03:16 PM

New Member
*
Newbie
42 posts

Joined: Sep 2013
VPN also has trottled connection speed...
Sighz.. any other workaround?
SUSraynman
post Sep 2 2024, 04:25 PM

Look at all my stars!!
*******
Senior Member
4,333 posts

Joined: Jan 2003


QUOTE(Weisun79 @ Sep 2 2024, 03:16 PM)
VPN also has trottled connection speed...
Sighz.. any other workaround?
*
I am afraid there are only two ways to circumvent MCMC's transparent DNS proxy.

1. Use a VPN
2. Install Cloudflare's WARP
brkli
post Sep 2 2024, 04:26 PM

On my way
****
Junior Member
592 posts

Joined: Oct 2018
QUOTE(redframelowyat @ Sep 2 2024, 02:58 PM)
When madani is more pas than pas itself..
*
if PAS implemented this. how can they going layan undanghub easily..
cubiclecarbonate
post Sep 2 2024, 04:39 PM

On my way
****
Junior Member
558 posts

Joined: Jul 2011


QUOTE(kmrdeva @ Sep 2 2024, 02:07 PM)
Nothing, really. Just prefer to use google or cloudflare dns.
*
Meaning, there should be no issues if the default dns is used? I remember during the early stages of chatgpt, some countries are required to use vpn due to their access to chatgpt was blocked.
HumanExtinction
post Sep 2 2024, 04:41 PM

Casual
***
Junior Member
364 posts

Joined: Jan 2018
From: Tim Apple
quad 9 for the win
Quantum Geist
post Sep 2 2024, 04:41 PM

Getting Started
**
Junior Member
109 posts

Joined: May 2013


QUOTE(Weisun79 @ Sep 2 2024, 03:16 PM)
VPN also has trottled connection speed...
Sighz.. any other workaround?
*
In order from simplest to more technical

1. change dns on the browser you use to DoT/DoH, most up to date desktop browsers like chrome/firefox/edge has built in profile for different dns provider if I'm not mistaken
2. Change dns to use DoH/DoT based dns on device, most modern operating system (android/ios/macos/windows/linux) should have guides on how to do it.
3. Change settings on router to use DoH/DoT, not all routers support so you have to google it yourself
4. self host own local recursive dns server (adguard home/pihole/blocky/etc) and use DoH/DoT as source

some resources:
https://forum.lowyat.net/index.php?showtopi...ost&p=110377301
https://www.privacyguides.org/en/dns/
https://www.reddit.com/r/privacy

This post has been edited by Quantum Geist: Sep 2 2024, 08:16 PM
jibpek
post Sep 2 2024, 04:53 PM

Enthusiast
*****
Junior Member
708 posts

Joined: Jul 2012
QUOTE(PJng @ Sep 2 2024, 01:55 PM)
https://one.one.one.one/help/#eyJpc0NmIjoiW...joiMTMzMzUifQ==

tracert -d 8.8.8.8

Tracing route to 8.8.8.8 over a maximum of 30 hops

  1    1 ms    1 ms    1 ms  192.168.0.1
  2    7 ms    4 ms    4 ms  100.70.63.254
  3    6 ms    23 ms    24 ms  10.233.33.89
  4    7 ms    5 ms    5 ms  10.55.48.16
  5    8 ms    6 ms    6 ms  72.14.214.220
  6    10 ms    8 ms    8 ms  216.239.63.133
  7    9 ms    7 ms    7 ms  142.250.62.59
  8    8 ms    7 ms    6 ms  8.8.8.8

Trace complete.

tracert -d 1.1.1.1

Tracing route to 1.1.1.1 over a maximum of 30 hops

  1    2 ms    1 ms    1 ms  192.168.0.1
  2    8 ms    4 ms    4 ms  100.70.63.254
  3    7 ms    4 ms    4 ms  10.233.33.89
  4    8 ms    6 ms    6 ms  10.55.37.90
  5    *        *        *    Request timed out.
  6    7 ms    7 ms    7 ms  1.1.1.1

Trace complete.

so what mean
*
100.x.x.x is ISP NAT, you do not have public IP

kmrdeva
post Sep 2 2024, 04:54 PM

Look at all my stars!!
*******
Senior Member
4,790 posts

Joined: Jan 2003
QUOTE(annoymous1234 @ Sep 2 2024, 03:00 PM)
I'm using adguard for dns. Is there other way?
*
Not sure about android platform. Someone else here can advise?
jibpek
post Sep 2 2024, 04:54 PM

Enthusiast
*****
Junior Member
708 posts

Joined: Jul 2012
QUOTE(Brotherjoe @ Sep 2 2024, 11:25 AM)
How come you are on ipv4?
Mine showing ipv6.
*
Display ipv6 in your router, or use -4 in tracert.
kmrdeva
post Sep 2 2024, 04:56 PM

Look at all my stars!!
*******
Senior Member
4,790 posts

Joined: Jan 2003
QUOTE(cubiclecarbonate @ Sep 2 2024, 04:39 PM)
Meaning, there should be no issues if the default dns is used? I remember during the early stages of chatgpt, some countries are required to use vpn due to their access to chatgpt was blocked.
*
For normal use I don’t think there is a problem. only an issue when you want to browse sites that are ‘blocked’.
PJng
post Sep 2 2024, 05:07 PM

10k Club
********
All Stars
12,052 posts

Joined: Oct 2017


QUOTE(jibpek @ Sep 2 2024, 04:53 PM)
100.x.x.x is ISP NAT, you do not have public IP
*
yes, 300mbps plan, no public IP
mcchin
post Sep 2 2024, 05:11 PM

SLAVA UKRAINI !
*******
Senior Member
3,902 posts

Joined: Jul 2005
From: Sin Lor, B'worth,Pg.
QUOTE(PJng @ Sep 2 2024, 05:07 PM)
yes, 300mbps plan, no public IP
*
Eh?
300mbps plan unifi ka

Last time they say only affect those 100 and below?
Deswai I upgrade to 300 within 7months of started using unifi 100mbps
PJng
post Sep 2 2024, 05:13 PM

10k Club
********
All Stars
12,052 posts

Joined: Oct 2017


QUOTE(mcchin @ Sep 2 2024, 05:11 PM)
Eh?
300mbps plan unifi ka

Last time they say only affect those 100 and below?
Deswai I upgrade to 300 within 7months of started using unifi 100mbps
*
yes, many confirm with TM, now min 500mbps for public IP
jibpek
post Sep 2 2024, 05:15 PM

Enthusiast
*****
Junior Member
708 posts

Joined: Jul 2012
QUOTE(mcchin @ Sep 2 2024, 05:11 PM)
Eh?
300mbps plan unifi ka

Last time they say only affect those 100 and below?
Deswai I upgrade to 300 within 7months of started using unifi 100mbps
*
How much is 300 plan now?
mcchin
post Sep 2 2024, 05:16 PM

SLAVA UKRAINI !
*******
Senior Member
3,902 posts

Joined: Jul 2005
From: Sin Lor, B'worth,Pg.
QUOTE(PJng @ Sep 2 2024, 05:13 PM)
yes, many confirm with TM, now min 500mbps for public IP
*
I was 300 free up to 500
Now on 180 IP range

You were on 300 or free up from 100?
PJng
post Sep 2 2024, 05:16 PM

10k Club
********
All Stars
12,052 posts

Joined: Oct 2017


QUOTE(mcchin @ Sep 2 2024, 05:16 PM)
I was 300 free up to 500
Now on 180 IP range

You were on 300 or free up from 100?
*
yes, 100 free upgrade to 300, RM129
mcchin
post Sep 2 2024, 05:17 PM

SLAVA UKRAINI !
*******
Senior Member
3,902 posts

Joined: Jul 2005
From: Sin Lor, B'worth,Pg.
QUOTE(jibpek @ Sep 2 2024, 05:15 PM)
How much is 300 plan now?
*
I standard price jer

168.55
mcchin
post Sep 2 2024, 05:18 PM

SLAVA UKRAINI !
*******
Senior Member
3,902 posts

Joined: Jul 2005
From: Sin Lor, B'worth,Pg.
QUOTE(PJng @ Sep 2 2024, 05:16 PM)
yes, 100 free upgrade to 300, RM129
*
I guess the cgnat stuck even though you upgraded to 300mbps


PJng
post Sep 2 2024, 05:20 PM

10k Club
********
All Stars
12,052 posts

Joined: Oct 2017


QUOTE(mcchin @ Sep 2 2024, 05:18 PM)
I guess the cgnat stuck even though you upgraded to 300mbps
*
got trying to get cheapest price, but cannot, there are many able to get 500mbps RM119
mcchin
post Sep 2 2024, 05:22 PM

SLAVA UKRAINI !
*******
Senior Member
3,902 posts

Joined: Jul 2005
From: Sin Lor, B'worth,Pg.
QUOTE(PJng @ Sep 2 2024, 05:20 PM)
got trying to get cheapest price, but cannot, there are many able to get 500mbps RM119
*
Yeah
Tm is well know to don't gip a fuark for those loyal user
Always give freebies to those new registration one

Like my sales guy said

Sales man only need to focus on those that have half interest in your product
Those that totally no interest, no need the effort
Those that are current using, also no need much effort
Those potential ones are needed to be enticed
isr25
post Sep 2 2024, 05:26 PM

Regular
******
Senior Member
1,263 posts

Joined: Nov 2009
From: Johor Bahru



QUOTE(TruboXL @ Sep 2 2024, 03:02 PM)
why you stop update oil price?
*
Busy with work laugh.gif

But I will continue back soon
skywardsword
post Sep 2 2024, 05:27 PM

On my way
****
Junior Member
680 posts

Joined: Sep 2010
what is the test to show if my dns is under poisoned?
GHBZDK
post Sep 2 2024, 05:29 PM

Getting Started
**
Junior Member
173 posts

Joined: Jun 2012
Quad9 gang
SUSraynman
post Sep 2 2024, 05:34 PM

Look at all my stars!!
*******
Senior Member
4,333 posts

Joined: Jan 2003


QUOTE(GHBZDK @ Sep 2 2024, 05:29 PM)
Quad9 gang
*
Will kena sooner or later cool2.gif
solarmystic
post Sep 2 2024, 05:35 PM

Getting Started
**
Junior Member
271 posts

Joined: Jun 2009
Everything still seems fine on my end, my Unifi connection is as stated on my sig (300/50).

Checked Murray Hunter's substack and all the usual suspects too. Nothing has changed since the initial reveal on the 6th of August by sinar project.

user posted image

user posted image

This post has been edited by solarmystic: Sep 2 2024, 05:37 PM
zerorating
post Sep 2 2024, 05:49 PM

Miskin Adab
*****
Senior Member
975 posts

Joined: Aug 2007
From: Lokap Polis


QUOTE(solarmystic @ Sep 2 2024, 05:35 PM)
Everything still seems fine on my end, my Unifi connection is as stated on my sig (300/50).

Checked Murray Hunter's substack and all the usual suspects too. Nothing has changed since the initial reveal on the 6th of August by sinar project.

user posted image

user posted image
*
maybe cloudflare doh server down at the time ts did the test kot.
anyway i still waiting for tm to push for the implementation, i guess it will be hard to them since their customers count is in millions.they need to provision alot of servers to cover this, implying that this service can be load balanced in first place.
Brotherjoe
post Sep 2 2024, 05:50 PM

Look at all my stars!!
*******
Senior Member
2,216 posts

Joined: Jan 2003
From: Ipoh/Penang/PJ/Melaka
QUOTE(jibpek @ Sep 2 2024, 04:54 PM)
Display ipv6 in your router, or use -4 in tracert.
*
tracert -4 -d google.com

I will get Request timed out.

But without -4. it will show ipv6.

Btw, i'm on unifi 100.


This post has been edited by Brotherjoe: Sep 2 2024, 06:03 PM
countingcrows
post Sep 2 2024, 05:54 PM

Getting Started
**
Junior Member
259 posts

Joined: Feb 2023
QUOTE(zerorating @ Sep 2 2024, 05:49 PM)
maybe cloudflare doh server down at the time ts did the test kot.
anyway i still waiting for tm to push for the implementation, i guess it will be hard to them since their customers count is in millions.they  need to provision alot of servers to cover this, implying that this service can be load balanced in first place.
*
Still working. Maybe in stages? Not sure what they did or going to do.
But if I have to reconfigure all the PCs, laptops, phones and devices I am going to be pissed. 😁
SUSraynman
post Sep 2 2024, 06:14 PM

Look at all my stars!!
*******
Senior Member
4,333 posts

Joined: Jan 2003


QUOTE(thankyou @ Sep 2 2024, 10:42 AM)
I think people who are on CGNAT kena first...

My DNS is still not restricted yet
*
user posted image

user posted image

I am not on CGNAT and yet I kena last night
MR_alien
post Sep 2 2024, 06:22 PM

Mr.Alien on the loss
*******
Senior Member
3,582 posts

Joined: Oct 2007
From: everywhere in sabah



elon musk already foresee everything
he just need to keep using the same meme picture but keep changing the name of country only laugh.gif


Quantum Geist
post Sep 2 2024, 06:29 PM

Getting Started
**
Junior Member
109 posts

Joined: May 2013


QUOTE(zerorating @ Sep 2 2024, 05:49 PM)
maybe cloudflare doh server down at the time ts did the test kot.
anyway i still waiting for tm to push for the implementation, i guess it will be hard to them since their customers count is in millions.they  need to provision alot of servers to cover this, implying that this service can be load balanced in first place.
*
I've already seen one weird issue in one local mobile isp a few weeks back, for some reason their users can't find the dns record for one of the domain that was registered under the company I work for, all other isp had no issues. Maybe related?
JohnL77
post Sep 2 2024, 06:34 PM

Regular
******
Senior Member
1,887 posts

Joined: Mar 2013


QUOTE(MR_alien @ Sep 2 2024, 06:22 PM)
elon musk already foresee everything
he just need to keep using the same meme picture but keep changing the name of country only laugh.gif


*
Most people are not going to pay for VPN. Also in China they crackdown on VPN companies.


SUSraynman
post Sep 2 2024, 06:36 PM

Look at all my stars!!
*******
Senior Member
4,333 posts

Joined: Jan 2003


QUOTE(JohnL77 @ Sep 2 2024, 06:34 PM)
Most people are not going to pay for VPN. Also in China they crackdown on VPN companies.
*
Curious. How do they crackdown on VPN companies? Ban their websites?
MR_alien
post Sep 2 2024, 06:38 PM

Mr.Alien on the loss
*******
Senior Member
3,582 posts

Joined: Oct 2007
From: everywhere in sabah



QUOTE(JohnL77 @ Sep 2 2024, 06:34 PM)
Most people are not going to pay for VPN. Also in China they crackdown on VPN companies.
*
has anybody in china being stopped from using VPN?

if they are then why are their content still being uploaded to youtube? hmm.gif laugh.gif
and why are they on IG, FB, twitter? laugh.gif

most people are not going to pay for VPN....until they needed to brows.gif
i guess u have no idea how big of a market social media is in MY...many people's rice bowl is actually social media
ylyap
post Sep 2 2024, 06:41 PM

New Member
*
Junior Member
44 posts

Joined: Dec 2009


I just realized my Surfshark still have 106 days left.
Use VPN problem solved thumbup.gif

Edit: torrent speed seems not affected when everything else failed to connect lol (with VPN off of course).

This post has been edited by ylyap: Sep 2 2024, 06:54 PM
JohnL77
post Sep 2 2024, 06:44 PM

Regular
******
Senior Member
1,887 posts

Joined: Mar 2013


QUOTE(raynman @ Sep 2 2024, 06:36 PM)
Curious. How do they crackdown on VPN companies? Ban their websites?
*
Literally raid the office and arrest people la. Twitter's office in Brazil also forced to close and they froze the bank accounts of the lawyer who represented Twitter.

QUOTE(MR_alien @ Sep 2 2024, 06:38 PM)
has anybody in china being stopped from using VPN?

if they are then why are their content still being uploaded to youtube? hmm.gif  laugh.gif
and why are they on IG, FB, twitter? laugh.gif

most people are not going to pay for VPN....until they needed to brows.gif
i guess u have no idea how big of a market social media is in MY...many people's rice bowl is actually social media
*
Who gives a fuck about sohai influencers? Replace all the Western socmed with CCP socmed and those sohai influencers can still cari makan.

During the anti-lockdown protests, they used AirDrop to share videos. Then Apple limited the feature at the request of Xipeepee.

https://forum.lowyat.net/index.php?showtopic=5333977&hl=

This post has been edited by JohnL77: Sep 2 2024, 06:45 PM
mellovicious
post Sep 2 2024, 06:46 PM

Casual
***
Junior Member
469 posts

Joined: Sep 2009
From: under your bed


why mine still works fine

is it not implemented nationwide?
SUSraynman
post Sep 2 2024, 06:51 PM

Look at all my stars!!
*******
Senior Member
4,333 posts

Joined: Jan 2003


QUOTE(mellovicious @ Sep 2 2024, 06:46 PM)
why mine still works fine

is it not implemented nationwide?
*
I think Unifi is implementing the transparent DNS proxy in stages.

Mine unlucky kena first.


I installed Cloudflare's WARP to circumvent the banned websites blocking
zerorating
post Sep 2 2024, 07:02 PM

Miskin Adab
*****
Senior Member
975 posts

Joined: Aug 2007
From: Lokap Polis


QUOTE(raynman @ Sep 2 2024, 06:51 PM)
I think Unifi is implementing the transparent DNS proxy in stages.

Mine unlucky kena first.
I installed Cloudflare's WARP to circumvent the banned websites blocking
*
while at it can you test out plaintext dns server that i put in my signature want to see how far isp goes.
delphine.88
post Sep 2 2024, 07:03 PM

Getting Started
**
Junior Member
143 posts

Joined: Aug 2021
Unker at your age still watch ehem ehem ah?
SUSraynman
post Sep 2 2024, 07:05 PM

Look at all my stars!!
*******
Senior Member
4,333 posts

Joined: Jan 2003


QUOTE(zerorating @ Sep 2 2024, 07:02 PM)
while at it  can you test out plaintext dns server that i put in my signature  want to see how far isp goes.
*
I have disabled signature viewing, sorry
Skylinestar
post Sep 2 2024, 07:05 PM

Mega Duck
********
All Stars
10,478 posts

Joined: Jan 2003
From: Sarawak
QUOTE(JohnL77 @ Sep 2 2024, 06:34 PM)
Most people are not going to pay for VPN. Also in China they crackdown on VPN companies.
*
if i roaming with celcom in China, can I access google? if no, what vpn works there?
zerorating
post Sep 2 2024, 07:06 PM

Miskin Adab
*****
Senior Member
975 posts

Joined: Aug 2007
From: Lokap Polis


QUOTE(raynman @ Sep 2 2024, 07:05 PM)
I have disabled signature viewing, sorry
*
sure use ip below
15.235.146.143
dev/numb
post Sep 2 2024, 07:06 PM

On my way
****
Junior Member
691 posts

Joined: Nov 2021
MCMC actually helping educate public. Nobody should be using legacy bareback DNS in 2024. If they start hard blocking the default TLS port 853, then you start worrying.
dev/numb
post Sep 2 2024, 07:10 PM

On my way
****
Junior Member
691 posts

Joined: Nov 2021
QUOTE(Skylinestar @ Sep 2 2024, 07:05 PM)
if i roaming with celcom in China, can I access google? if no, what vpn works there?
*
Depends on their “defcon” level. Some days any consumer VPN WireGuard tunnel to a Taiwan or HK server will work fine. Other days when your da ke too butthurt by Pooh memes, you will likely need shadowsocks or v2ray.
PJng
post Sep 2 2024, 07:13 PM

10k Club
********
All Stars
12,052 posts

Joined: Oct 2017


QUOTE(zerorating @ Sep 2 2024, 07:06 PM)
sure  use ip below
15.235.146.143
*
what that, refuse to connect
HolySatan
post Sep 2 2024, 07:15 PM

Regular
******
Senior Member
1,116 posts

Joined: Dec 2009
unifi fibre & uhome5g still can access using DNS
zerorating
post Sep 2 2024, 07:50 PM

Miskin Adab
*****
Senior Member
975 posts

Joined: Aug 2007
From: Lokap Polis


QUOTE(PJng @ Sep 2 2024, 07:13 PM)
what that, refuse to connect
*
dns brah.

QUOTE
Microsoft Windows [Version 10.0.22631.3880]
© Microsoft Corporation. All rights reserved.

C:\Users\user>nslookup
Default Server:  OpenWrt.lan
Address:  fd8f:fd52:ffa3::1

> server 15.235.146.143
Default Server:  vps-c690e196.vps.ovh.ca
Address:  15.235.146.143

> pornhub.com
Server:  vps-c690e196.vps.ovh.ca
Address:  15.235.146.143

Non-authoritative answer:
Name:    pornhub.com
Address:  66.254.114.41

PJng
post Sep 2 2024, 07:55 PM

10k Club
********
All Stars
12,052 posts

Joined: Oct 2017


QUOTE(zerorating @ Sep 2 2024, 07:50 PM)
dns brah.
*
C:\Users\User>nslookup
Default Server: dns.tm.net.my
Address: 2001:e68::b:68

> server 15.235.146.143
Default Server: vps-c690e196.vps.ovh.ca
Address: 15.235.146.143


not yet expert on this, haha
router don have those DNS can set, only set on windows 11 use 1.1.1.1 DNS
zerorating
post Sep 2 2024, 07:57 PM

Miskin Adab
*****
Senior Member
975 posts

Joined: Aug 2007
From: Lokap Polis


QUOTE(PJng @ Sep 2 2024, 07:55 PM)
C:\Users\User>nslookup
Default Server:  dns.tm.net.my
Address:  2001:e68::b:68

> server 15.235.146.143
Default Server:  vps-c690e196.vps.ovh.ca
Address:  15.235.146.143
not yet expert on this, haha
router don have those DNS can set, only set on windows 11 use 1.1.1.1 DNS
*
are you affected with the dns transparent proxy implementation?
brkli
post Sep 2 2024, 07:57 PM

On my way
****
Junior Member
592 posts

Joined: Oct 2018
QUOTE(ylyap @ Sep 2 2024, 06:41 PM)
I just realized my Surfshark still have 106 days left.
Use VPN problem solved  thumbup.gif

Edit: torrent speed seems not affected when everything else failed to connect lol (with VPN off of course).
*
torrent most the time use IP only.. using IP why the heck need DNS.
zerorating
post Sep 2 2024, 07:58 PM

Miskin Adab
*****
Senior Member
975 posts

Joined: Aug 2007
From: Lokap Polis


QUOTE(brkli @ Sep 2 2024, 07:57 PM)
torrent most the time use IP only.. using IP why the heck need DNS.
*
tracker can easily be blocked by ISP.
PJng
post Sep 2 2024, 08:06 PM

10k Club
********
All Stars
12,052 posts

Joined: Oct 2017


QUOTE(zerorating @ Sep 2 2024, 07:57 PM)
are you affected with the dns transparent proxy implementation?
*
https://forum.lowyat.net/index.php?showtopi...ost&p=110377412

cannot open this site, mean yes right, i no visit those ahem video site
i was trying understand on network section, how to test without actually visit those site
zerorating
post Sep 2 2024, 08:08 PM

Miskin Adab
*****
Senior Member
975 posts

Joined: Aug 2007
From: Lokap Polis


QUOTE(PJng @ Sep 2 2024, 08:06 PM)
https://forum.lowyat.net/index.php?showtopi...ost&p=110377412

cannot open this site, mean yes right, i no visit those ahem video site
i was trying understand on network section, how to test without actually visit those site
*
your default dns is pointing to TM wan la brah. no wonder you cant access.
hyperwavedrift
post Sep 2 2024, 08:20 PM

Getting Started
**
Junior Member
89 posts

Joined: Mar 2017
So TM applied this shit but internet slow down still isn't fixed. Get your fucking priorities straight TM
zerorating
post Sep 2 2024, 08:33 PM

Miskin Adab
*****
Senior Member
975 posts

Joined: Aug 2007
From: Lokap Polis


QUOTE(hyperwavedrift @ Sep 2 2024, 08:20 PM)
So TM applied this shit but internet slow down still isn't fixed. Get your fucking priorities straight TM
*
actually TM are the one late to implement this dns transparent proxy.
vapanel
post Sep 2 2024, 08:39 PM

Regular
******
Senior Member
1,075 posts

Joined: Oct 2022


QUOTE(isr25 @ Sep 2 2024, 06:06 AM)
My full DNS settings

user posted image
*
ok done configure the same thing lol
hyperwavedrift
post Sep 3 2024, 04:10 PM

Getting Started
**
Junior Member
89 posts

Joined: Mar 2017
QUOTE(zerorating @ Sep 2 2024, 08:33 PM)
actually TM are the one late to implement this dns transparent proxy.
*
they implement censorship bullshit rather than fixing their service that people pay money for. that's misplaced priority.
zerorating
post Sep 3 2024, 04:33 PM

Miskin Adab
*****
Senior Member
975 posts

Joined: Aug 2007
From: Lokap Polis


QUOTE(hyperwavedrift @ Sep 3 2024, 04:10 PM)
they implement censorship bullshit rather than fixing their service that people pay money for. that's misplaced priority.
*
kesian cant relate to you.
user posted image
user posted image

This post has been edited by zerorating: Sep 3 2024, 04:35 PM
hyperwavedrift
post Sep 3 2024, 09:02 PM

Getting Started
**
Junior Member
89 posts

Joined: Mar 2017
QUOTE(zerorating @ Sep 3 2024, 04:33 PM)
kesian  cant relate to you.
user posted image
user posted image
*
I have 800mbps plan, the issue is that the slowdown happens at night mostly. What's your data plan? or is this private vpn server?

This post has been edited by hyperwavedrift: Sep 3 2024, 09:03 PM
zerorating
post Sep 3 2024, 09:36 PM

Miskin Adab
*****
Senior Member
975 posts

Joined: Aug 2007
From: Lokap Polis


QUOTE(hyperwavedrift @ Sep 3 2024, 09:02 PM)
I have 800mbps plan, the issue is that the slowdown happens at night mostly. What's your data plan? or is this private vpn server?
*
duuhhh, its peak hour (peak hour for SE asia, evening time in europe and USA people start waking up)
alot of time its the content provider issue, they choose to downscale the number of CDN capacity because its too darn expensive (not every provider can afford to use cloudlflare CDN), sometime having load balancer limitation. anyway, I still can get 10MB/s single connection download from USA mirror and 15MB/s single connection from EU mirror at this period.

do remind that not everything can be cached on CDN end.

also it could be ISP problem if you are living in highly dense area. TM GPON max bandwidth is only 2.5gbps and you are sharing those bandwidth with the other 31 houses, dont forget trunk pipe too. anyway, TM is currently upgrading to 10GPON (XGS-PON?), better late than never.
user posted image
user posted image
user posted image

anyway, i never like VPN, most of the time direct connection give me better result, i already test multiple singapore VPN already, malaysia VPN wan sure sampah, same goes with thailand wan.

This post has been edited by zerorating: Sep 3 2024, 09:52 PM
countingcrows
post Sep 3 2024, 09:41 PM

Getting Started
**
Junior Member
259 posts

Joined: Feb 2023
QUOTE(hyperwavedrift @ Sep 3 2024, 09:02 PM)
I have 800mbps plan, the issue is that the slowdown happens at night mostly. What's your data plan? or is this private vpn server?
*
Just tested, 9:5xpm

user posted image
user posted image

This post has been edited by countingcrows: Sep 3 2024, 09:56 PM
Thebestscammer
post Sep 3 2024, 10:14 PM

Casual
***
Junior Member
311 posts

Joined: Jul 2019
using encryopted dns like next and recently trying adguard, but its so slow
sometimes lowyat news load so slow
reddit also load so slow now
so fking annoying
not even sure if its the night time rush hour crap or what but its so slow to load eveyrthing now

kmrdeva
post Sep 3 2024, 10:25 PM

Look at all my stars!!
*******
Senior Member
4,790 posts

Joined: Jan 2003
QUOTE(Thebestscammer @ Sep 3 2024, 10:14 PM)
using encryopted dns like next and recently trying adguard, but its so slow
sometimes lowyat news load so slow
reddit also load so slow now
so fking annoying
not even sure if its the night time rush hour crap or what but its so slow to load eveyrthing now
*
What connection are you on?

On my Win11 PCs, I've enabled secure DNS (in Edge browser) and adguard (Edge extension) - websites load just fine.
soonwai
post Sep 3 2024, 10:29 PM


********
All Stars
11,459 posts

Joined: Oct 2007
From: KL


All OK here. Using Adguard Home. But area, Kajang, is affected by the DNS hijacking.

Penang ppl not affected yet right?

This post has been edited by soonwai: Sep 3 2024, 10:35 PM
hyperwavedrift
post Sep 3 2024, 10:30 PM

Getting Started
**
Junior Member
89 posts

Joined: Mar 2017
QUOTE(zerorating @ Sep 3 2024, 09:36 PM)
duuhhh, its peak hour (peak hour for SE asia, evening time in europe and USA people start waking up)
alot of time its the content provider issue, they choose to downscale the number of CDN capacity because its too darn expensive (not every provider can afford to use cloudlflare CDN), sometime having load balancer limitation. anyway, I still can get 10MB/s single connection download from USA mirror and 15MB/s single connection from EU mirror at this period.

do remind that not everything can be cached on CDN end.

*
Whatever the reason is, this didn't used to be a problem before. It only starting to happen after I upgraded my plan around late last year, and I think it's fair to complain and demand better service. So it's good that they are planning to upgrade their service.

QUOTE(countingcrows @ Sep 3 2024, 09:41 PM)
Just tested, 9:5xpm

user posted image
user posted image
*
The speed is fine locally, it's on overseas site that gets really affected.

user posted image
mhyug
post Sep 3 2024, 10:31 PM

Regular
******
Senior Member
1,553 posts

Joined: May 2009
Proposing mods to move this thread to serious kopitiam. Some good info on how to circumvent since not everyone sangap for porn, some just want to enjoy manga, anime news etc.
zerorating
post Sep 3 2024, 10:41 PM

Miskin Adab
*****
Senior Member
975 posts

Joined: Aug 2007
From: Lokap Polis


QUOTE(hyperwavedrift @ Sep 3 2024, 10:30 PM)
Whatever the reason is, this didn't used to be a problem before. It only starting to happen after I upgraded my plan around late last year, and I think it's fair to complain and demand better service. So it's good that they are planning to upgrade their service.
user posted image
*
everytime tm give speed upgrade sure got speed degradation wan. they are not totally ready for speed upgrade in first place, but hey things improve, for example bandwidth to USA, europe or even china is ample now. but why slow, uhmmm, maybe content provider's CDN resource upstream ISP is overloaded?
anyway, internet are heck alot more complex, sometime throw money also wont solve problem.

anyway, i have been living in TM 3KB/s to oversea network era, today slowness are not much an issue for me. laugh.gif
zerorating
post Sep 3 2024, 10:51 PM

Miskin Adab
*****
Senior Member
975 posts

Joined: Aug 2007
From: Lokap Polis


QUOTE(mhyug @ Sep 3 2024, 10:31 PM)
Proposing mods to move this thread to serious kopitiam. Some good info on how to circumvent since not everyone sangap for porn, some just want to enjoy manga, anime news etc.
*
sometime openly discussing makes the situation even worse. last few months got people so bangga that dns-over-tls(DOT) or dns-over-https(DOH) can overcome this proxy, didnt awared that TM already one step ahead sad.gif
if everything is blocked, looks like its time for me to setup http proxy via VPS, or aws compute resource, with authentication or allowed IP lists of course.

sorry, if i setup a proxy, it wont be shared resource, i dont want to be responsible of anyone vile action.

This post has been edited by zerorating: Sep 3 2024, 10:59 PM
zerorating
post Sep 3 2024, 10:55 PM

Miskin Adab
*****
Senior Member
975 posts

Joined: Aug 2007
From: Lokap Polis


QUOTE(Thebestscammer @ Sep 3 2024, 10:14 PM)
using encryopted dns like next and recently trying adguard, but its so slow
sometimes lowyat news load so slow
reddit also load so slow now
so fking annoying
not even sure if its the night time rush hour crap or what but its so slow to load eveyrthing now
*
thats the limitation of encrypted DNS, there are too much overhead and i dont think DNS service will allow our connection to keep open for long period of time, they have many other clients to serve.i take plaintext DNS anyday.

zerorating
post Sep 3 2024, 10:57 PM

Miskin Adab
*****
Senior Member
975 posts

Joined: Aug 2007
From: Lokap Polis


QUOTE(kmrdeva @ Sep 3 2024, 10:25 PM)
What connection are you on?

On my Win11 PCs, I've enabled secure DNS (in Edge browser) and adguard (Edge extension) - websites load just fine.
*
TM proxy implementation is by stages.
they cant have a single server cluster handles the task of hijacking every users dns requests.
kmrdeva
post Sep 3 2024, 11:02 PM

Look at all my stars!!
*******
Senior Member
4,790 posts

Joined: Jan 2003
QUOTE(zerorating @ Sep 3 2024, 10:57 PM)
TM proxy implementation is by stages.
they cant have a single server cluster handles the task of hijacking every users dns requests.
*
I'm on time fibre though. remember reading that time had implemented this way before tm.
zerorating
post Sep 3 2024, 11:08 PM

Miskin Adab
*****
Senior Member
975 posts

Joined: Aug 2007
From: Lokap Polis


QUOTE(kmrdeva @ Sep 3 2024, 11:02 PM)
I'm on time fibre though. remember reading that time had implemented this way before tm.
*
but time didnt cover DoH and DoT right?
hopefully SKMM didnt mandate those blocking lel.
Weisun79
post Sep 3 2024, 11:12 PM

New Member
*
Newbie
42 posts

Joined: Sep 2013
i tried.. Firefox... enable Increased Protection.. Chooose NextDNS as provider... it works....

or Use Safari...

user posted image
zerorating
post Sep 3 2024, 11:13 PM

Miskin Adab
*****
Senior Member
975 posts

Joined: Aug 2007
From: Lokap Polis


QUOTE(Weisun79 @ Sep 3 2024, 11:12 PM)
i tried.. Firefox... enable Increased Protection.. Chooose NextDNS as provider... it works....

or Use Safari...

user posted image
*
cloudflare and google dont work?

failed.hashcheck
post Sep 3 2024, 11:24 PM

Neighborhood plant pathologist
*******
Senior Member
2,096 posts

Joined: Aug 2009
From: Shithole Klang
QUOTE(Weisun79 @ Sep 3 2024, 11:12 PM)
i tried.. Firefox... enable Increased Protection.. Chooose NextDNS as provider... it works....

or Use Safari...

user posted image
*
or if you use win11, just use OS level DoH at network setting.
Attached Image

This post has been edited by failed.hashcheck: Sep 3 2024, 11:27 PM
zerorating
post Sep 3 2024, 11:29 PM

Miskin Adab
*****
Senior Member
975 posts

Joined: Aug 2007
From: Lokap Polis


QUOTE(failed.hashcheck @ Sep 3 2024, 11:24 PM)
or if you use win11, just use OS level DoH at network setting.
*
just read unifi thread, TM just reroute google dns or cloudflare to their TM dns resource. looks like TM use the most efficient method without provisioning tons of servers for transparent proxy. such evil.

failed.hashcheck
post Sep 3 2024, 11:37 PM

Neighborhood plant pathologist
*******
Senior Member
2,096 posts

Joined: Aug 2009
From: Shithole Klang
QUOTE(zerorating @ Sep 3 2024, 11:29 PM)
just read unifi thread, TM just reroute google dns or cloudflare to their TM dns resource. looks like TM use the most efficient method without provisioning tons of servers for transparent proxy. such evil.
*
that only for plaintext dns right?
Even with DoT they could only block at most.
If they could tamper DoH, like rerouting and return a valid response without hijacking browser certificate, I think we have global IT emergency right now since that means TLS 1.3 has been broken.
zerorating
post Sep 3 2024, 11:41 PM

Miskin Adab
*****
Senior Member
975 posts

Joined: Aug 2007
From: Lokap Polis


QUOTE(failed.hashcheck @ Sep 3 2024, 11:37 PM)
that only for plaintext dns right?
Even with DoT they could only block at most.
If they could tamper DoH, like rerouting and return a valid response without hijacking browser certificate, I think we have global IT emergency right now since that means TLS 1.3 has been broken.
*
IP level la boss, meaning plaintext, dot, doh all redirected.

doh will not work without valid cert.

anyway, i will move to "not widely" known public dns service, koff koff ans1.Singapore3.Level3.net,ans2.Singapore3.Level3.net
AIMS also have DNS server that not filtering ahem site. IP is 110.74.147.67

alibaba also (47.254.217.105), (may send data to CCP)

This post has been edited by zerorating: Sep 3 2024, 11:53 PM
failed.hashcheck
post Sep 3 2024, 11:57 PM

Neighborhood plant pathologist
*******
Senior Member
2,096 posts

Joined: Aug 2009
From: Shithole Klang
QUOTE(zerorating @ Sep 3 2024, 11:41 PM)
IP level la boss, meaning plaintext, dot, doh all redirected.

doh will not work without valid cert.

anyway, i will move to "not widely" known public dns service, koff koff ans1.Singapore3.Level3.net
AIMS also have DNS server that not filtering ahem site. IP is 110.74.147.67
*
kek so DoH simply stop working then

When that finally happen to me I'll just fire up unbound and spawn my own DNS server.
Finally got some real legit use for those Oracle Compute instances that I don't know what to do other than hosting hentai@home laugh.gif
soonwai
post Sep 4 2024, 01:03 AM


********
All Stars
11,459 posts

Joined: Oct 2007
From: KL


QUOTE(failed.hashcheck @ Sep 3 2024, 11:57 PM)
kek so DoH simply stop working then

When that finally happen to me I'll just fire up unbound and  spawn my own DNS server.
Finally got some real legit use for those Oracle Compute instances that I don't know what to do other than hosting hentai@home  laugh.gif
*
everything stop working. even Google dns website also they berani hantam. cos TM curi the whole 8.8.8.8 IP.

user posted image
Before

user posted image
After. You can also click Advanced to look at the SSL cert.


soonwai
post Sep 4 2024, 01:05 AM


********
All Stars
11,459 posts

Joined: Oct 2007
From: KL


Not all ppl affected though so means TM just testing je. So far:

Kajang ❌❌ me & raynman
Kuching ✅ karenzayn
Penang ✅ tng55
PJ ✅ countingcrows
cloudstrife07
post Sep 4 2024, 01:06 AM

I'm back, beaches!
*******
Senior Member
4,688 posts

Joined: Jan 2003
From: http://127.0.0.1


QUOTE(failed.hashcheck @ Sep 3 2024, 11:57 PM)
kek so DoH simply stop working then

When that finally happen to me I'll just fire up unbound and  spawn my own DNS server.
Finally got some real legit use for those Oracle Compute instances that I don't know what to do other than hosting hentai@home  laugh.gif
*
Wah masih lagi run h@h
brkli
post Sep 4 2024, 01:08 AM

On my way
****
Junior Member
592 posts

Joined: Oct 2018
QUOTE(zerorating @ Sep 3 2024, 11:29 PM)
just read unifi thread, TM just reroute google dns or cloudflare to their TM dns resource. looks like TM use the most efficient method without provisioning tons of servers for transparent proxy. such evil.
*
if using TLS, they cannot just simply reroute it just like that. unless they want to break the connection and functionality. reason being the decryption key only exist in google /cloudflare server. public only have the encryption key (public key) to encrypt the payload to send over, so yeah.
soonwai
post Sep 4 2024, 01:12 AM


********
All Stars
11,459 posts

Joined: Oct 2007
From: KL


QUOTE(brkli @ Sep 4 2024, 01:08 AM)
if using TLS, they cannot just simply reroute it just like that. unless they want to break the connection and functionality. reason being the decryption key only exist in google /cloudflare server. public only have the encryption key (public key) to encrypt the payload to send over, so yeah.
*
Already broken. TM's google, cloudflare, opendns & cleanbrowsing dun have DoH or DoT capabilities. No point since they dun have the cert.
zerorating
post Sep 4 2024, 01:13 AM

Miskin Adab
*****
Senior Member
975 posts

Joined: Aug 2007
From: Lokap Polis


QUOTE(brkli @ Sep 4 2024, 01:08 AM)
if using TLS, they cannot just simply reroute it just like that. unless they want to break the connection and functionality. reason being the decryption key only exist in google /cloudflare server. public only have the encryption key (public key) to encrypt the payload to send over, so yeah.
*
they just add static route,have a server that was assigned with IP 8.8.8.8,8.8.4.4, 1.1.1.1(not internet facing) with its job were redirecting all traffic meant for port 53,443 to their DNS server (dns.tm.net.my). totally blocks doh and dot service. tm dns dont support dot and doh, so it wont work at all.

anyway, the leftover workaround were just the alternative public dns, hopefully TM dont block it too.

This post has been edited by zerorating: Sep 4 2024, 02:36 AM
soonwai
post Sep 4 2024, 01:15 AM


********
All Stars
11,459 posts

Joined: Oct 2007
From: KL


take some, give some.

If using Cleanbrowsing-Adult DNS, (185.228.168.10 & 185.228.168.11) last time cannot access www.porno hammer.com.

Now with TM's "upgraded" Cleanbrowsing-Adult DNS (185.228.168.10), can.

TQ TM
zerorating
post Sep 4 2024, 01:25 AM

Miskin Adab
*****
Senior Member
975 posts

Joined: Aug 2007
From: Lokap Polis


QUOTE(soonwai @ Sep 4 2024, 01:15 AM)
take some, give some.

If using Cleanbrowsing-Adult DNS, (185.228.168.10 & 185.228.168.11) last time cannot access www.porno hammer.com.

Now with TM's "upgraded" Cleanbrowsing-Adult DNS (185.228.168.10), can.

TQ TM
*
TM have dns server that dont follow mcmc guideline.
175.139.1.45
175.139.156.45
failed.hashcheck
post Sep 4 2024, 01:30 AM

Neighborhood plant pathologist
*******
Senior Member
2,096 posts

Joined: Aug 2009
From: Shithole Klang
QUOTE(soonwai @ Sep 4 2024, 01:05 AM)
Not all ppl affected though so means TM just testing je. So far:

Kajang ❌❌ me & raynman
Kuching ✅ karenzayn
Penang ✅ tng55
PJ ✅ countingcrows
*
Hard to imagine they would make this standard. The stake is too damn high.
Right now Google have lots of their apps hardwired to their (cleartext) DNS, and it's not unreasonable to see they will go further with DoT in future.
Shit going to hit the fan really hard when that day finally come.

QUOTE(cloudstrife07 @ Sep 4 2024, 01:06 AM)
Wah masih lagi run h@h
*
At some point few years ago Oracle realized they are being stupidly generous offering a rather thicc instances for free (up to 4 micro instances with pooled 200gb storage and up to 24gb ram). And now they will terminate and reclaim those that they deemed underused for 7 consecutive days.

So I have to generate some CPU/ram and traffic to keep my holding, and apparently h@h is perfect for that 🤣
annoymous1234
post Sep 4 2024, 01:33 AM

Look at all my stars!!
*******
Senior Member
7,617 posts

Joined: Mar 2009

In other words, changing to DOH and DOT doesn't work anymore right?

This post has been edited by annoymous1234: Sep 4 2024, 01:34 AM
brkli
post Sep 4 2024, 01:33 AM

On my way
****
Junior Member
592 posts

Joined: Oct 2018
QUOTE(soonwai @ Sep 4 2024, 01:12 AM)
Already broken. TM's google, cloudflare, opendns & cleanbrowsing dun have DoH or DoT capabilities. No point since they dun have the cert.
*
QUOTE(zerorating @ Sep 4 2024, 01:13 AM)
they just add  static route,have a server that was assigned with IP 8.8.8.8,8.8.4.4, 1.1.1.1(not internet facing) with its job were redirecting all traffic meant for port 53 to their DNS server. totally blocks doh and dot service. tm dns dont support dot and doh, so it wont work at all.

anyway, the leftover workaround were just the alternative public dns, hopefully TM dont block it too.
*
lol... kek.. so much for "transparent" proxy.. might as well say DNS hijacking, since not transparent at all..
brkli
post Sep 4 2024, 01:35 AM

On my way
****
Junior Member
592 posts

Joined: Oct 2018
QUOTE(annoymous1234 @ Sep 4 2024, 01:33 AM)
In other words, DOH and DOT doesn't work too?
*
yes, DOH and DOT won't work if your DNS traffic got hijacked (route to another server).
zerorating
post Sep 4 2024, 01:39 AM

Miskin Adab
*****
Senior Member
975 posts

Joined: Aug 2007
From: Lokap Polis


QUOTE(brkli @ Sep 4 2024, 01:33 AM)
lol... kek.. so much for "transparent" proxy.. might as well say DNS hijacking, since not transparent at all..
*
the usage of proxy are resource intensive especially when it come to million of users smile.gif
i dont think we have specialized ASIC for this operation, so general purpose CPU need to be use.

but when it come to NAT and IP routing, we have ASIC for that.
NAQD
post Sep 4 2024, 01:39 AM

Getting Started
**
Junior Member
78 posts

Joined: Nov 2006
From: Bandar Sungai Long


i think my connection affected already. i set secure dns on browser level suddenly got error message that fixable by disabling secure dns

kajang area
soonwai
post Sep 4 2024, 01:43 AM


********
All Stars
11,459 posts

Joined: Oct 2007
From: KL


QUOTE(brkli @ Sep 4 2024, 01:33 AM)
lol... kek.. so much for "transparent" proxy.. might as well say DNS hijacking, since not transparent at all..
*
Not just DNS, they hijack the freakin IP. Malaysia got no laws against that?

This post has been edited by soonwai: Sep 4 2024, 01:51 AM
soonwai
post Sep 4 2024, 01:46 AM


********
All Stars
11,459 posts

Joined: Oct 2007
From: KL


QUOTE(NAQD @ Sep 4 2024, 01:39 AM)
i think my connection affected already. i set secure dns on browser level suddenly got error message that fixable by disabling secure dns

kajang area
*
Congrats. www.porno hammer.com Unlocked :-)

Can you go https://dns.google ?

Anyways just use another DoH provider, other than google, Cloudflare, opendns & cleanbrowsing, you should be ok. For now anyway.

This post has been edited by soonwai: Sep 4 2024, 01:50 AM
brkli
post Sep 4 2024, 01:49 AM

On my way
****
Junior Member
592 posts

Joined: Oct 2018
QUOTE(soonwai @ Sep 4 2024, 01:43 AM)
They hijack the freakin IP. Malaysia got no laws against that?
*
Fakmi: I am the law.
NAQD
post Sep 4 2024, 01:55 AM

Getting Started
**
Junior Member
78 posts

Joined: Nov 2006
From: Bandar Sungai Long


QUOTE(soonwai @ Sep 4 2024, 01:46 AM)
Congrats. www.porno hammer.com Unlocked :-)

Can you go https://dns.google ?

Anyways just use another DoH provider, other than google, Cloudflare, opendns & cleanbrowsing, you should be ok. For now anyway.

*
with secure dns enabled chrome error message is "DNS_PROBE_FINISHED_BAD_SECURE_CONFIG"
on firefox the message is "Firefox wasn’t able to connect to mozilla.cloudflare-dns.com."

NextDNS on firefox still work (for now)
NAQD
post Sep 4 2024, 01:57 AM

Getting Started
**
Junior Member
78 posts

Joined: Nov 2006
From: Bandar Sungai Long


user posted image

this is a hint i guess?
oRoXoRo
post Sep 4 2024, 01:59 AM

Level 1 Audiophile
******
Senior Member
1,630 posts

Joined: Jul 2005


so VPN the only solution?
brkli
post Sep 4 2024, 02:03 AM

On my way
****
Junior Member
592 posts

Joined: Oct 2018
QUOTE(NAQD @ Sep 4 2024, 01:57 AM)
user posted image

this is a hint i guess?
*
hahahaha.. "transparent"....
soonwai
post Sep 4 2024, 02:12 AM


********
All Stars
11,459 posts

Joined: Oct 2007
From: KL


QUOTE(oRoXoRo @ Sep 4 2024, 01:59 AM)
so VPN the only solution?
*
For now can just use another DNS provider. VPN, of course, will also work.
zerorating
post Sep 4 2024, 02:29 AM

Miskin Adab
*****
Senior Member
975 posts

Joined: Aug 2007
From: Lokap Polis


QUOTE(soonwai @ Sep 4 2024, 01:43 AM)
Not just DNS, they hijack the freakin IP. Malaysia got no laws against that?
*
let google know so they can saman gomen.

anyway.
user posted image
zerorating
post Sep 4 2024, 02:30 AM

Miskin Adab
*****
Senior Member
975 posts

Joined: Aug 2007
From: Lokap Polis


QUOTE(oRoXoRo @ Sep 4 2024, 01:59 AM)
so VPN the only solution?
*
you can check my sig
zerorating
post Sep 4 2024, 02:39 AM

Miskin Adab
*****
Senior Member
975 posts

Joined: Aug 2007
From: Lokap Polis


QUOTE(NAQD @ Sep 4 2024, 01:55 AM)
with secure dns enabled chrome error message is "DNS_PROBE_FINISHED_BAD_SECURE_CONFIG"
on firefox the message is "Firefox wasn’t able to connect to mozilla.cloudflare-dns.com."

NextDNS on firefox still work (for now)
*
kena hijacked already.
user posted image
zerorating
post Sep 4 2024, 02:40 AM

Miskin Adab
*****
Senior Member
975 posts

Joined: Aug 2007
From: Lokap Polis


anyway, myself(puchong) kena already.
switching to other public DNS.

have fun.
smallgiant
post Sep 4 2024, 02:47 AM

New Member
*
Junior Member
49 posts

Joined: Feb 2015
Ip blocking? 1.1.1.1 and 8.8.8.8 unreachable.
JohnL77
post Sep 4 2024, 02:48 AM

Regular
******
Senior Member
1,887 posts

Joined: Mar 2013


QUOTE(zerorating @ Sep 4 2024, 02:39 AM)
kena hijacked already.
user posted image
*
Which websites are Minister of Truth blocking?
zerorating
post Sep 4 2024, 02:50 AM

Miskin Adab
*****
Senior Member
975 posts

Joined: Aug 2007
From: Lokap Polis


QUOTE(JohnL77 @ Sep 4 2024, 02:48 AM)
Which websites are Minister of Truth blocking?
*
website that burukkan negara.
prawn (especially child prawn wan)
torrent,warez site
iherb

the list goes on
brkli
post Sep 4 2024, 02:52 AM

On my way
****
Junior Member
592 posts

Joined: Oct 2018
QUOTE(JohnL77 @ Sep 4 2024, 02:48 AM)
Which websites are Minister of Truth blocking?
*
why not ask which websites is allowed. the list might be shorter.
h@ksam
post Sep 4 2024, 02:59 AM

@ is a
*******
Senior Member
3,460 posts

Joined: Nov 2009
From: KL
QUOTE(brkli @ Sep 4 2024, 02:52 AM)
why not ask which websites is allowed. the list might be shorter.
*
1000% allowed

https://www.facebook.com/Fahmi.Fadzil.1/?locale=ms_MY
SUSraynman
post Sep 4 2024, 05:14 AM

Look at all my stars!!
*******
Senior Member
4,333 posts

Joined: Jan 2003


QUOTE(soonwai @ Sep 3 2024, 10:29 PM)
All OK here. Using Adguard Home. But area, Kajang, is affected by the DNS hijacking.

Penang ppl not affected yet right?
*
QUOTE(soonwai @ Sep 4 2024, 01:23 AM)
PJ ok, Seremban OK.

So far only me & raynman in Kajang kena. Maybe because TM need to demo to Anwar at his house in Sg Long.

Kajang ❌❌
Kuching ✅
Penang ✅
PJ ✅✅✅
Seremban ✅
*
You are right. Unifi is showing Anwar they have done his bidding. LOL!!
SUSraynman
post Sep 4 2024, 05:33 AM

Look at all my stars!!
*******
Senior Member
4,333 posts

Joined: Jan 2003


With Cloudflare WARP deactivated, cannot access torrent site https://eztv.tf


user posted image

user posted image




With Cloudflare WARP activated


user posted image

user posted image


cool2.gif
mcchin
post Sep 4 2024, 06:49 AM

SLAVA UKRAINI !
*******
Senior Member
3,902 posts

Joined: Jul 2005
From: Sin Lor, B'worth,Pg.
QUOTE(raynman @ Sep 4 2024, 05:33 AM)
With Cloudflare WARP deactivated, cannot access torrent site https://eztv.tf
user posted image

user posted image
With Cloudflare WARP activated
user posted image

user posted image
cool2.gif
*
Errrmm... Apa tu warp?

I no have anything,

user posted image
dman
post Sep 4 2024, 07:10 AM

On my way
****
Junior Member
540 posts

Joined: Mar 2006


Opis at damansara PJ kena liao.

Now using surfshark vpn.

I think they are encouraging ppl to get VPN lol.


SUSraynman
post Sep 4 2024, 07:49 AM

Look at all my stars!!
*******
Senior Member
4,333 posts

Joined: Jan 2003


QUOTE(mcchin @ Sep 4 2024, 06:49 AM)
Errrmm... Apa tu warp?

I no have anything,

user posted image
*
You didn't kena Unifi's transparent DNS proxy yet.

Anyway where are you located?
SUSraynman
post Sep 4 2024, 07:53 AM

Look at all my stars!!
*******
Senior Member
4,333 posts

Joined: Jan 2003


QUOTE(dman @ Sep 4 2024, 07:10 AM)
Opis at damansara PJ kena liao.

Now using surfshark vpn.

I think they are encouraging ppl to get VPN lol.
*
Cloudflare's WARP is actually a FREE VPN.

I am using it right now.

You can get it here https://1.1.1.1
MR_alien
post Sep 4 2024, 08:04 AM

Mr.Alien on the loss
*******
Senior Member
3,582 posts

Joined: Oct 2007
From: everywhere in sabah



QUOTE(raynman @ Sep 4 2024, 07:53 AM)
Cloudflare's WARP is actually a FREE VPN.

I am using it right now.

You can get it here  https://1.1.1.1
*
cloudflare warp won't work forever because the host server is still at MY and/or SG

u cannot choose server...so end solution, people will still need to subscribe VPN on their own
SUSraynman
post Sep 4 2024, 08:06 AM

Look at all my stars!!
*******
Senior Member
4,333 posts

Joined: Jan 2003


QUOTE(MR_alien @ Sep 4 2024, 08:04 AM)
cloudflare warp won't work forever because the host server is still at MY and/or SG

u cannot choose server...so end solution, people will still need to subscribe VPN on their own
*
I also have free ProtonVPN on standby whistling.gif
soonwai
post Sep 4 2024, 08:12 AM


********
All Stars
11,459 posts

Joined: Oct 2007
From: KL


QUOTE(zerorating @ Sep 4 2024, 02:39 AM)
kena hijacked already.
user posted image
*
Kajang? Bangi?

just read your next mesg. Puchong lang.

This post has been edited by soonwai: Sep 4 2024, 08:13 AM
mcchin
post Sep 4 2024, 08:13 AM

SLAVA UKRAINI !
*******
Senior Member
3,902 posts

Joined: Jul 2005
From: Sin Lor, B'worth,Pg.
QUOTE(raynman @ Sep 4 2024, 07:49 AM)
You didn't kena Unifi's transparent DNS proxy yet.

Anyway where are you located?
*
Park high Penang

GG liou like that
SUSraynman
post Sep 4 2024, 08:17 AM

Look at all my stars!!
*******
Senior Member
4,333 posts

Joined: Jan 2003


QUOTE(mcchin @ Sep 4 2024, 08:13 AM)
Park high Penang

GG liou like that
*
Your turn will come eventually.

Unifi is implementing it in stages.

Let us know again when you kena cool2.gif
soonwai
post Sep 4 2024, 08:18 AM


********
All Stars
11,459 posts

Joined: Oct 2007
From: KL


QUOTE(mcchin @ Sep 4 2024, 08:13 AM)
Park high Penang

GG liou like that
*
Penang macam still OK. DAPower.


This post has been edited by soonwai: Sep 4 2024, 08:18 AM
soonwai
post Sep 4 2024, 08:26 AM


********
All Stars
11,459 posts

Joined: Oct 2007
From: KL


QUOTE(zerorating @ Sep 4 2024, 01:25 AM)
TM have dns server that dont follow mcmc guideline.
175.139.1.45
175.139.156.45
*
These 2 servers weird. The first time I dig a blocked site, it returns TM's hell hole. 175.139.142.25. Then after that, it returns the correct IP addresses.

But other than that, they work. For those who don't want to mess around too much, can just use these as DNS.
tzarain
post Sep 4 2024, 08:27 AM

Regular
******
Senior Member
1,190 posts

Joined: Jan 2003
From: Seremban


QUOTE(soonwai @ Sep 4 2024, 08:12 AM)
Kajang? Bangi?

just read your next mesg. Puchong lang.
*
Kajang confirm kena already last night/early morning. Configured DoT on my phone earlier but when wakes up this morning, saw my phone on Mobile Data and disconnected from WiFi due Private DNS not accessible.
JohnL77
post Sep 4 2024, 10:05 AM

Regular
******
Senior Member
1,887 posts

Joined: Mar 2013


QUOTE(zerorating @ Sep 4 2024, 02:50 AM)
website that burukkan negara.
prawn (especially child prawn wan)
torrent,warez site
iherb

the list goes on
*
Wtf iherb too?


Hmm ya can't open the website anymore. tertiary

This post has been edited by JohnL77: Sep 4 2024, 10:12 AM
zerorating
post Sep 4 2024, 10:42 AM

Miskin Adab
*****
Senior Member
975 posts

Joined: Aug 2007
From: Lokap Polis


QUOTE(JohnL77 @ Sep 4 2024, 10:05 AM)
Wtf iherb too?
Hmm ya can't open the website anymore. tertiary
*
because they are selling unapproved supplement here la.
some brand sells here easily doubled there, despite the product were made in usa.
also some malaysia tends to overdose, some like to abuse.there is one supplement i take there more powerful than antideprresent, you could get high if you dont have any mental illness.
Selectt
post Sep 4 2024, 10:43 AM

wattttt!!
******
Senior Member
1,712 posts

Joined: Aug 2009
baru kena few days ago. i m not on major ISP, i thought i never kena but kena also. i dont think they are testing, they are implementing it
zerorating
post Sep 4 2024, 10:44 AM

Miskin Adab
*****
Senior Member
975 posts

Joined: Aug 2007
From: Lokap Polis


QUOTE(raynman @ Sep 4 2024, 07:53 AM)
Cloudflare's WARP is actually a FREE VPN.

I am using it right now.

You can get it here  https://1.1.1.1
*
lel,later more people know habis semput their vpn resource. too many sangap people here.
Selectt
post Sep 4 2024, 10:44 AM

wattttt!!
******
Senior Member
1,712 posts

Joined: Aug 2009
QUOTE(zerorating @ Sep 4 2024, 01:25 AM)
TM have dns server that dont follow mcmc guideline.
175.139.1.45
175.139.156.45
*
bro, above ip better or 15.235.146.143? which 1 u using?
zerorating
post Sep 4 2024, 10:51 AM

Miskin Adab
*****
Senior Member
975 posts

Joined: Aug 2007
From: Lokap Polis


QUOTE(Selectt @ Sep 4 2024, 10:44 AM)
bro, above ip better or 15.235.146.143? which 1 u using?
*
dunno about tm wan, i avoid tm stuff like a plague, im using aims wan, which literally just re-cache result from google dns. the other were i got from level3 (hostes in singapore)
that 15.235.146.143 do the same stuff,just that it hosted from cheap vps in singapore.

anyway both are unecrypted plaintext dns so pick your poison
JohnL77
post Sep 4 2024, 10:54 AM

Regular
******
Senior Member
1,887 posts

Joined: Mar 2013


QUOTE(Selectt @ Sep 4 2024, 10:43 AM)
baru kena few days ago. i m not on major ISP, i thought i never kena but kena also. i dont think they are testing, they are implementing it
*
Of course they are implementing it la. What is there to test?
brkli
post Sep 4 2024, 11:02 AM

On my way
****
Junior Member
592 posts

Joined: Oct 2018
QUOTE(zerorating @ Sep 4 2024, 10:51 AM)
dunno about tm wan, i avoid tm stuff like a plague, im using aims wan, which literally just re-cache result from google dns. the other were i got from level3 (hostes in singapore)
that 15.235.146.143 do the same stuff,just that it hosted from cheap vps in singapore.

anyway both are unecrypted plaintext dns  so pick your poison
*
next they will intercept all plain(unencrypted) DNS query point to their own DNS. then ur DNS relay to support SSL..
zerorating
post Sep 4 2024, 11:07 AM

Miskin Adab
*****
Senior Member
975 posts

Joined: Aug 2007
From: Lokap Polis


QUOTE(brkli @ Sep 4 2024, 11:02 AM)
next they will intercept all plain(unencrypted) DNS query point to their own DNS. then ur DNS relay to support SSL..
*
common la cat and mouse game, mouse will always need to find a way(loopholes) to avoid their prey.i understand the game,thats why i dont go maki isp here and there
Quantum Geist
post Sep 4 2024, 11:24 AM

Getting Started
**
Junior Member
109 posts

Joined: May 2013


I find it kinda comical that maxis straight up name the 175.139.142.25 as mcmc-redirect
JohnL77
post Sep 4 2024, 11:30 AM

Regular
******
Senior Member
1,887 posts

Joined: Mar 2013


QUOTE(Quantum Geist @ Sep 4 2024, 11:24 AM)
I find it kinda comical that maxis straight up name the 175.139.142.25 as mcmc-redirect
*
Maxis: Bukan sarahan kami, just following orders.
JohnL77
post Sep 4 2024, 11:46 AM

Regular
******
Senior Member
1,887 posts

Joined: Mar 2013


QUOTE(zerorating @ Sep 4 2024, 10:42 AM)
because they are selling unapproved supplement here la.
some brand sells here easily doubled there, despite the product were made in usa.
also some malaysia tends to overdose, some like to abuse.there is one supplement i take there more powerful than antideprresent, you  could get high if you dont have any mental illness.
*
So how are you going to buy your supplements now?
coyouth
post Sep 4 2024, 11:54 AM

Enthusiast
*****
Junior Member
820 posts

Joined: Aug 2006


QUOTE(raynman @ Sep 2 2024, 05:23 AM)

My Cloudfare secure DNS on TM Unifi does not work anymore

After disabling Cloudflare secure DNS in my browser, most of my ahem websites are inaccessible.

Anyone facing the same problem?

It seems VPN is the only way out now
*
looks like we're becoming china now. VPN sales from malaysians will be soaring.
zerorating
post Sep 4 2024, 11:58 AM

Miskin Adab
*****
Senior Member
975 posts

Joined: Aug 2007
From: Lokap Polis


QUOTE(JohnL77 @ Sep 4 2024, 11:46 AM)
So how are you going to buy your supplements now?
*
iherb can still access with other dns what.
zerorating
post Sep 4 2024, 12:08 PM

Miskin Adab
*****
Senior Member
975 posts

Joined: Aug 2007
From: Lokap Polis


QUOTE(coyouth @ Sep 4 2024, 11:54 AM)
looks like we're becoming china now. VPN sales from malaysians will be soaring.
*
still got big loophole la. knowing malaysian they will seek for free one first lel.
if paid one can be questionable, i dont know how the free one will behave lel.
coyouth
post Sep 4 2024, 12:13 PM

Enthusiast
*****
Junior Member
820 posts

Joined: Aug 2006


QUOTE(zerorating @ Sep 4 2024, 12:08 PM)
still got big loophole la. knowing malaysian they will seek for free one first lel.
if paid one can be questionable, i dont know how the free one will behave lel.
*
what do you mean paid one is questionable?
zerorating
post Sep 4 2024, 12:15 PM

Miskin Adab
*****
Senior Member
975 posts

Joined: Aug 2007
From: Lokap Polis


QUOTE(coyouth @ Sep 4 2024, 12:13 PM)
what do you mean paid one is questionable?
*
performance sucks, speedtest meh, ping test jump up and down, very inconsistent. im talking about VPN hosted here btw (name it surfshark, expressvpn, earthvpn etc)
but hey it probably better than kena total block lel.

This post has been edited by zerorating: Sep 4 2024, 12:16 PM
JohnL77
post Sep 4 2024, 12:24 PM

Regular
******
Senior Member
1,887 posts

Joined: Mar 2013


QUOTE(zerorating @ Sep 4 2024, 11:58 AM)
iherb can still access with other dns what.
*
Past few years no problem to receive the parcel.

What I worry is, they start blocking the website now, they'll probably step up kastam enforcement too.

I only order multivitamins, probiotics and sometimes melatonin (which I don't use daily). Like this oso cannot? Thanks, Malaysia Baru.

This post has been edited by JohnL77: Sep 4 2024, 12:26 PM
coyouth
post Sep 4 2024, 12:25 PM

Enthusiast
*****
Junior Member
820 posts

Joined: Aug 2006


QUOTE(zerorating @ Sep 4 2024, 12:15 PM)
performance sucks, speedtest meh, ping test jump up and down, very inconsistent. im talking about VPN hosted here btw (name it surfshark, expressvpn, earthvpn etc)
but hey it probably better than kena total block lel.
*
i guess that's the downside of using VPN. so how come overseas one can be seen as smoother? due to their servers?
zerorating
post Sep 4 2024, 12:31 PM

Miskin Adab
*****
Senior Member
975 posts

Joined: Aug 2007
From: Lokap Polis


QUOTE(coyouth @ Sep 4 2024, 12:25 PM)
i guess that's the downside of using VPN. so how come overseas one can be seen as smoother? due to their servers?
*
their ISP probably have spared bandwidth. anyway alot of content providers already cut corner nowadays, they probably wont cache everything and sometimes their CDN upstream network kantoi.

takes discord for example, cdn at singapore, sometime loads, sometime not around peak hour time here. other resource that using the same equinix, telstra singapore pipe like x.com are not affected. meanwhile resource that host directly in US, like twitch are not affected.

it is really complex, but people blame TM for everything lel. easy target right.

This post has been edited by zerorating: Sep 4 2024, 12:43 PM
zerorating
post Sep 4 2024, 12:32 PM

Miskin Adab
*****
Senior Member
975 posts

Joined: Aug 2007
From: Lokap Polis


QUOTE(JohnL77 @ Sep 4 2024, 12:24 PM)
Past few years no problem to receive the parcel.

What I worry is, they start blocking the website now, they'll probably step up kastam enforcement too.

I only order multivitamins, probiotics and sometimes melatonin (which I don't use daily). Like this oso cannot? Thanks, Malaysia Baru.
*
dunno, last time i order stuff from iherb were like 1 years+, dunno they still give free shipping after rm200.
SUSraynman
post Sep 4 2024, 01:02 PM

Look at all my stars!!
*******
Senior Member
4,333 posts

Joined: Jan 2003


How many more Unifi users have been affected now?
PJng
post Sep 4 2024, 01:04 PM

10k Club
********
All Stars
12,052 posts

Joined: Oct 2017


Use cluudflare and google DNS kena, use other DNS no problem
zerorating
post Sep 4 2024, 01:06 PM

Miskin Adab
*****
Senior Member
975 posts

Joined: Aug 2007
From: Lokap Polis


QUOTE(raynman @ Sep 4 2024, 01:02 PM)
How many more Unifi users have been affected now?
*
probably cyberjaya, putrajaya are affected now.
mine address is puchong, but the tm box said 'cyber'
smallgiant
post Sep 4 2024, 01:12 PM

New Member
*
Junior Member
49 posts

Joined: Feb 2015
QUOTE(zerorating @ Sep 4 2024, 01:06 PM)
probably cyberjaya, putrajaya are affected now.
mine address is puchong, but the tm box said 'cyber'
*
Kidah affected, all browsers on my phone didn't work last night (DoH), bilibili not accessible on TV box (plain dns).
SUSraynman
post Sep 4 2024, 01:20 PM

Look at all my stars!!
*******
Senior Member
4,333 posts

Joined: Jan 2003


QUOTE(zerorating @ Sep 4 2024, 01:06 PM)
probably cyberjaya, putrajaya are affected now.
mine address is puchong, but the tm box said 'cyber'
*
So you are now affected.

How did you avoid the blocking?
zerorating
post Sep 4 2024, 01:25 PM

Miskin Adab
*****
Senior Member
975 posts

Joined: Aug 2007
From: Lokap Polis


QUOTE(raynman @ Sep 4 2024, 01:20 PM)
So you are now affected.

How did you avoid the blocking?
*
use other dns service.
anyway, i will not keep posting dns servers that i use, the less people know, the longer it can survive.
but hey feel free to use dns server on my sig (for people who are totally lost)

This post has been edited by zerorating: Sep 4 2024, 01:25 PM
smallgiant
post Sep 4 2024, 01:33 PM

New Member
*
Junior Member
49 posts

Joined: Feb 2015
QUOTE(zerorating @ Sep 4 2024, 01:25 PM)
use other dns service.
anyway, i will not keep posting dns servers that i use, the less people know, the longer it can survive.
but hey feel free to use dns server on my sig (for people who are totally lost)
*
Plain dns still works? Tm nut doesn't intercept all?
SUSraynman
post Sep 4 2024, 01:34 PM

Look at all my stars!!
*******
Senior Member
4,333 posts

Joined: Jan 2003


QUOTE(smallgiant @ Sep 4 2024, 01:12 PM)
Kidah affected, all browsers on my phone didn't work last night (DoH), bilibili not accessible on TV box (plain dns).
*
When did it first start to be affected? Yesterday?
zerorating
post Sep 4 2024, 01:35 PM

Miskin Adab
*****
Senior Member
975 posts

Joined: Aug 2007
From: Lokap Polis


QUOTE(smallgiant @ Sep 4 2024, 01:33 PM)
Plain dns still works? Tm nut doesn't intercept all?
*
implement transparent proxy for the whole nation scale is costly.
that is why they utilize static route change instead.

i cant brain how much cost for them to implement proxy, enterprise usually use two virtual appliance in one site. one active, one failover, if got load balanced also only two virtual appliance active. each license cost like 2000usd per year.

This post has been edited by zerorating: Sep 4 2024, 01:41 PM
smallgiant
post Sep 4 2024, 01:39 PM

New Member
*
Junior Member
49 posts

Joined: Feb 2015
QUOTE(raynman @ Sep 4 2024, 01:34 PM)
When did it first start to be affected? Yesterday?
*
Past midnight, tried to use the browser around 2 am, no go.
SUSraynman
post Sep 4 2024, 01:41 PM

Look at all my stars!!
*******
Senior Member
4,333 posts

Joined: Jan 2003


QUOTE(smallgiant @ Sep 4 2024, 01:39 PM)
Past midnight, tried to use the browser around 2 am, no go.
*
Thanks for sharing
Oltromen Ripot
post Sep 4 2024, 01:53 PM

👍 999999 person Likes this member
*******
Senior Member
4,034 posts

Joined: Dec 2019
sigh...
on maxis mobile internet

manual dig pornhub.com
@1.1.1.1 hijacked
@8.8.8.8 hijacked
@9.9.9.9 hijacked

so much for MSC charter
SUSraynman
post Sep 4 2024, 01:56 PM

Look at all my stars!!
*******
Senior Member
4,333 posts

Joined: Jan 2003


QUOTE(Oltromen Ripot @ Sep 4 2024, 01:53 PM)
sigh...
on maxis mobile internet

manual dig pornhub.com
@1.1.1.1 hijacked
@8.8.8.8 hijacked
@9.9.9.9 hijacked

so much for MSC charter
*
Quad9 also affected now?
zerorating
post Sep 4 2024, 02:00 PM

Miskin Adab
*****
Senior Member
975 posts

Joined: Aug 2007
From: Lokap Polis


QUOTE(raynman @ Sep 4 2024, 01:56 PM)
Quad9 also affected now?
*
openvpn also kena.
if someone found a loophole, keep it for yourself. i dont think TM will stop at here.
Oltromen Ripot
post Sep 4 2024, 02:02 PM

👍 999999 person Likes this member
*******
Senior Member
4,034 posts

Joined: Dec 2019
QUOTE(raynman @ Sep 4 2024, 01:56 PM)
Quad9 also affected now?
*
user posted image
mhyug
post Sep 4 2024, 02:06 PM

Regular
******
Senior Member
1,553 posts

Joined: May 2009
QUOTE(zerorating @ Sep 4 2024, 02:00 PM)
openvpn also kena.
if someone found a loophole, keep it for yourself. i dont think TM will stop at here.
*
i dont think it will be secret or can be kept secret for long. Some may share some not but eitehr way since enforcement is here they will rat it out until either side breaks.

Well heres what we do know, some isp you can still bypass stuf with the dot settings, dns etc etc etc, while some others cant. VPN is an option albeit we may need to pay for it. good time for VPN companies eh. biggrin.gif

Annoyingly kena blanket censorship of what they deem right and wrong tu yg x tahan.

This post has been edited by mhyug: Sep 4 2024, 02:06 PM
zerorating
post Sep 4 2024, 02:10 PM

Miskin Adab
*****
Senior Member
975 posts

Joined: Aug 2007
From: Lokap Polis


QUOTE(mhyug @ Sep 4 2024, 02:06 PM)
i dont think it will be secret or can be kept secret for long. Some may share some not but eitehr way since enforcement is here they will rat it out until either side breaks.

Well heres what we do know, some isp you can still bypass stuf with the dot settings, dns etc etc etc, while some others cant. VPN is an option albeit we  may need to pay for it. good time for VPN companies eh. biggrin.gif

Annoyingly kena blanket censorship of what they deem right and wrong tu yg x tahan.
*
i am currently plan to have dns server that are not using standard port 53, will like masquerade as port 443
good thing openwrt accept non standard port dns service as upstream biggrin.gif

This post has been edited by zerorating: Sep 4 2024, 02:10 PM
SUSraynman
post Sep 4 2024, 02:10 PM

Look at all my stars!!
*******
Senior Member
4,333 posts

Joined: Jan 2003


QUOTE(mhyug @ Sep 4 2024, 02:06 PM)
i dont think it will be secret or can be kept secret for long. Some may share some not but eitehr way since enforcement is here they will rat it out until either side breaks.

Well heres what we do know, some isp you can still bypass stuf with the dot settings, dns etc etc etc, while some others cant. VPN is an option albeit we  may need to pay for it. good time for VPN companies eh. biggrin.gif

Annoyingly kena blanket censorship of what they deem right and wrong tu yg x tahan.
*


Yes, VPN companies are going to make a killing biggrin.gif
mhyug
post Sep 4 2024, 02:12 PM

Regular
******
Senior Member
1,553 posts

Joined: May 2009
on a long run, ie change of gov, i do wonder if they will still uphold all these policies. since i think(may be wrong) it has some financial impacts since isp's have to do extra stuff ecte tc.

will we see a these censorships dropped?only time and next GE will telll la kot haha
Kadaj
post Sep 4 2024, 02:25 PM

On my way
****
Junior Member
586 posts

Joined: Mar 2006
I'm kind, who look for alternative, take it:
QUOTE
If your country has hijacked Cloudflare (1.1.1.1) and Google DNS (8.8.8.8), here are some alternative DNS services you can try:

    OpenDNS by Cisco
        Primary DNS: 208.67.222.222
        Secondary DNS: 208.67.220.220

    Quad9
        Primary DNS: 9.9.9.9
        Secondary DNS: 149.112.112.112

    AdGuard DNS
        Primary DNS: 94.140.14.14
        Secondary DNS: 94.140.15.15

    Comodo Secure DNS
        Primary DNS: 8.26.56.26
        Secondary DNS: 8.20.247.20

    CleanBrowsing
        Family Filter DNS: 185.228.168.168
        Adult Filter DNS: 185.228.168.10
        Security Filter DNS: 185.228.168.9

    Yandex.DNS
        Basic: 77.88.8.8
        Safe: 77.88.8.88
        Family: 77.88.8.7

    Verisign Public DNS
        Primary DNS: 64.6.64.6
        Secondary DNS: 64.6.65.6

    Neustar UltraDNS Public
        Primary DNS: 156.154.70.1
        Secondary DNS: 156.154.71.1

In environments where DNS hijacking is a concern, you might want to consider using DNS over HTTPS (DoH) or DNS over TLS (DoT) to encrypt your DNS queries, preventing interception or tampering. Some of the services listed above, like Cloudflare and Google, support these protocols, and others might as well. However, you should check each service's documentation for details.

---

Thanks to ChatGPT.

Just a kind reminder, it's easier for ISP to catch those who bypass the DNS blocking but still use unencrypted connection without VPN.
alpha33
post Sep 4 2024, 02:30 PM

Regular
******
Senior Member
1,010 posts

Joined: Apr 2005


anyone using 'dns.adguard.com' on their mobile to bypass ads?
it stopped working for me the same time i am affected with the block(unifi).

but it still works on my unaffected office line.

any alternative for this?
for playing games adfree on mobile.

SUSraynman
post Sep 4 2024, 02:39 PM

Look at all my stars!!
*******
Senior Member
4,333 posts

Joined: Jan 2003


My Cloudflare WARP just started not to work and I cannot access those torrent sites anymore.

Luckily I am now using ProtonVPN to circumvent the blocking.
brkli
post Sep 4 2024, 02:41 PM

On my way
****
Junior Member
592 posts

Joined: Oct 2018
QUOTE(oRoXoRo @ Sep 4 2024, 01:59 AM)
so VPN the only solution?
*
use ipv6.. owai..
junsheng
post Sep 4 2024, 02:51 PM

---> pokemon ftw <---
******
Senior Member
1,257 posts

Joined: Apr 2011
From: Penang Malaysia, sometime KL


QUOTE(mhyug @ Sep 4 2024, 02:12 PM)
on a long run, ie change of gov, i do wonder if they will still uphold all these policies. since i think(may be wrong) it has some financial impacts since isp's have to do extra stuff ecte tc.

will we see a these censorships dropped?only time and next GE will telll la kot haha
*
they will still uphold it, imagine getting all the tools implemented by others but not the hate?
this has been ongoing for quite sometimes, the situation is just like frog in boilling water.
kamfoo
post Sep 4 2024, 03:24 PM

Enthusiast
*****
Junior Member
847 posts

Joined: Nov 2010


QUOTE(alpha33 @ Sep 4 2024, 02:30 PM)
anyone using 'dns.adguard.com' on their mobile to bypass ads?
it stopped working for me the same time i am affected with the block(unifi).

but it still works on my unaffected office line.

any alternative for this?
for playing games adfree on mobile.
*
can u go https://adguard-dns.io/en/welcome.html ? i cannot connect at all...

alpha33
post Sep 4 2024, 04:08 PM

Regular
******
Senior Member
1,010 posts

Joined: Apr 2005


QUOTE(kamfoo @ Sep 4 2024, 03:24 PM)
can u go https://adguard-dns.io/en/welcome.html ? i cannot connect at all...
*
can access.
then i tried to ping dns.adguard.com, it comes back with replies.
maybe tonight i will do a hard reboot on all the routers and see.


SUSredic
post Sep 4 2024, 04:25 PM

Casual
***
Junior Member
330 posts

Joined: Apr 2009

stupid T&C for Brics joining

have to follow CCP's way
stinger
post Sep 4 2024, 04:52 PM

Casual
***
Junior Member
333 posts

Joined: Mar 2005
From: 夢の国


QUOTE(raynman @ Sep 2 2024, 05:23 AM)

My Cloudfare secure DNS on TM Unifi does not work anymore

After disabling Cloudflare secure DNS in my browser, most of my ahem websites are inaccessible.

Anyone facing the same problem?

It seems VPN is the only way out now
*
I tried to share this post on facebook from sinar project but then facebook removed it and noted that it is a "Spam"

Owai sweat.gif
poooky
post Sep 4 2024, 04:57 PM

Enthusiast
*****
Junior Member
844 posts

Joined: Sep 2011
If no access to router, no way to bypass?
SUSifourtos
post Sep 4 2024, 04:58 PM

Look at all my stars!!
*******
Senior Member
2,256 posts

Joined: Feb 2012



QUOTE(raynman @ Sep 2 2024, 05:55 AM)
Which alternate DNS do you use? Cloudflare or Google?
*
openDNS by cisco
annoymous1234
post Sep 4 2024, 05:01 PM

Look at all my stars!!
*******
Senior Member
7,617 posts

Joined: Mar 2009

QUOTE(mhyug @ Sep 4 2024, 02:12 PM)
on a long run, ie change of gov, i do wonder if they will still uphold all these policies. since i think(may be wrong) it has some financial impacts since isp's have to do extra stuff ecte tc.

will we see a these censorships dropped?only time and next GE will telll la kot haha
*
Who ever becomes the government, the policy will remain. Blocking is nothing new, even during BN era, porn, gambling, torrent, etc site has been block, many has been switching DNS to overcome this, it's just that ISP close one eye all these while. Now they are going all out.

I never ever thought that we would actually need VPN to access porn site. What's next? Getting copyright letter from ISP for torrenting like Singapore?
seatux
post Sep 4 2024, 05:04 PM

Getting Started
**
Junior Member
233 posts

Joined: May 2007
QUOTE(annoymous1234 @ Sep 4 2024, 05:01 PM)
Who ever becomes the government, the policy will remain. Blocking is nothing new, even during BN era, porn, gambling, torrent, etc site has been block, many has been switching DNS to overcome this, it's just that ISP close one eye all these while. Now they are going all out.

I never ever thought that we would actually need VPN to access porn site. What's next? Getting copyright letter from ISP for torrenting like Singapore?
*
Seeing that perlesenan laman sesawang media sosial news, it was inevitable its a start to a slippery slope for censorship.
estacado
post Sep 4 2024, 05:15 PM

New Member
*
Junior Member
41 posts

Joined: Mar 2006
Even in mahafiraun days, the internet wasnt blocked, and Anwar benefited from it . There would be no reformasi if atuk blocked everything. I think the reason atuk didn't block was because of is MSC.

This post has been edited by estacado: Sep 4 2024, 05:18 PM
soonwai
post Sep 4 2024, 05:26 PM


********
All Stars
11,459 posts

Joined: Oct 2007
From: KL


QUOTE(kamfoo @ Sep 4 2024, 03:24 PM)
can u go https://adguard-dns.io/en/welcome.html ? i cannot connect at all...
*
adguard-dns.io looks ok
soonwai
post Sep 4 2024, 05:40 PM


********
All Stars
11,459 posts

Joined: Oct 2007
From: KL


We all are overthinking it.

TM is not doing any DNS proxy, DNS redirection, DoH or DoT blocking. I don't think the committee assigned to this knows how or even what those terms are.

All they are doing is taking over the IP addresses. 8.8.8.8 or 9.9.9.9 or 1.1.1.1 no longer goes to Google or Quad9 or Cloudflare respectively. Those addresses now go to TM's Mickey Mouse DNS server which only has port 53 working, no DoH or DoT here.

Easy job done and wait for bonus.
kamfoo
post Sep 4 2024, 05:40 PM

Enthusiast
*****
Junior Member
847 posts

Joined: Nov 2010


QUOTE(alpha33 @ Sep 4 2024, 04:08 PM)
can access.
then i tried to ping dns.adguard.com, it comes back with replies.
maybe tonight i will do a hard reboot on all the routers and see.
*
QUOTE(soonwai @ Sep 4 2024, 05:26 PM)
adguard-dns.io looks ok
*
thanks.

soonwai
post Sep 4 2024, 05:43 PM


********
All Stars
11,459 posts

Joined: Oct 2007
From: KL


QUOTE(raynman @ Sep 4 2024, 07:53 AM)
Cloudflare's WARP is actually a FREE VPN.

I am using it right now.

You can get it here  https://1.1.1.1
*
1.1.1.1 sudah bora bora in Brickfields.

Warp clients can still download from here: https://developers.cloudflare.com/cloudflar.../download-warp/
loonsave
post Sep 4 2024, 05:46 PM

Regular
******
Senior Member
1,635 posts

Joined: May 2005


QUOTE(soonwai @ Sep 4 2024, 05:40 PM)
We all are overthinking it.

TM is not doing any DNS proxy, DNS redirection, DoH or DoT blocking. I don't think the committee assigned to this knows how or even what those terms are.

All they are doing is taking over the IP addresses. 8.8.8.8 or 9.9.9.9 or 1.1.1.1 no longer goes to Google or Quad9 or Cloudflare respectively. Those addresses now go to TM's Mickey Mouse DNS server which only has port 53 working, no DoH or DoT here.

Easy job done and wait for bonus.
*
I think you are right. The traceroute seems route within TM network only. What a brute force method.

This post has been edited by loonsave: Sep 4 2024, 05:46 PM
JohnL77
post Sep 4 2024, 05:48 PM

Regular
******
Senior Member
1,887 posts

Joined: Mar 2013


QUOTE(soonwai @ Sep 4 2024, 05:40 PM)
We all are overthinking it.

TM is not doing any DNS proxy, DNS redirection, DoH or DoT blocking. I don't think the committee assigned to this knows how or even what those terms are.

All they are doing is taking over the IP addresses. 8.8.8.8 or 9.9.9.9 or 1.1.1.1 no longer goes to Google or Quad9 or Cloudflare respectively. Those addresses now go to TM's Mickey Mouse DNS server which only has port 53 working, no DoH or DoT here.

Easy job done and wait for bonus.
*
So what's the solution?
loonsave
post Sep 4 2024, 05:50 PM

Regular
******
Senior Member
1,635 posts

Joined: May 2005


QUOTE(JohnL77 @ Sep 4 2024, 05:48 PM)
So what's the solution?
*
VPN.
shinigamidesu
post Sep 4 2024, 05:50 PM

Getting Started
**
Junior Member
150 posts

Joined: Oct 2009
What is the best value VPN out there?
SUSraynman
post Sep 4 2024, 05:51 PM

Look at all my stars!!
*******
Senior Member
4,333 posts

Joined: Jan 2003


QUOTE(soonwai @ Sep 4 2024, 05:43 PM)
1.1.1.1 sudah bora bora in Brickfields.

Warp clients can still download from here: https://developers.cloudflare.com/cloudflar.../download-warp/
*
WARP now doesn't work for me from 2:30 pm today.

I have to use ProtonVPN now to bypass blocking
Rusty Nail
post Sep 4 2024, 05:53 PM

Why am I still here?
*******
Senior Member
4,883 posts

Joined: Jan 2003
From: Petaling Jaya



any known sites blocked? need to test my setup
SUSraynman
post Sep 4 2024, 05:53 PM

Look at all my stars!!
*******
Senior Member
4,333 posts

Joined: Jan 2003


QUOTE(shinigamidesu @ Sep 4 2024, 05:50 PM)
What is the best value VPN out there?
*
ProtonVPN.

There is a free version
annoymous1234
post Sep 4 2024, 05:55 PM

Look at all my stars!!
*******
Senior Member
7,617 posts

Joined: Mar 2009

QUOTE(raynman @ Sep 4 2024, 05:53 PM)
ProtonVPN.

There is a free version
*
what is the limit for free version?
JohnL77
post Sep 4 2024, 05:56 PM

Regular
******
Senior Member
1,887 posts

Joined: Mar 2013


QUOTE(loonsave @ Sep 4 2024, 05:50 PM)
VPN.
*
If they can block WARP, can't they block VPNs too?

QUOTE(raynman @ Sep 4 2024, 05:51 PM)
WARP now doesn't work for me from 2:30 pm today.

I have to use ProtonVPN now to bypass blocking
*
QUOTE(Rusty Nail @ Sep 4 2024, 05:53 PM)
any known sites blocked? need to test my setup
*
iHerb.
SUSraynman
post Sep 4 2024, 05:57 PM

Look at all my stars!!
*******
Senior Member
4,333 posts

Joined: Jan 2003


QUOTE(annoymous1234 @ Sep 4 2024, 05:55 PM)
what is the limit for free version?
*
There is a limited number of VPN servers to choose from
isr25
post Sep 4 2024, 06:07 PM

Regular
******
Senior Member
1,263 posts

Joined: Nov 2009
From: Johor Bahru



QUOTE(raynman @ Sep 4 2024, 05:51 PM)
WARP now doesn't work for me from 2:30 pm today.

I have to use ProtonVPN now to bypass blocking
*
This is seriously getting bad… I’m not affected yet, but time will tell if they manage to expand this nationwide
JLA
post Sep 4 2024, 06:10 PM

Look at all my stars!!
*******
Senior Member
2,791 posts

Joined: May 2008
seeing BERSIH dan malayakini all quiet
this block dns must be very good
support
lemonkaki
post Sep 4 2024, 06:13 PM

Getting Started
**
Junior Member
104 posts

Joined: Jun 2022
That means DNS.adguard.com also not working anymore ?
Knowing Malaysia, all traffic go thru TM proxy. Ltr got security issue all sure kena together.
SUShamsterdam
post Sep 4 2024, 06:17 PM

New Member
*
Junior Member
15 posts

Joined: Feb 2023


QUOTE(M4A1 @ Sep 2 2024, 01:57 PM)
cause this is the govt that ktard voted in  laugh.gif
*
Ktard voted for BN ahjibkor, your info outdated alr
waikang
post Sep 4 2024, 06:30 PM

New Member
*
Junior Member
16 posts

Joined: May 2012
my area sri petaling kena block too... the weird thing is, some normal website very slow response like china website, also the facebook image loading and video streaming loading also sot sot liao..
soonwai
post Sep 4 2024, 06:36 PM


********
All Stars
11,459 posts

Joined: Oct 2007
From: KL


QUOTE(JohnL77 @ Sep 4 2024, 05:48 PM)
So what's the solution?
*
Remember last time when we change from TM DNS to Google DNS to bypass their DNS blocks. Same thing except now cannot use Google, OpenDNS, Cloudflare, Quad9 & CleanBrowsing.

Save the VPN for when TM ups their game.
soonwai
post Sep 4 2024, 06:39 PM


********
All Stars
11,459 posts

Joined: Oct 2007
From: KL


QUOTE(Rusty Nail @ Sep 4 2024, 05:53 PM)
any known sites blocked? need to test my setup
*
Just go https://8.8.8.8 (https://google.dns)
user posted image
If you're not affected.

Nothing to do with DNS.

This post has been edited by soonwai: Sep 4 2024, 06:53 PM
JohnL77
post Sep 4 2024, 06:39 PM

Regular
******
Senior Member
1,887 posts

Joined: Mar 2013


QUOTE(soonwai @ Sep 4 2024, 06:36 PM)
Remember last time when we change from TM DNS to Google DNS to bypass their DNS blocks. Same thing except now cannot use Google, OpenDNS, Cloudflare, Quad9 & CleanBrowsing.

Save the VPN for when TM ups their game.
*
Eventually all the DNS blocked liao then how?

Majority will not pay for VPN, and isn't it possible for them to go after VPNs too?

See how bingchilling don't know anything about Tiananmen Square. It's possible to erase history.
soonwai
post Sep 4 2024, 06:42 PM


********
All Stars
11,459 posts

Joined: Oct 2007
From: KL


QUOTE(JohnL77 @ Sep 4 2024, 06:39 PM)
Eventually all the DNS blocked liao then how?

Majority will not pay for VPN, and isn't it possible for them to go after VPNs too?

See how bingchilling don't know anything about Tiananmen Square. It's possible to erase history.
*
Then gg lor. Spend more time with family.

This post has been edited by soonwai: Sep 4 2024, 06:42 PM
alexander3133
post Sep 4 2024, 06:48 PM

Regular
******
Senior Member
1,716 posts

Joined: May 2006
From: JDT


QUOTE(soonwai @ Sep 4 2024, 06:39 PM)
Just go https://8.8.8.8 (https://google.dns)
user posted image
If you're not affected.

Nothing to do with DNS.
*
Your URL not same with own screenshot
soonwai
post Sep 4 2024, 06:52 PM


********
All Stars
11,459 posts

Joined: Oct 2007
From: KL


QUOTE(alexander3133 @ Sep 4 2024, 06:48 PM)
Your URL not same with own screenshot
*
TQ, that's just to press my point forward that it's not a TM DNS issue.

But seriously, typo je. smile.gif Corrected


failed.hashcheck
post Sep 4 2024, 06:57 PM

Neighborhood plant pathologist
*******
Senior Member
2,096 posts

Joined: Aug 2009
From: Shithole Klang
QUOTE(shinigamidesu @ Sep 4 2024, 05:50 PM)
What is the best value VPN out there?
*
Vote PN next time
pysh
post Sep 4 2024, 06:57 PM

Casual
***
Junior Member
382 posts

Joined: Jul 2008
From: Penang



i'm on Time.. hamster still works
loserguy
post Sep 4 2024, 07:07 PM

On my way
****
Junior Member
500 posts

Joined: Dec 2019
QUOTE(JohnL77 @ Sep 4 2024, 06:39 PM)
Eventually all the DNS blocked liao then how?

Majority will not pay for VPN, and isn't it possible for them to go after VPNs too?

See how bingchilling don't know anything about Tiananmen Square. It's possible to erase history.
*
It is also possible to self host your own DNS server.

The problem is, once you start something like this, the majority of people will be too lazy to do anything.

Kalau dulu 10000 pipu layan blocked website, vs 10 pipu layan blocked website, u sked or not?
iotbot000
post Sep 4 2024, 07:12 PM

New Member
*
Junior Member
36 posts

Joined: Apr 2019
QUOTE(loserguy @ Sep 4 2024, 07:07 PM)
Kalau dulu 10000 pipu layan blocked website, vs 10 pipu layan blocked website, u sked or not?
*
Will we see a revolt in Kelantan ? biggrin.gif
soonwai
post Sep 4 2024, 07:18 PM


********
All Stars
11,459 posts

Joined: Oct 2007
From: KL


TM got Turkish consultants ka?

https://www.internetsociety.org/blog/2014/0...d-dns-security/

Or maybe one of their network engineers asked ChatGPT and got the same link as above.

This post has been edited by soonwai: Sep 4 2024, 07:19 PM
poooky
post Sep 4 2024, 07:22 PM

Enthusiast
*****
Junior Member
844 posts

Joined: Sep 2011
Can confirm using Warp on Android connect TM WiFi no line at all. things are getting bad.

Hopefully /k got watari killswitch when the time comes
kwss
post Sep 4 2024, 07:25 PM

Regular
******
Senior Member
1,208 posts

Joined: Aug 2018
Cross posting from Unifi thread for those who didn't go there. Running cost should be less than USD $0.60 per month

DNS wall climbing for beginner
This quick guide will teach you how to use CDN to front DoH server using Amazon CloudFront.
The benefit this provides over other method is the difficulty of the censor to block this kind of setup without blocking the whole CDN provider.

Requirements:
AWS Account
Browser / OS / resolver supporting DoH

Login to your AWS account and search for CloudFront. Create a new distribution.
Refer to the setting below and put in your desired DoH server:
user posted image

After you are done creating the distribution, wait for it to finish deploying:
user posted image

Put the address and the full path into your browser / OS / resolver:
user posted image

Finally test your resolver:
user posted image

DNS wall climbing stealth setup
This is a setup for people who are already using CloudFront for their business and wish to hide DoH inside it.
I am using ControlD here instead of Cloudflare DNS. The "/dns-query" in cloudflare is "/p0" in controld.

First add an Origin like below:
user posted image

Then add a Behavior:
user posted image

Wait for it to finish deploying. You will access it via https://mydomain.com/bkaj41f

For people wondering what is my "DoH-fronting" policy, here is it:
user posted image
failed.hashcheck
post Sep 4 2024, 07:31 PM

Neighborhood plant pathologist
*******
Senior Member
2,096 posts

Joined: Aug 2009
From: Shithole Klang
QUOTE(kwss @ Sep 4 2024, 07:25 PM)
Cross posting from Unifi thread for those who didn't go there. Running cost should be less than USD $0.60 per month

DNS wall climbing for beginner
This quick guide will teach you how to use CDN to front DoH server using Amazon CloudFront.
The benefit this provides over other method is the difficulty of the censor to block this kind of setup without blocking the whole CDN provider.

Requirements:
AWS Account
Browser / OS / resolver supporting DoH

Login to your AWS account and search for CloudFront. Create a new distribution.
Refer to the setting below and put in your desired DoH server:
user posted image

After you are done creating the distribution, wait for it to finish deploying:
user posted image

Put the address and the full path into your browser / OS / resolver:
user posted image

Finally test your resolver:
user posted image

DNS wall climbing stealth setup
This is a setup for people who are already using CloudFront for their business and wish to hide DoH inside it.
I am using ControlD here instead of Cloudflare DNS. The "/dns-query" in cloudflare is "/p0" in controld.

First add an Origin like below:
user posted image

Then add a Behavior:
user posted image

Wait for it to finish deploying. You will access it via https://mydomain.com/bkaj41f

For people wondering what is my "DoH-fronting" policy, here is it:
user posted image
*
if like this its much cheaper and easier to just buy nat vps in sg and set up wireguard blink.gif
kwss
post Sep 4 2024, 07:33 PM

Regular
******
Senior Member
1,208 posts

Joined: Aug 2018
QUOTE(failed.hashcheck @ Sep 4 2024, 07:31 PM)
if like this its much cheaper and easier to just buy nat vps in sg and set up wireguard  blink.gif
*
It is...
Actually my USD $0.60 calculation involved some very serious usage.
My current bill for this setup is only USD $0.01
seiferalmercy
post Sep 4 2024, 07:35 PM

Getting Started
**
Junior Member
135 posts

Joined: May 2010


sigh, now cannot access my research database anymore
vapanel
post Sep 4 2024, 07:39 PM

Regular
******
Senior Member
1,075 posts

Joined: Oct 2022


So this is not nationwide?

I can still access everything
SUSraynman
post Sep 4 2024, 07:39 PM

Look at all my stars!!
*******
Senior Member
4,333 posts

Joined: Jan 2003


QUOTE(seiferalmercy @ Sep 4 2024, 07:35 PM)
sigh, now cannot access my research database anymore
*
No choice have to use a VPN
soonwai
post Sep 4 2024, 07:47 PM


********
All Stars
11,459 posts

Joined: Oct 2007
From: KL


QUOTE(vapanel @ Sep 4 2024, 07:39 PM)
So this is not nationwide?

I can still access everything
*
Mostly Klang Valley for now and not all parts but Kajang for sure. Penang, Negeri & JB still ok. Where you?
JohnL77
post Sep 4 2024, 07:48 PM

Regular
******
Senior Member
1,887 posts

Joined: Mar 2013


QUOTE(loserguy @ Sep 4 2024, 07:07 PM)
It is also possible to self host your own DNS server.

The problem is, once you start something like this, the majority of people will be too lazy to do anything.

Kalau dulu 10000 pipu layan blocked website, vs 10 pipu layan blocked website, u sked or not?
*
Honestly, I oso will give up if they go so extreme. If they don't want honest feedback from the rakyat then go ahead just censor us all la. What's the point of sharing information that the majority doesn't have anyway? See I shared information during COVID but you all hate me call me antivax, tried to doxx me, tried to get me arrested.

Fuck la study until Cambridge oso come back here and toe the party like. They are all the same.
soul78
post Sep 4 2024, 07:48 PM

Enthusiast
*****
Junior Member
937 posts

Joined: Jul 2005


https://www.mysterium.network

for those who wanna go down decentralized vpns
JohnL77
post Sep 4 2024, 07:51 PM

Regular
******
Senior Member
1,887 posts

Joined: Mar 2013


QUOTE(seiferalmercy @ Sep 4 2024, 07:35 PM)
sigh, now cannot access my research database anymore
*
People laughed when I said I don't stream.

The painful part is one of my nuclear codes drive died shortly before they started implementing Great Firewall. Not sure if I'll have the chance to recollect everything.
Skylinestar
post Sep 4 2024, 07:52 PM

Mega Duck
********
All Stars
10,478 posts

Joined: Jan 2003
From: Sarawak
QUOTE(soonwai @ Sep 4 2024, 06:39 PM)
Just go https://8.8.8.8 (https://google.dns)
user posted image
If you're not affected.

Nothing to do with DNS.
*
what does it mean? i just visited this website. icon_question.gif
soonwai
post Sep 4 2024, 07:55 PM


********
All Stars
11,459 posts

Joined: Oct 2007
From: KL


QUOTE(Skylinestar @ Sep 4 2024, 07:52 PM)
what does it mean? i just visited this website. icon_question.gif
*
You can still connect to the real Google DNS server. So means your area not affected yet. Where are you?


This post has been edited by soonwai: Sep 4 2024, 07:56 PM
syahpian
post Sep 4 2024, 08:01 PM

Enthusiast
*****
Junior Member
814 posts

Joined: Jul 2008
From: Kota Kinabalu <-> Kuala Lumpur


QUOTE(soul78 @ Sep 4 2024, 07:48 PM)
https://www.mysterium.network

for those who wanna go down decentralized vpns
*
sentinel better, they have free app and telegram bot biggrin.gif
Oltromen Ripot
post Sep 4 2024, 08:01 PM

👍 999999 person Likes this member
*******
Senior Member
4,034 posts

Joined: Dec 2019
QUOTE(Skylinestar @ Sep 4 2024, 07:52 PM)
what does it mean? i just visited this website. icon_question.gif
*
https website needs valid certificate
- valid issuing authority
- valid owning organisation
- valid certificate's start and expiry dates
- certificate name matches the name of respurce being accessed

if you can browse https://dns.google without issue, that means everything is hunky dory.

but if you tried to browse it and get presented with a invalid certificate, and your system clock is correct, it's probably another non-Google entity pretending to be Google, without access to valid Google-owned certificate.

OR, if you can't load it at all and you are certain your internet connection is up, highly likely it is blocked altogether to prevent DoH.

(DNS-over-HTTPS uses tcp/443 just like any other default SSL web hosting.)

This post has been edited by Oltromen Ripot: Sep 4 2024, 08:02 PM
JimbeamofNRT
post Sep 4 2024, 08:05 PM

the Original Lanji@_ Chicken Rice Shop Since 2002
******
Senior Member
1,902 posts

Joined: Sep 2012

QUOTE(soonwai @ Sep 4 2024, 07:55 PM)
You can still connect to the real Google DNS server. So means your area not affected yet. Where are you?
*
muahahaha

all your base are belong to us

user posted image

This post has been edited by JimbeamofNRT: Sep 4 2024, 08:07 PM
loserguy
post Sep 4 2024, 08:30 PM

On my way
****
Junior Member
500 posts

Joined: Dec 2019
QUOTE(JohnL77 @ Sep 4 2024, 07:48 PM)
Honestly, I oso will give up if they go so extreme. If they don't want honest feedback from the rakyat then go ahead just censor us all la. What's the point of sharing  information that the majority doesn't have anyway? See I shared information during COVID but you all hate me call me antivax, tried to doxx me, tried to get me arrested.

Fuck la study until Cambridge oso come back here and toe the party like. They are all the same.
*
I think there should be a balance between free speech and moderation.

All the while we believe in self policing and society self correcting the fringe. Just leave unpopular opinions alone, so that people can see and make up their own minds. I may disagree with what you say, but I will absolutely defend your right to say it. But that was a different time, where passersby can just ignore the crazy person shouting in a corner. Nowadays, via social media, everybody has a global reach.

A lot of people, myself included, got pretty nervous looking at what happened in the UK.

Is the current DNS hijacking overkill? Maybe. But looking at the wild wild west in most social media sites (Facebook, TikTok), I sometimes do wish there would be some form of moderation there.

JohnL77
post Sep 4 2024, 08:31 PM

Regular
******
Senior Member
1,887 posts

Joined: Mar 2013


QUOTE(loserguy @ Sep 4 2024, 08:30 PM)
I think there should be a balance between free speech and moderation.

All the while we believe in self policing and society self correcting the fringe. Just leave unpopular opinions alone, so that people can see and make up their own minds. I may disagree with what you say, but I will absolutely defend your right to say it. But that was a different time, where passersby can just ignore the crazy person shouting in a corner. Nowadays, via social media, everybody has a global reach.

A lot of people, myself included, got pretty nervous looking at what happened in the UK.

Is the current DNS hijacking overkill? Maybe. But looking at the wild wild west in most social media sites (Facebook, TikTok), I sometimes do wish there would be some form of moderation there.
*
Apa sarahan iHerb?
loserguy
post Sep 4 2024, 08:34 PM

On my way
****
Junior Member
500 posts

Joined: Dec 2019
QUOTE(JohnL77 @ Sep 4 2024, 08:31 PM)
Apa sarahan iHerb?
*
Is the current DNS hijacking overkill? Maybe.
Quantum Geist
post Sep 4 2024, 08:40 PM

Getting Started
**
Junior Member
109 posts

Joined: May 2013


QUOTE(loserguy @ Sep 4 2024, 08:30 PM)
I think there should be a balance between free speech and moderation.

All the while we believe in self policing and society self correcting the fringe. Just leave unpopular opinions alone, so that people can see and make up their own minds. I may disagree with what you say, but I will absolutely defend your right to say it. But that was a different time, where passersby can just ignore the crazy person shouting in a corner. Nowadays, via social media, everybody has a global reach.

A lot of people, myself included, got pretty nervous looking at what happened in the UK.

Is the current DNS hijacking overkill? Maybe. But looking at the wild wild west in most social media sites (Facebook, TikTok), I sometimes do wish there would be some form of moderation there.
*
It's a slippery slope, if the current government doesn't abuse the blocking mechanism (which is arguable), then what about the next one, and the one after that and so on. Frankly putting the blocking mechanism in place just opens up a can of worms instead of closing (censoring) it.
poooky
post Sep 4 2024, 08:53 PM

Enthusiast
*****
Junior Member
844 posts

Joined: Sep 2011
is there a simple solution around this? or need to us VPN?
JohnL77
post Sep 4 2024, 08:56 PM

Regular
******
Senior Member
1,887 posts

Joined: Mar 2013


QUOTE(poooky @ Sep 4 2024, 08:53 PM)
is there a simple solution around this? or need to us VPN?
*
https://youtu.be/jKINA-ikgE4


Halibut
post Sep 4 2024, 08:58 PM

Enthusiast
*****
Junior Member
790 posts

Joined: Aug 2022
So far can tengok udang hub lagi
swanlover
post Sep 4 2024, 08:58 PM

Enthusiast
*****
Junior Member
739 posts

Joined: Jun 2014


So many sites cannot access anymore…
loserguy
post Sep 4 2024, 09:00 PM

On my way
****
Junior Member
500 posts

Joined: Dec 2019
-

This post has been edited by loserguy: Sep 4 2024, 09:03 PM
SUSlurkingaround
post Sep 4 2024, 09:19 PM

Rule of Law
*******
Senior Member
7,066 posts

Joined: Sep 2019
From: South Klang Valley suburb




QUOTE(poooky @ Sep 4 2024, 08:53 PM)
is there a simple solution around this? or need to us VPN?
*
.
AFAIK, no need VPN to bypass the ISPs' Transparent DNS proxy blocking by redirecting our DNS servers, ie only need Secure DNS over HTTPS, .......

https://imap.sinarproject.org/news/internet...lic-dns-servers - 6 Aug 2024
.... Securing DNS services

Users being redirected to unauthenticated websites and services that are different from that intended can pose a security risk and result in unexpected technical issues. Standard DNS queries are also unencrypted and addresses requested by users can be viewed and logged.

Users that are affected, can configure their browser settings to enable DNS over HTTPS to secure their DNS lookups by using direct encrypted connection to private or public trusted DNS servers. This will also bypass transparent DNS proxy interference and provide warning of interference.

Firefox Web Browser
Users using Firefox web browser and enable DNS over HTTPS via Settings and the Privacy & Security Tab. Enable Max Protection to use DNS over HTTPs when browning all sites.

Chrome Web Browser
Users using Chrome Web Browser can enable DNS over HTTPS via Settings and the Security tab. Enable Use secure DNS and then select one of the public DNS servers such as Google or Cloudflare ...


For Android Firefox, use the Nightly Release, not the Stable Release, which the former can still access about:config for custom settings, .......

https://www.reddit.com/r/firefox/comments/r...tps_in_firefox/ - Steps to Enable DOH (DNS-OVER-HTTPS) in Firefox NIGHTLY Mobile/Desktop via about:config - 3 yr ago
.

smallgiant
post Sep 4 2024, 09:33 PM

New Member
*
Junior Member
49 posts

Joined: Feb 2015
QUOTE(lurkingaround @ Sep 4 2024, 09:19 PM)
.
AFAIK, no need VPN to bypass the ISPs' Transparent DNS proxy blocking by redirecting our DNS servers, ie only need Secure DNS over HTTPS, .......

...
DoH does not work anymore with those common DNS servers.
s@ni
post Sep 4 2024, 09:36 PM

Gambar Di Lesen Kereta Saya
*******
Senior Member
2,843 posts

Joined: Jun 2005
From: Seasaw



QUOTE(raynman @ Sep 2 2024, 05:23 AM)

My Cloudfare secure DNS on TM Unifi does not work anymore

After disabling Cloudflare secure DNS in my browser, most of my ahem websites are inaccessible.

Anyone facing the same problem?

It seems VPN is the only way out now
*
Wah.. Even during td 2nd stint pun didn't do like this 1.
alpha33
post Sep 4 2024, 09:41 PM

Regular
******
Senior Member
1,010 posts

Joined: Apr 2005


QUOTE(s@ni @ Sep 4 2024, 09:36 PM)
Wah.. Even during td 2nd stint pun didn't do like this 1.
*
dey...adguard dns no more work.
kena cari alternative. PM
SUSlurkingaround
post Sep 4 2024, 09:51 PM

Rule of Law
*******
Senior Member
7,066 posts

Joined: Sep 2019
From: South Klang Valley suburb




QUOTE((lurkingaround @ Sep 4 2024, 09:19 PM)
.
AFAIK, no need VPN to bypass the ISPs' Transparent DNS proxy blocking by redirecting our DNS servers, ie only need Secure DNS over HTTPS, .......

https://imap.sinarproject.org/news/internet...lic-dns-servers - 6 Aug 2024
.... Securing DNS services

Users being redirected to unauthenticated websites and services that are different from that intended can pose a security risk and result in unexpected technical issues. Standard DNS queries are also unencrypted and addresses requested by users can be viewed and logged.

Users that are affected, can configure their browser settings to enable DNS over HTTPS to secure their DNS lookups by using direct encrypted connection to private or public trusted DNS servers. This will also bypass transparent DNS proxy interference and provide warning of interference.

Firefox Web Browser
Users using Firefox web browser and enable DNS over HTTPS via Settings and the Privacy & Security Tab. Enable Max Protection to use DNS over HTTPs when browning all sites.

Chrome Web Browser
Users using Chrome Web Browser can enable DNS over HTTPS via Settings and the Security tab. Enable Use secure DNS and then select one of the public DNS servers such as Google or Cloudflare ...


For Android Firefox, use the Nightly Release, not the Stable Release, which the former can still access about:config for custom settings, .......

https://www.reddit.com/r/firefox/comments/r...tps_in_firefox/ - Steps to Enable DOH (DNS-OVER-HTTPS) in Firefox NIGHTLY Mobile/Desktop via about:config - 3 yr ago
.
*
QUOTE(smallgiant @ Sep 4 2024, 09:33 PM)
DoH does not work anymore with those common DNS servers.
*
.
Maybe Secure DoH not working only for TM Fibre Unifi if using Secure Google8888, Cloudflare1111 and Quad9999 DNS servers = use other secure public DNS servers, eg Level3DNS, ComodoDNS and many others.

It's still working for me on U Mobile with Secure Google8888 DNS server.
....... Secure DoH server can be manually set in the browser Settings or Android System Settings.

Fyi, a long list of public DNS servers to choose from, .......
https://github.com/curl/curl/wiki/DNS-over-...ailable-servers - DNS-over-HTTPS#publicly-available-servers

Can public Proxy servers be also used to bypass this "Great Firewall Of Malaysia".?
.

This post has been edited by lurkingaround: Sep 4 2024, 10:06 PM
NAQD
post Sep 4 2024, 09:53 PM

Getting Started
**
Junior Member
78 posts

Joined: Nov 2006
From: Bandar Sungai Long


refer to the photo below. this site test dns by running query from client side (so it's like you manually change dns server)

affected dns server all show as 'unavailable'

user posted image
loonsave
post Sep 4 2024, 09:59 PM

Regular
******
Senior Member
1,635 posts

Joined: May 2005


» Click to show Spoiler - click again to hide... «


Thanks for sharing the Cloudfront method. How do you secure and prevent other to use your Cloudfront as DNS?
annoymous1234
post Sep 4 2024, 10:17 PM

Look at all my stars!!
*******
Senior Member
7,617 posts

Joined: Mar 2009

I've been using adguard dns as it block ads. Any alternative to block ads?

QUOTE(NAQD @ Sep 4 2024, 09:53 PM)
refer to the photo below. this site test dns by running query from client side (so it's like you manually change dns server)

affected dns server all show as 'unavailable'

user posted image
*
This post has been edited by annoymous1234: Sep 4 2024, 10:18 PM
kwss
post Sep 4 2024, 10:23 PM

Regular
******
Senior Member
1,208 posts

Joined: Aug 2018
QUOTE(loonsave @ Sep 4 2024, 09:59 PM)
» Click to show Spoiler - click again to hide... «


Thanks for sharing the Cloudfront method. How do you secure and prevent other to use your Cloudfront as DNS?
*
From low tech to high tech:
1. Keep the generated URL secret. (first tutorial)
2. Create another Origin with path, then assign a Behavior with "password" as your new path (second tutorial)
3. Use signed URL:
https://docs.aws.amazon.com/AmazonCloudFron...igned-urls.html
kwss
post Sep 4 2024, 10:28 PM

Regular
******
Senior Member
1,208 posts

Joined: Aug 2018
QUOTE(annoymous1234 @ Sep 4 2024, 10:17 PM)
I've been using adguard dns as it block ads. Any alternative to block ads?
*
I'm using Control D. Personal opinion: Better than adguard.
annoymous1234
post Sep 4 2024, 11:06 PM

Look at all my stars!!
*******
Senior Member
7,617 posts

Joined: Mar 2009

QUOTE(kwss @ Sep 4 2024, 10:28 PM)
I'm using Control D. Personal opinion: Better than adguard.
*
thanks will try
loonsave
post Sep 4 2024, 11:13 PM

Regular
******
Senior Member
1,635 posts

Joined: May 2005


QUOTE(kwss @ Sep 4 2024, 10:23 PM)
From low tech to high tech:
1. Keep the generated URL secret. (first tutorial)
2. Create another Origin with path, then assign a Behavior with "password" as your new path (second tutorial)
3. Use signed URL:
https://docs.aws.amazon.com/AmazonCloudFron...igned-urls.html
*
Since TM blackhole 1.1.1.1, wouldn't be it still fail to resolve since the Cloudfront URL origin is cloudflare-dns.com, which is 1.1.1.1

This post has been edited by loonsave: Sep 4 2024, 11:16 PM
s@ni
post Sep 4 2024, 11:20 PM

Gambar Di Lesen Kereta Saya
*******
Senior Member
2,843 posts

Joined: Jun 2005
From: Seasaw



QUOTE(alpha33 @ Sep 4 2024, 09:41 PM)
dey...adguard dns no more work.
kena cari alternative. PM
*
Pmx at russia
SUSlurkingaround
post Sep 4 2024, 11:21 PM

Rule of Law
*******
Senior Member
7,066 posts

Joined: Sep 2019
From: South Klang Valley suburb




Fyi, .......

zerorating,Sep 3 2024, 10:51 PM
sometime openly discussing makes the situation even worse. last few months got people so bangga that dns-over-tls(DOT) or dns-over-https(DOH) can overcome this proxy, didnt awared that TM already one step ahead sad.gif
if everything is blocked, looks like its time for me to setup http proxy via VPS, or aws compute resource, with authentication or allowed IP lists of course.

sorry, if i setup a proxy, it wont be shared resource, i dont want to be responsible of anyone vile action.

.
QUOTE((zerorating @ Sep 3 2024, 11:41 PM)
IP level la boss, meaning plaintext, dot, doh all redirected.

doh will not work without valid cert.

anyway, i will move to "not widely" known public dns service, koff koff ans1.Singapore3.Level3.net,ans2.Singapore3.Level3.net 
AIMS also have DNS server that not filtering ahem site. IP is 110.74.147.67

alibaba also (47.254.217.105), (may send data to CCP)
*
QUOTE((soonwai @ Sep 4 2024, 01:03 AM)
everything stop working. even Google dns website also they berani hantam. cos TM curi the whole 8.8.8.8 IP.

user posted image
Before

user posted image
After. You can also click Advanced to look at the SSL cert.
*
QUOTE((zerorating @ Sep 4 2024, 01:13 AM)
they just add  static route,have a server that was assigned with IP 8.8.8.8,8.8.4.4, 1.1.1.1(not internet facing) with its job were redirecting all traffic meant for port 53,443 to their DNS server (dns.tm.net.my). totally blocks doh and dot service. tm dns dont support dot and doh, so it wont work at all.

anyway, the leftover workaround were just the alternative public dns, hopefully TM dont block it too.
*
.
zerorating,Sep 4 2024, 01:25 AM
TM have dns server that dont follow mcmc guideline.
175.139.1.45
175.139.156.45



QUOTE((zerorating @ Sep 4 2024, 02:10 PM)
i am currently plan to have dns server that are not using standard port 53, will like masquerade as port 443
good thing openwrt accept non standard port dns service as upstream biggrin.gif
*
QUOTE((soonwai @ Sep 4 2024, 05:40 PM)
We all are overthinking it.

TM is not doing any DNS proxy, DNS redirection, DoH or DoT blocking. I don't think the committee assigned to this knows how or even what those terms are.

All they are doing is taking over the IP addresses. 8.8.8.8 or 9.9.9.9 or 1.1.1.1 no longer goes to Google or Quad9 or Cloudflare respectively. Those addresses now go to TM's Mickey Mouse DNS server which only has port 53 working, no DoH or DoT here.

Easy job done and wait for bonus.
*
.
= DoH and DoT can bypass Transparent DNS Proxy blocking. So TM is using IP address blocking to stop DoH bypass using Public Google8888, Cloudflare1111, Quad9999 and other common Public Secure DNS servers. .......

https://surfshark.com/blog/how-do-isps-block-sites - How do ISPs block sites & how to access them anyway -
Martynas Klimas in Internet censorship - 2022, February 17

....
How to remove ISP blocking – and do it successfully

You can bypass ISP blocking (but not remove the fact that they’re blocking stuff) by using the right tool for the right issue. We will discuss what to do if your ISP is engaging in:

DNS blocking
IP blocking
Deep packet inspection ...

You can bypass IP blocking by:

using a Proxy
using a VPN ...


Affected TM users can Google for the lists of free Proxy servers. See can bypass or not.
.

This post has been edited by lurkingaround: Sep 4 2024, 11:33 PM
kwss
post Sep 4 2024, 11:25 PM

Regular
******
Senior Member
1,208 posts

Joined: Aug 2018
QUOTE(loonsave @ Sep 4 2024, 11:13 PM)
Since TM blackhole 1.1.1.1, wouldn't be it still fail to resolve since the Cloudfront URL origin is cloudflare-dns.com, which is 1.1.1.1
*
Basically we put Amazon CDN in front of whatever DoH resolver we want to use.

We then connect to Amazon CDN to get to our preferred DoH, effectively bypassing all blocking.

Bonus: Nobody can block this method without blocking AWS. So this will works for a very long time, until AWS exit Malaysia.

That's why I am sharing this without the slightest worry.
kwss
post Sep 4 2024, 11:28 PM

Regular
******
Senior Member
1,208 posts

Joined: Aug 2018
Everyone needing a no hassle setup can use this:
https://sky.rethinkdns.com/dns-query

It runs on Cloudflare Workers on all edge location and cannot be IP blocked.
If it's DNS bootstrap blocked, just put lowyat.net IP in your HOST file and it should work again
JohnL77
post Sep 4 2024, 11:30 PM

Regular
******
Senior Member
1,887 posts

Joined: Mar 2013


QUOTE(kwss @ Sep 4 2024, 11:28 PM)
Everyone needing a no hassle setup can use this:
https://sky.rethinkdns.com/dns-query

It runs on Cloudflare Workers on all edge location and cannot be IP blocked.
If it's DNS bootstrap blocked, just put lowyat.net IP in your HOST file and it should work again
*
user posted image
failed.hashcheck
post Sep 4 2024, 11:31 PM

Neighborhood plant pathologist
*******
Senior Member
2,096 posts

Joined: Aug 2009
From: Shithole Klang
QUOTE(kwss @ Sep 4 2024, 11:28 PM)
Everyone needing a no hassle setup can use this:
https://sky.rethinkdns.com/dns-query

It runs on Cloudflare Workers on all edge location and cannot be IP blocked.
If it's DNS bootstrap blocked, just put lowyat.net IP in your HOST file and it should work again
*
So its actually possible.
I always thought about this possible solution around using cf worker but never bothered to further look into it.

This post has been edited by failed.hashcheck: Sep 4 2024, 11:32 PM
supsupsui
post Sep 4 2024, 11:36 PM

Getting Started
**
Junior Member
77 posts

Joined: Jun 2019


QUOTE(alpha33 @ Sep 4 2024, 09:41 PM)
dey...adguard dns no more work.
kena cari alternative. PM
*
should post this matter on their forum. Let the pros over there fix for us.
SUSlurkingaround
post Sep 4 2024, 11:41 PM

Rule of Law
*******
Senior Member
7,066 posts

Joined: Sep 2019
From: South Klang Valley suburb




QUOTE(kwss @ Sep 4 2024, 11:25 PM)
Basically we put Amazon CDN in front of whatever DoH resolver we want to use.

We then connect to Amazon CDN to get to our preferred DoH, effectively bypassing all blocking.

Bonus: Nobody can block this method without blocking AWS. So this will works for a very long time, until AWS exit Malaysia.

That's why I am sharing this without the slightest worry.
*
.
AFAIK, if Malaysia's MCMC is ready to ban or block Social Media websites like Facebook and Twitter next year if they do not apply for a local license, MCMC is ready to also similarly ban or block Amazon CDN for bypassing MCMC's website-blocking tools or the "Great Firewall of Malaysia".
.

SUSlurkingaround
post Sep 4 2024, 11:46 PM

Rule of Law
*******
Senior Member
7,066 posts

Joined: Sep 2019
From: South Klang Valley suburb




QUOTE(JohnL77 @ Sep 4 2024, 11:30 PM)
user posted image
*
.
https://rethinkdns.com/ can be accessed on the Internet.
.

loonsave
post Sep 4 2024, 11:49 PM

Regular
******
Senior Member
1,635 posts

Joined: May 2005


QUOTE(lurkingaround @ Sep 4 2024, 11:41 PM)
.
AFAIK, if Malaysia's MCMC is ready to ban or block Social Media websites like Facebook and Twitter next year if they do not apply for a local license, MCMC is ready to also similarly ban or block Amazon CDN for bypassing MCMC's website-blocking tools or the "Great Firewall of Malaysia".
.
*
That's the issue. If MCMC do this without any regulation, they can just block anything when request by the Gov. It's unlikely they will block Amazon CDN since they just official launch AWS MY region.

This post has been edited by loonsave: Sep 4 2024, 11:50 PM
brkli
post Sep 4 2024, 11:50 PM

On my way
****
Junior Member
592 posts

Joined: Oct 2018
QUOTE(lurkingaround @ Sep 4 2024, 11:41 PM)
.
AFAIK, if Malaysia's MCMC is ready to ban or block Social Media websites like Facebook and Twitter next year if they do not apply for a local license, MCMC is ready to also similarly ban or [b]block Amazon CDN for bypassing MCMC's website-blocking tools or the "Great Firewall of Malaysia".[b]
.
*
so.. if ppl choose AWS new region in Malaysia to host their workload. everything cannot load? essentially sampah hosting? or Data center provider is "immune" to these..
thankyou
post Sep 4 2024, 11:53 PM

Regular
******
Senior Member
1,941 posts

Joined: Jan 2003
it's almost impossible to block FB/AWS... If they really do so I think MYR will become sampah again...
SUSlurkingaround
post Sep 4 2024, 11:54 PM

Rule of Law
*******
Senior Member
7,066 posts

Joined: Sep 2019
From: South Klang Valley suburb




QUOTE(loonsave @ Sep 4 2024, 11:49 PM)
That's the issue. If MCMC do this without any regulation, they can just block anything when request by the Gov. It's unlikely they will block Amazon CDN since they just official launch AWS MY region.
*
QUOTE(brkli @ Sep 4 2024, 11:50 PM)
so.. if ppl choose AWS new region in Malaysia to host their workload. everything cannot load? essentially sampah hosting? or Data center provider is "immune" to these..
*
.
Affected TM users can use Google Cloud or M$ Azure if AWS will not cooperate with MCMC.?
.

solarmystic
post Sep 4 2024, 11:55 PM

Getting Started
**
Junior Member
271 posts

Joined: Jun 2009
Who'd have thought Madanon's government would be the one to usher in and enforce the most strictest and complete censorship methods yet?

Not even Thanos (both v1 and v2) or Ah Jib Kor went this far during their respective tenures.

Welp, we get what we vote for i suppose. I mean, frickin iHerb of all sites got blacklisted. iHerb.

This post has been edited by solarmystic: Sep 4 2024, 11:56 PM
kwss
post Sep 4 2024, 11:56 PM

Regular
******
Senior Member
1,208 posts

Joined: Aug 2018
QUOTE(JohnL77 @ Sep 4 2024, 11:30 PM)
user posted image
*
Ummm... Works for me.

QUOTE(failed.hashcheck @ Sep 4 2024, 11:31 PM)
So its actually possible.
I always thought about this possible solution around using cf worker but never bothered to further look into it.
*
Did it work for you?

QUOTE(lurkingaround @ Sep 4 2024, 11:41 PM)
.
AFAIK, if Malaysia's MCMC is ready to ban or block Social Media websites like Facebook and Twitter next year if they do not apply for a local license, MCMC is ready to also similarly ban or block Amazon CDN for bypassing MCMC's website-blocking tools or the "Great Firewall of Malaysia".
.
*
They won't go down this route because the collateral damage is huge. Malaysian bank use AWS too. They won't shut down the financial industry.
Also what message do the government send to data center operator if they do this? If they block AWS I use Cloudflare over CloudFront. They gonna block Cloudflare too?
Amazon, Akamai and Cloudflare are top 3 CDN providers. If they block AWS, it's as good as shutting down the internet.

They will have better luck banning VPN like China, UAE and Indonesia. None of these country dare block Amazon.
loonsave
post Sep 4 2024, 11:59 PM

Regular
******
Senior Member
1,635 posts

Joined: May 2005


QUOTE(lurkingaround @ Sep 4 2024, 11:54 PM)
.
Affected TM users can use Google Cloud or M$ Azure if AWS will not cooperate with MCMC.?
.
*
Amazon spent so much money to build infrastructure in MY. Pretty sure MCMC won't do that.
countingcrows
post Sep 4 2024, 11:59 PM

Getting Started
**
Junior Member
259 posts

Joined: Feb 2023
QUOTE(kwss @ Sep 4 2024, 11:28 PM)
Everyone needing a no hassle setup can use this:
https://sky.rethinkdns.com/dns-query

It runs on Cloudflare Workers on all edge location and cannot be IP blocked.
If it's DNS bootstrap blocked, just put lowyat.net IP in your HOST file and it should work again
*
It uses Cloudflare 1.1.1.1? 😁

user posted image
kwss
post Sep 5 2024, 12:01 AM

Regular
******
Senior Member
1,208 posts

Joined: Aug 2018
QUOTE(countingcrows @ Sep 4 2024, 11:59 PM)
It uses Cloudflare 1.1.1.1? 😁

user posted image
*
Yes it is...
If TM DNS block the domain just use lowyat.net or cloudflare.com IP address in your HOST file.
kwss
post Sep 5 2024, 12:05 AM

Regular
******
Senior Member
1,208 posts

Joined: Aug 2018
QUOTE(loonsave @ Sep 4 2024, 11:59 PM)
Amazon spent so much money to build infrastructure in MY. Pretty sure MCMC won't do that.
*
Don't forget local telco use AWS for their stuff too. They won't nuke themselves out of existence
brkli
post Sep 5 2024, 12:09 AM

On my way
****
Junior Member
592 posts

Joined: Oct 2018
QUOTE(lurkingaround @ Sep 4 2024, 11:54 PM)
.
Affected TM users can use Google Cloud or M$ Azure if AWS will not cooperate with MCMC.?
.
*
MS also setting up data center in JB.. owai..
SUSlurkingaround
post Sep 5 2024, 12:09 AM

Rule of Law
*******
Senior Member
7,066 posts

Joined: Sep 2019
From: South Klang Valley suburb




QUOTE((lurkingaround @ Sep 4 2024, 11:41 PM)
.
AFAIK, if Malaysia's MCMC is ready to ban or block Social Media websites like Facebook and Twitter next year if they do not apply for a local license, MCMC is ready to also similarly ban or block Amazon CDN for bypassing MCMC's website-blocking tools or the "Great Firewall of Malaysia".
.
*
QUOTE(kwss @ Sep 4 2024, 11:56 PM)
They won't go down this route because the collateral damage is huge. Malaysian bank use AWS too. They won't shut down the financial industry.
Also what message do the government send to data center operator if they do this? If they block AWS I use Cloudflare over CloudFront. They gonna block Cloudflare too?
Amazon, Akamai and Cloudflare are top 3 CDN providers. If they block AWS, it's as good as shutting down the internet.

They will have better luck banning VPN like China, UAE and Indonesia. None of these country dare block Amazon.
*
.
AFAIK, online services from Amazon, Google, Facebook, Twitter, etc have been banned by CCP China wrt the Great Firewall Of China and China is still Numba One in the world of wumao and EV-lovers.
....... Maybe Malaysia will be Numba Two. biggrin.gif
.

countingcrows
post Sep 5 2024, 12:13 AM

Getting Started
**
Junior Member
259 posts

Joined: Feb 2023
QUOTE(kwss @ Sep 5 2024, 12:01 AM)
If TM DNS block the domain just use lowyat.net or cloudflare.com IP address in your HOST file.
You mean like this?

user posted image
failed.hashcheck
post Sep 5 2024, 12:15 AM

Neighborhood plant pathologist
*******
Senior Member
2,096 posts

Joined: Aug 2009
From: Shithole Klang
QUOTE(kwss @ Sep 4 2024, 11:56 PM)
Ummm... Works for me.
Did it work for you?

*
Didn't try. Tm routing is so shit that I have to have always on wireguard anyway. So these DNS thing is pretty much irrelevant to me currently.

Even if I decide to do something about it later, I'd rather opt for a straightforward solution - by spawning my own doh server using unbound.

This post has been edited by failed.hashcheck: Sep 5 2024, 12:17 AM
kwss
post Sep 5 2024, 12:16 AM

Regular
******
Senior Member
1,208 posts

Joined: Aug 2018
QUOTE(countingcrows @ Sep 5 2024, 12:13 AM)
You mean like this?

user posted image
*
No no.
Use cloudflare or lowyat IP.
But put sky.rethinkdns.com
kwss
post Sep 5 2024, 12:18 AM

Regular
******
Senior Member
1,208 posts

Joined: Aug 2018
QUOTE(lurkingaround @ Sep 5 2024, 12:09 AM)
.
AFAIK, online services from Amazon, Google, Facebook, Twitter, etc have been banned by CCP China wrt the Great Firewall Of China and China is still Numba One in the world of wumao and EV-lovers.
....... Maybe Malaysia will be Numba Two.  biggrin.gif
.
*
Don't la. If it really happens I think we have bigger things to worry about... Like sanction
loonsave
post Sep 5 2024, 12:18 AM

Regular
******
Senior Member
1,635 posts

Joined: May 2005


QUOTE(lurkingaround @ Sep 5 2024, 12:09 AM)
.
AFAIK, online services from Amazon, Google, Facebook, Twitter, etc have been banned by CCP China wrt the Great Firewall Of China and China is still Numba One in the world of wumao and EV-lovers.
....... Maybe Malaysia will be Numba Two.  biggrin.gif
.
*
Can't compare in that way. China is the world's second largest economy country. They afford to do that. MY got what?

This post has been edited by loonsave: Sep 5 2024, 12:20 AM
zerorating
post Sep 5 2024, 12:19 AM

Miskin Adab
*****
Senior Member
975 posts

Joined: Aug 2007
From: Lokap Polis


QUOTE(kwss @ Sep 4 2024, 11:28 PM)
Everyone needing a no hassle setup can use this:
https://sky.rethinkdns.com/dns-query

It runs on Cloudflare Workers on all edge location and cannot be IP blocked.
If it's DNS bootstrap blocked, just put lowyat.net IP in your HOST file and it should work again
*
lol nice one. but IP not fixed meh?
TM can always hijack these IPs.
loonsave
post Sep 5 2024, 12:20 AM

Regular
******
Senior Member
1,635 posts

Joined: May 2005


QUOTE(failed.hashcheck @ Sep 5 2024, 12:15 AM)
Didn't try.  Tm routing is so shit that I have to have always on wireguard anyway. So these DNS thing is pretty much irrelevant to me currently.

Even if I decide to do something about it later, I'd rather opt for a straightforward solution - by spawning my own doh server using unbound.
*
I was thinking to setup Adguard server + Unbound too. Seems more straight forward to me instead of setup Cloudfrount.
kwss
post Sep 5 2024, 12:23 AM

Regular
******
Senior Member
1,208 posts

Joined: Aug 2018
QUOTE(zerorating @ Sep 5 2024, 12:19 AM)
lol nice one. but IP not fixed meh?
TM can always hijack these IPs.
*
TM can only hijack dedicated DNS IP. They can never hijack CDN IP without breaking the Internet.

If they do it lowyat.net, cloudflare.com and many website will instantly break
brkli
post Sep 5 2024, 12:23 AM

On my way
****
Junior Member
592 posts

Joined: Oct 2018
QUOTE(failed.hashcheck @ Sep 5 2024, 12:15 AM)
Didn't try.  Tm routing is so shit that I have to have always on wireguard anyway. So these DNS thing is pretty much irrelevant to me currently.

Even if I decide to do something about it later, I'd rather opt for a straightforward solution - by spawning my own doh server using unbound.
*
for me, i just use plain old host file. it still baffle me they already hijacking IP, why not just hijack the actual IP of the website they want to block, rather than hijacking DNS server/request.

as simple host file entry can solve it already. unless u got like thousand of block site u want to access.
SUSdattebayo
post Sep 5 2024, 12:24 AM

Look at all my stars!!
*******
Senior Member
5,366 posts

Joined: Aug 2005


QUOTE(kwss @ Sep 5 2024, 12:01 AM)
Yes it is...
If TM DNS block the domain just use lowyat.net or cloudflare.com IP address in your HOST file.
*
it won't work this way

Cloudflare IPs are dynamic from time to time

sometimes you connected to KUL server, sometimes SIN server, depending on latency



countingcrows
post Sep 5 2024, 12:25 AM

Getting Started
**
Junior Member
259 posts

Joined: Feb 2023
QUOTE(kwss @ Sep 5 2024, 12:16 AM)
No no.
Use cloudflare or lowyat IP.
But put sky.rethinkdns.com
*
Like this?

user posted image
zerorating
post Sep 5 2024, 12:26 AM

Miskin Adab
*****
Senior Member
975 posts

Joined: Aug 2007
From: Lokap Polis


QUOTE(kwss @ Sep 5 2024, 12:23 AM)
TM can only hijack dedicated DNS IP. They can never hijack CDN IP without breaking the Internet.

If they do it lowyat.net, cloudflare.com and many website will instantly break
*
you can always do /32 static route what. small inconvenience are acceptable laugh.gif
thankyou
post Sep 5 2024, 12:26 AM

Regular
******
Senior Member
1,941 posts

Joined: Jan 2003
QUOTE(brkli @ Sep 5 2024, 12:23 AM)
for me, i just use plain old host file. it still baffle me they already hijacking IP, why not just hijack the actual IP of the website they want to block, rather than hijacking DNS server/request.

as simple host file entry can solve it already. unless u got like thousand of block site u want to access.
*
It's all about the cost. The IP Firewall at the national level is very costly. Rerouting a small number of DNS server IP addresses and blocking it at the DNS level probably makes more sense.

Look at the current discussion about the DNS issues, it's already got us discuss for days bangwall.gif

This post has been edited by thankyou: Sep 5 2024, 12:28 AM
brkli
post Sep 5 2024, 12:28 AM

On my way
****
Junior Member
592 posts

Joined: Oct 2018
QUOTE(loonsave @ Sep 5 2024, 12:20 AM)
I was thinking to setup Adguard server + Unbound too. Seems more straight forward to me instead of setup Cloudfrount.
*
no need so complicated la. telco and setup proxy u also can setup proxy. just use network load balancer (most cloud provider have this) to forward the tcp traffic to your desidred dns server can already. same like using cloudfront, but support standard TCP, rather than just HTTP/HTTPS for cloudfront.
zerorating
post Sep 5 2024, 12:28 AM

Miskin Adab
*****
Senior Member
975 posts

Joined: Aug 2007
From: Lokap Polis


QUOTE(brkli @ Sep 5 2024, 12:23 AM)
for me, i just use plain old host file. it still baffle me they already hijacking IP, why not just hijack the actual IP of the website they want to block, rather than hijacking DNS server/request.

as simple host file entry can solve it already. unless u got like thousand of block site u want to access.
*
shhhhhhhhh, dont challenge them.
i take dns block than IP block anyday
kwss
post Sep 5 2024, 12:29 AM

Regular
******
Senior Member
1,208 posts

Joined: Aug 2018
QUOTE(dattebayo @ Sep 5 2024, 12:24 AM)
it won't work this way

Cloudflare IPs are dynamic from time to time

sometimes you connected to KUL server, sometimes SIN server, depending on latency
*
Yes correct. That's why only do it when you get domain blocked. But from observation the IP allocation lifetime from Cloudflare is pretty long lived. Plus you can always lookup a new IP.
Or use the Amazon CDN bypass method which is way more stable.

QUOTE(countingcrows @ Sep 5 2024, 12:25 AM)
Like this?

user posted image
*
Correct. But also see my reply on top.
SUSdattebayo
post Sep 5 2024, 12:30 AM

Look at all my stars!!
*******
Senior Member
5,366 posts

Joined: Aug 2005


QUOTE(zerorating @ Sep 5 2024, 12:26 AM)
you can always do /32 static route what. small inconvenience are acceptable  laugh.gif
*
modern CDN networks are having dynamic IPs

at one moment you connect to LYN at 1.2.3.4, 10 minutes later it will resolved to 4.5.6.7

not to mention cloudflare and other CDNs are sharing the same IP for other customers like AirAsia as well, we won't know

so how to block LYN using archaic /32 IP block, without sacrificing AirAsia in the process?

This post has been edited by dattebayo: Sep 5 2024, 12:31 AM
Kadaj
post Sep 5 2024, 12:31 AM

On my way
****
Junior Member
586 posts

Joined: Mar 2006
QUOTE(kwss @ Sep 5 2024, 12:16 AM)
No no.
Use cloudflare or lowyat IP.
But put sky.rethinkdns.com
*
point <any cloudflare cdn ip> to sky.rethinkdns.com
is this how it works?
brkli
post Sep 5 2024, 12:32 AM

On my way
****
Junior Member
592 posts

Joined: Oct 2018
QUOTE(thankyou @ Sep 5 2024, 12:26 AM)
It's all about the cost. The IP Firewall at the national level is very costly. Rerouting a small number of DNS server IP addresses and blocking it at the DNS level probably makes more sense.

Look at the current discussion about the DNS issues, it's already got us discuss for days  bangwall.gif
*
actually no.

let me ask you.

1) traffic for 1.1.1.1 from malaysia
2) traffic to prawnhub from malaysia

which one higher traffic? of course is 1). reason being a lot ppl uses 1.1.1.1 (even those who do not surf prawnhub). now it redirect all to its own server = wasting hosting power. if they just use network level block (or route the selected ip to a black hole). the cost and processing power is very minimal,
Icehart
post Sep 5 2024, 12:33 AM

72.55.191.6
********
All Stars
14,901 posts

Joined: Apr 2005
From: Kuala Lumpur & Selangor


QUOTE(solarmystic @ Sep 4 2024, 11:55 PM)
Who'd have thought Madanon's government would be the one to usher in and enforce the most strictest and complete censorship methods yet?

Not even Thanos (both v1 and v2) or Ah Jib Kor went this far during their respective tenures.

Welp, we get what we vote for i suppose. I mean, frickin iHerb of all sites got blacklisted. iHerb.
*
Yup. Hardcore censorship in place.
kwss
post Sep 5 2024, 12:33 AM

Regular
******
Senior Member
1,208 posts

Joined: Aug 2018
QUOTE(zerorating @ Sep 5 2024, 12:26 AM)
you can always do /32 static route what. small inconvenience are acceptable  laugh.gif
*
Any IP here will work:
https://www.cloudflare.com/ips/

They have no choice but to block all of them
Yes and by doing that sacrifices other million dollar local company. Including bank.

QUOTE(Kadaj @ Sep 5 2024, 12:31 AM)
point <any cloudflare cdn ip> to sky.rethinkdns.com
is this how it works?
*
Yes
countingcrows
post Sep 5 2024, 12:34 AM

Getting Started
**
Junior Member
259 posts

Joined: Feb 2023
QUOTE(kwss @ Sep 5 2024, 12:29 AM)
Yes correct. That's why only do it when you get domain blocked. But from observation the IP allocation lifetime from Cloudflare is pretty long lived. Plus you can always lookup a new IP.
Or use the Amazon CDN bypass method which is way more stable.
Correct. But also see my reply on top.
*
Ok, I understand.
Thanks.
zerorating
post Sep 5 2024, 12:35 AM

Miskin Adab
*****
Senior Member
975 posts

Joined: Aug 2007
From: Lokap Polis


QUOTE(dattebayo @ Sep 5 2024, 12:30 AM)
modern CDN networks are having dynamic IPs

at one moment you connect to LYN at 1.2.3.4, 10 minutes later it will resolved to 4.5.6.7

not to mention cloudflare and other CDNs are sharing the same IP for other customers like AirAsia as well, we won't know

so how to block LYN using archaic /32 IP block, without sacrificing AirAsia in the process?
*
cant comment further, the company i work have dedicated IP per CDN site which we can access most of our endpoint. the only differentiating factor is them SNI.
JohnL77
post Sep 5 2024, 12:35 AM

Regular
******
Senior Member
1,887 posts

Joined: Mar 2013


Sounds like the most convenient and probably secure way is to use VPN? But it costs money.

The free way is to try whatever you guys are discussing here?
brkli
post Sep 5 2024, 12:36 AM

On my way
****
Junior Member
592 posts

Joined: Oct 2018
QUOTE(JohnL77 @ Sep 5 2024, 12:35 AM)
Sounds like the most convenient and probably secure way is to use VPN? But it costs money.

The free way is to try whatever you guys are discussing here?
*
use your company VPN.. owai..
zerorating
post Sep 5 2024, 12:37 AM

Miskin Adab
*****
Senior Member
975 posts

Joined: Aug 2007
From: Lokap Polis


QUOTE(brkli @ Sep 5 2024, 12:36 AM)
use your company VPN.. owai..
*
honestly our company VPN is better than paid vpn hosted in malaysia in term of performance lel.
JohnL77
post Sep 5 2024, 12:38 AM

Regular
******
Senior Member
1,887 posts

Joined: Mar 2013


QUOTE(brkli @ Sep 5 2024, 12:36 AM)
use your company VPN.. owai..
*
So far none of you talked about the Bawang. But cannot use it to torrent.
thankyou
post Sep 5 2024, 12:39 AM

Regular
******
Senior Member
1,941 posts

Joined: Jan 2003
QUOTE(brkli @ Sep 5 2024, 12:32 AM)
actually no.

let me ask you.

1) traffic for 1.1.1.1 from malaysia
2) traffic to prawnhub from malaysia

which one higher traffic? of course is 1). reason being a lot ppl uses 1.1.1.1 (even those who do not surf prawnhub). now it redirect all to its own server = wasting hosting power. if they just use network level block (or route the selected ip to a black hole). the cost and processing power is very minimal,
*
There are too many filtering rules to block all hosting IP addresses. It is probably more realistic to block them at the DNS level.
SUSdattebayo
post Sep 5 2024, 12:40 AM

Look at all my stars!!
*******
Senior Member
5,366 posts

Joined: Aug 2005


QUOTE(zerorating @ Sep 5 2024, 12:35 AM)
cant comment further, the company i work have dedicated IP per CDN site which we can access most of our endpoint. the only differentiating factor is them SNI.
*
that is not cheap man

but when you mention things like SNI it suggests that the same IP probably been shared across multiple users dy


zerorating
post Sep 5 2024, 12:41 AM

Miskin Adab
*****
Senior Member
975 posts

Joined: Aug 2007
From: Lokap Polis


QUOTE(thankyou @ Sep 5 2024, 12:39 AM)
There are too many filtering rules to block all hosting IP addresses. It is probably more realistic to block them at the DNS level.
*
actually they did IP block before during covid, it just to conserve bandwidth as most people stay at home. once bukkake they release it lel.
SUSdattebayo
post Sep 5 2024, 12:42 AM

Look at all my stars!!
*******
Senior Member
5,366 posts

Joined: Aug 2005


QUOTE(zerorating @ Sep 5 2024, 12:41 AM)
actually they did IP block before during covid, it just to conserve bandwidth as most people stay at home. once bukkake they release it lel.
*
its futile as more and more workloads are on cloud these days

just click a few buttons and the IPs already changed

one can configure AWS global accelerator to use US IP, but the backend is still SG/MY region

i dare MCMC to block entire AWS US IP block, essentially 2/3 of the IPs would be blacklisted KEK

This post has been edited by dattebayo: Sep 5 2024, 12:43 AM
Kadaj
post Sep 5 2024, 12:43 AM

On my way
****
Junior Member
586 posts

Joined: Mar 2006
QUOTE(kwss @ Sep 5 2024, 12:33 AM)
They have no choice but to block all of them
Yes and by doing that sacrifices other million dollar local company. Including bank.
Yes
*
Interesting.
Thanks to CDN it's impossible to block the IP without affecting other big corporations which also using same CDN then.
QUOTE(JohnL77 @ Sep 5 2024, 12:35 AM)
Sounds like the most convenient and probably secure way is to use VPN? But it costs money.

The free way is to try whatever you guys are discussing here?
*
Yes, even though you bypass the dns hijack, ISP still can eavesdropping which sites you're connecting to.
Best solution is to use VPN to conceal all your traffic from surveillance.
zerorating
post Sep 5 2024, 12:45 AM

Miskin Adab
*****
Senior Member
975 posts

Joined: Aug 2007
From: Lokap Polis


QUOTE(dattebayo @ Sep 5 2024, 12:40 AM)
that is not cheap man

but when you mention things like SNI it suggests that the same IP probably been shared across multiple users dy
*
yup, the A record provide by CDN provider point to the same IP address (depend on which site, current client geolocation), with custom cert installed too issued by CDN provider, but cant pass HSTS la, to pass HSTS we need to use our own server cert.
still we can use other IP if we feels like, but leceh la need change hosts file bagai

i believe the fixed IP is for convenience, our client just only need to whitelist few of the IP in their firewall rule without the need to whitelist whole subnet.

This post has been edited by zerorating: Sep 5 2024, 12:49 AM
brkli
post Sep 5 2024, 12:47 AM

On my way
****
Junior Member
592 posts

Joined: Oct 2018
QUOTE(Kadaj @ Sep 5 2024, 12:43 AM)
Yes, even though you bypass the dns hijack, ISP still can eavesdropping which sites you're connecting to.
Best solution is to use VPN to conceal all your traffic from surveillance.
*
depend on your level of "eavesdropping ". if the site is running on HTTPS, at most they can see is the destination IP and port. the other part like the FULL HTTP request is encrypted.
thankyou
post Sep 5 2024, 12:48 AM

Regular
******
Senior Member
1,941 posts

Joined: Jan 2003
QUOTE(zerorating @ Sep 5 2024, 12:41 AM)
actually they did IP block before during covid, it just to conserve bandwidth as most people stay at home. once bukkake they release it lel.
*
Actually, MCMC has been floating the idea of monitoring the telco traffic for a long long time. Many proposals have been tabled but in the end, it didn't materialise because it's all down to the cost.

Now with this approach, MCMC simply just put the cost to the telcos:

So, ended up DNS is still the cheapest and most effective way to implement blocking.
zerorating
post Sep 5 2024, 12:52 AM

Miskin Adab
*****
Senior Member
975 posts

Joined: Aug 2007
From: Lokap Polis


QUOTE(thankyou @ Sep 5 2024, 12:48 AM)
Actually, MCMC has been floating the idea of monitoring the telco traffic for a long long time. Many proposals have been tabled but in the end, it didn't materialise because it's all down to the cost.

Now with this approach, MCMC simply just put the cost to the telcos:

So, ended up DNS is still the cheapest and most effective way to implement blocking.
*
makes me wonder wheres the idea of transparent proxy came from, thats like the most expensive method as the appliances (regardless it is virtual or physical) need to check every packet datagram.
Kadaj
post Sep 5 2024, 12:56 AM

On my way
****
Junior Member
586 posts

Joined: Mar 2006
QUOTE(brkli @ Sep 5 2024, 12:47 AM)
depend on your level of "eavesdropping ". if the site is running on HTTPS, at most they can see is the destination IP and port. the other part like the FULL HTTP request is encrypted.
*
Once they notice you bypass their dns hijacking and still able to connect to murrayhunter.substack.com, which they blocked.
It doesn't matter they can't see what content you see. They just know you connected to the blocked sites. They'll identify you as a bad guy.

kwss
post Sep 5 2024, 12:56 AM

Regular
******
Senior Member
1,208 posts

Joined: Aug 2018
QUOTE(Kadaj @ Sep 5 2024, 12:43 AM)
Interesting.
Thanks to CDN it's impossible to block the IP without affecting other big corporations which also using same CDN then.

Yes, even though you bypass the dns hijack, ISP still can eavesdropping which sites you're connecting to.
Best solution is to use VPN to conceal all your traffic from surveillance.
*
Petronas is a big user of AWS.
Unless government don't want their oil money anymore, let's block AWS
thankyou
post Sep 5 2024, 12:56 AM

Regular
******
Senior Member
1,941 posts

Joined: Jan 2003
QUOTE(zerorating @ Sep 5 2024, 12:52 AM)
makes me wonder wheres the idea of transparent proxy came from, thats like the most expensive method as the appliances (regardless it is virtual or physical) need to check every packet datagram.
*
no matter what it's still cheaper than DPI at the national level... There's always a DPI services running at each of the Telco but probably for other purposes i.e. traffic SLA and security purposes. It's definitely going to be costly to fulfill MCMC's requirements biggrin.gif
JohnL77
post Sep 5 2024, 12:57 AM

Regular
******
Senior Member
1,887 posts

Joined: Mar 2013


QUOTE(zerorating @ Sep 5 2024, 12:52 AM)
makes me wonder wheres the idea of transparent proxy came from, thats like the most expensive method as the appliances (regardless it is virtual or physical) need to check every packet datagram.
*
My money is on Da Ge. I wouldn't be surprised if they're sponsoring this.

Notice how not a single wumao has made a single comment about this.

This post has been edited by JohnL77: Sep 5 2024, 12:57 AM
wcnew
post Sep 5 2024, 12:59 AM

Getting Started
**
Junior Member
275 posts

Joined: Oct 2009
Anyone facing watching certain youtube video will blank screen, after i turn on vpn all video back to normal, im using google dns on my router..
thankyou
post Sep 5 2024, 01:00 AM

Regular
******
Senior Member
1,941 posts

Joined: Jan 2003
QUOTE(wcnew @ Sep 5 2024, 12:59 AM)
Anyone facing watching certain youtube video will blank screen, after i turn on vpn all video back to normal, im using google dns on my router..
*
same, kena also... Shopee/Taobao also blank screen from time to time... I've been switching between WARP+, Proton VPN these few days...
JohnL77
post Sep 5 2024, 01:02 AM

Regular
******
Senior Member
1,887 posts

Joined: Mar 2013


QUOTE(wcnew @ Sep 5 2024, 12:59 AM)
Anyone facing watching certain youtube video will blank screen, after i turn on vpn all video back to normal, im using google dns on my router..
*
How do they block individual YouTube videos?
zerorating
post Sep 5 2024, 01:04 AM

Miskin Adab
*****
Senior Member
975 posts

Joined: Aug 2007
From: Lokap Polis


QUOTE(thankyou @ Sep 5 2024, 01:00 AM)
same, kena also... Shopee/Taobao also blank screen from time to time... I've been switching between WARP+, Proton VPN these few days...
*
there are some service will senyap2 use different DNS settings than the one we set on our device. takeover someone else IP memang dick move.
PJng
post Sep 5 2024, 01:04 AM

10k Club
********
All Stars
12,052 posts

Joined: Oct 2017


so before sleep, 9 dns is ok? i put v4 and v6
thankyou
post Sep 5 2024, 01:09 AM

Regular
******
Senior Member
1,941 posts

Joined: Jan 2003
btw, I want to share you can get free WARP+ keys from the following Telegram channel:

https://t.me/warpplus

1) get the key asap as soon as it's posted
2) Have to be evil enough, once get the key fully occupy the 4 - 5 slots with your devices, kick the rest of the hosts out of group
3) You'll fully own the key by occupying all slots
soonwai
post Sep 5 2024, 01:40 AM


********
All Stars
11,459 posts

Joined: Oct 2007
From: KL


QUOTE(PJng @ Sep 5 2024, 01:04 AM)
so before sleep, 9 dns is ok? i put v4 and v6
*
OK, only 9.9.9.9 & 9.9.9.10 are is bora'ed.

This post has been edited by soonwai: Sep 5 2024, 01:42 AM
soonwai
post Sep 5 2024, 02:11 AM


********
All Stars
11,459 posts

Joined: Oct 2007
From: KL


QUOTE(raynman @ Sep 4 2024, 05:51 PM)
WARP now doesn't work for me from 2:30 pm today.

I have to use ProtonVPN now to bypass blocking
*
I just gave Warp a try. Working. Yours still cannot?
user posted image
SUSraynman
post Sep 5 2024, 03:21 AM

Look at all my stars!!
*******
Senior Member
4,333 posts

Joined: Jan 2003


QUOTE(soonwai @ Sep 5 2024, 02:11 AM)
I just gave Warp a try. Working. Yours still cannot?
user posted image
*
Normal WARP (not WARP+) doesn't work for me now.

How did you get WARP+ that works for you?
soonwai
post Sep 5 2024, 03:26 AM


********
All Stars
11,459 posts

Joined: Oct 2007
From: KL


QUOTE(raynman @ Sep 5 2024, 03:21 AM)
Normal WARP (not WARP+) doesn't work for me now.

How did you get WARP+ that works for you?
*
I tried WARP before I entered the key for WARP+. Both works.

https://forum.lowyat.net/index.php?showtopi...ost&p=110391517
See here. Go to the TG channel to get your WARP+ key. Probably easier to just generate your own which is what I did.

Thanks to thankyou
billylks
post Sep 5 2024, 03:33 AM

Getting Started
**
Junior Member
180 posts

Joined: May 2010


QUOTE(brkli @ Sep 5 2024, 12:36 AM)
use your company VPN.. owai..
*
I once "tersalah" opened pron site using client's punya VPN lol.
SUSraynman
post Sep 5 2024, 03:34 AM

Look at all my stars!!
*******
Senior Member
4,333 posts

Joined: Jan 2003


QUOTE(soonwai @ Sep 5 2024, 03:26 AM)
I tried WARP before I entered the key for WARP+. Both works.

https://forum.lowyat.net/index.php?showtopi...ost&p=110391517
See here. Go to the TG channel to get your WARP+ key. Probably easier to just generate your own which is what I did.

Thanks to thankyou
*
Thanks, but I will go with the VPN solution biggrin.gif
billylks
post Sep 5 2024, 03:44 AM

Getting Started
**
Junior Member
180 posts

Joined: May 2010


QUOTE(smallgiant @ Sep 4 2024, 09:33 PM)
DoH does not work anymore with those common DNS servers.
*
Ayam using Time fiber in KL. Still working DoH using Firefox and Chrome. And DoT on Android.

Tested p**nhub.com. Or this site is not blocked?

soonwai
post Sep 5 2024, 03:54 AM


********
All Stars
11,459 posts

Joined: Oct 2007
From: KL


QUOTE(billylks @ Sep 5 2024, 03:44 AM)
Ayam using Time fiber in KL. Still working DoH using Firefox and Chrome. And DoT on Android.

Tested p**nhub.com. Or this site is not blocked?
*
Time & Maxis just using DNS port 53 redirection to their own DNS server. So no worries for 1337 /k.

On TM, p**nhub.com is blocked, youp**n.com is not. confused.gif

This post has been edited by soonwai: Sep 5 2024, 03:55 AM
BladeRider88
post Sep 5 2024, 03:59 AM

On my way
****
Junior Member
554 posts

Joined: Nov 2006


QUOTE(soonwai @ Sep 5 2024, 03:54 AM)
Time & Maxis just using DNS port 53 redirection to their own DNS server. So no worries for 1337 /k.

On TM, p**nhub.com is blocked, youp**n.com is not. :confused:
*
My side on TM (Penang) still ok for now. I still can access youp**n.com after you mentioned that.
I think like you said earlier, it is regional based

cklove96
post Sep 5 2024, 05:54 AM

hehe
*****
Junior Member
707 posts

Joined: Feb 2017

QUOTE(raynman @ Sep 4 2024, 02:02 PM)
How many more Unifi users have been affected now?
*
penang island area still okay @2024-09-05 05:54 AM


affected user can help to check onlyfans kena censored or not?

This post has been edited by cklove96: Sep 5 2024, 06:05 AM
cklove96
post Sep 5 2024, 06:04 AM

hehe
*****
Junior Member
707 posts

Joined: Feb 2017



double post ---

This post has been edited by cklove96: Sep 5 2024, 06:05 AM
beverlykho
post Sep 5 2024, 06:57 AM

On my way
****
Junior Member
501 posts

Joined: Dec 2007


QUOTE(loonsave @ Sep 5 2024, 12:18 AM)
Can't compare in that way. China is the world's second largest economy country. They afford to do that. MY got what?
*
Great Firewall of Malaysia.
smallcrab
post Sep 5 2024, 07:35 AM

Getting Started
**
Junior Member
140 posts

Joined: Jul 2007
From: Puchong


on Maxshit fiber
so far 8.8.8.8 still ok
MR_alien
post Sep 5 2024, 07:36 AM

Mr.Alien on the loss
*******
Senior Member
3,582 posts

Joined: Oct 2007
From: everywhere in sabah



QUOTE(thankyou @ Sep 5 2024, 01:09 AM)
btw, I want to share you can get free WARP+ keys from the following Telegram channel:

https://t.me/warpplus

1) get the key asap as soon as it's posted
2) Have to be evil enough, once get the key fully occupy the 4 - 5 slots with your devices, kick the rest of the hosts out of group
3) You'll fully own the key by occupying all slots
*
ive said it before WARP or WARP+ won't work forever, you'll need proper VPN
because u can't choose server and the host server is still located in MY/SG

you're basically like using nothing at all
soonwai
post Sep 5 2024, 07:54 AM


********
All Stars
11,459 posts

Joined: Oct 2007
From: KL


QUOTE(cklove96 @ Sep 5 2024, 05:54 AM)
penang island area still okay @2024-09-05 05:54 AM
affected user can help to check onlyfans kena censored or not?
*
onlyfans censored 175.139.142.25
IP from 8.8.8.8 google™ (google telekom malaysia)
soonwai
post Sep 5 2024, 07:57 AM


********
All Stars
11,459 posts

Joined: Oct 2007
From: KL


QUOTE(thankyou @ Sep 5 2024, 01:09 AM)
btw, I want to share you can get free WARP+ keys from the following Telegram channel:

https://t.me/warpplus

1) get the key asap as soon as it's posted
2) Have to be evil enough, once get the key fully occupy the 4 - 5 slots with your devices, kick the rest of the hosts out of group
3) You'll fully own the key by occupying all slots
*
Thanks. Easy one to setup for auntie/uncle. Working ok here . Can https://8.8.8.8

This post has been edited by soonwai: Sep 5 2024, 07:58 AM
BladeRider88
post Sep 5 2024, 08:24 AM

On my way
****
Junior Member
554 posts

Joined: Nov 2006


QUOTE(cklove96 @ Sep 5 2024, 05:54 AM)
penang island area still okay @2024-09-05 05:54 AM
affected user can help to check onlyfans kena censored or not?
*
Mine still working fine

From Penang & able to open OF website
Grape Seed X
post Sep 5 2024, 09:22 AM

Getting Started
**
Junior Member
200 posts

Joined: Nov 2022


blocked my movies also nvm.

https://web.netmovies.to/the-lord-of-the-rings-the-rings-of-power/ ://https://web.netmovies.to/the-lord-o...ings-of-power/

but now, even Binance also cannot access! blink.gif blink.gif bangwall.gif bangwall.gif

Diu liama ka hai TM® vmad.gif

Breaking people's rice bowl is akin to killing their parents.

Implementing a blanket ban like this is so god damn stupid!

seriously Fuck u 9 9 TM/Unifi o0o

SUSraynman
post Sep 5 2024, 09:24 AM

Look at all my stars!!
*******
Senior Member
4,333 posts

Joined: Jan 2003


QUOTE(Grape Seed X @ Sep 5 2024, 09:22 AM)
blocked my movies also nvm.

https://web.netmovies.to/the-lord-of-the-rings-the-rings-of-power/ ://https://web.netmovies.to/the-lord-o...ings-of-power/ ://https://web.netmovies.to/the-lord-o...ings-of-power/

but now, even Binance also cannot access!  blink.gif  blink.gif  bangwall.gif  bangwall.gif

Diu liama ka hai TM® vmad.gif

Breaking people's rice bowl is akin to killing their parents.

Implementing a blanket ban like this is so god damn stupid!

seriously Fuck u 9 9 TM/Unifi o0o

*
Not only Binance but KuCoin as well mad.gif
9m2w
post Sep 5 2024, 09:28 AM

Victoria Concordia Crescit
******
Senior Member
1,035 posts

Joined: Feb 2007


Illegal streaming sites alot down. Astro must be happy kek.


Grape Seed X
post Sep 5 2024, 09:30 AM

Getting Started
**
Junior Member
200 posts

Joined: Nov 2022


QUOTE(9m2w @ Sep 5 2024, 09:28 AM)
Illegal streaming sites alot down. Astro must be happy kek.
*
even then, no way i'll b going bck to Astro. Fuck their exorbitant prices
cms
post Sep 5 2024, 09:31 AM

Enthusiast
*****
Junior Member
763 posts

Joined: Jan 2003
QUOTE(Grape Seed X @ Sep 5 2024, 09:22 AM)
blocked my movies also nvm.

https://web.netmovies.to/the-lord-of-the-rings-the-rings-of-power/ ://https://web.netmovies.to/the-lord-o...ings-of-power/ ://https://web.netmovies.to/the-lord-o...ings-of-power/

but now, even Binance also cannot access!  blink.gif  blink.gif  bangwall.gif  bangwall.gif

Diu liama ka hai TM® vmad.gif

Breaking people's rice bowl is akin to killing their parents.

Implementing a blanket ban like this is so god damn stupid!

seriously Fuck u 9 9 TM/Unifi o0o

*
Chill lah, of it's instruction from MCMC then all ISP will follow soon.

Fuck PMX and Fahmi should be more accurate.

Grape Seed X
post Sep 5 2024, 09:34 AM

Getting Started
**
Junior Member
200 posts

Joined: Nov 2022


QUOTE(cms @ Sep 5 2024, 09:31 AM)
Chill lah, of it's instruction from MCMC then all ISP will follow soon.

Fuck PMX and Fahmi should be more accurate.
*
so god damn pissed off early in the morning. thr'll b a shit storm coming ranting.gif ranting.gif

fuck everybody in high places ! ! ! mad.gif
beverlykho
post Sep 5 2024, 09:42 AM

On my way
****
Junior Member
501 posts

Joined: Dec 2007


QUOTE(poooky @ Sep 4 2024, 08:53 PM)
is there a simple solution around this? or need to us VPN?
*
Bukit Bawang Cincin. Security is super tight and therefore it's best for no-other-way-out last resort surfing, and it can be a bit slow.


QUOTE(JohnL77 @ Sep 5 2024, 12:38 AM)
So far none of you talked about the Bawang. But cannot use it to torrent.
*
Bawang cannot torrent and stream, which is what the majority of people use broadband internet for.
annoymous1234
post Sep 5 2024, 09:42 AM

Look at all my stars!!
*******
Senior Member
7,617 posts

Joined: Mar 2009

If everything else fails, then I guess VPN is the only choice?
NathanJeans
post Sep 5 2024, 09:42 AM

Getting Started
**
Junior Member
77 posts

Joined: Nov 2014
Better don't use bawang. Too many cp and virus
JohnL77
post Sep 5 2024, 09:43 AM

Regular
******
Senior Member
1,887 posts

Joined: Mar 2013


QUOTE(MR_alien @ Sep 5 2024, 07:36 AM)
ive said it before WARP or WARP+ won't work forever, you'll need proper VPN
because u can't choose server and the host server is still located in MY/SG

you're basically like using nothing at all
*
Even satellite cannot run because they still have offices.

https://x.com/Starlink/status/1831053118265843722


tokroni76
post Sep 5 2024, 09:43 AM

New Member
*
Junior Member
3 posts

Joined: Dec 2021


Remember Mulmedia Super Corridor mid 90s pledge of no Internet censorship , ever?

Unker remembes

PMX and Fahmi needs to remember that it was the Internet that kept their reformasi movement alive for decades. Without site like Laman Reformasi and SangKancil newsgorup, we will never know about the weekly street protests in 1998-1999.

The mass mainstream media absolutuley thrashes Anwar and his team back then. For sure, Fami was still a schoolboy back then

This technology that kept the Reformasi movement alive compared to KuLi, Tunku and Hussein Onn's rebellion in mid to late 80s. Madey really kept his promise .


Now having power, they gostan and try to censor the tech that they used to great effect in the first place.

Irony of ironies


BladeRider88
post Sep 5 2024, 09:46 AM

On my way
****
Junior Member
554 posts

Joined: Nov 2006


QUOTE(tokroni76 @ Sep 5 2024, 09:43 AM)
Remember Mulmedia Super Corridor  mid 90s pledge of no Internet censorship , ever?

Unker remembes

PMX and Fahmi needs to remember that it was the Internet that kept their reformasi movement alive for decades. Without site like Laman Reformasi and SangKancil newsgorup,  we will never know about the weekly  street protests in 1998-1999.

The mass mainstream media absolutuley thrashes Anwar and his team back then. For sure, Fami was still a schoolboy back then

This technology that kept the Reformasi movement alive compared to KuLi, Tunku and Hussein Onn's rebellion in mid to late 80s. Madey really kept his promise .
Now having power, they gostan and try to censor the tech that they used to great effect in the first place.

Irony of ironies
*
Problem is they use haram this & that, scam here & there to exercise censorship in our internet..so who to blame i also don't know anymore
JohnL77
post Sep 5 2024, 09:46 AM

Regular
******
Senior Member
1,887 posts

Joined: Mar 2013


QUOTE(beverlykho @ Sep 5 2024, 09:42 AM)
Bukit Bawang Cincin. Security is super tight and therefore it's best for no-other-way-out last resort surfing, and it can be a bit slow.
Bawang cannot torrent and stream, which is what the majority of people use broadband internet for.
*
QUOTE(JohnL77 @ Sep 4 2024, 07:51 PM)
People laughed when I said I don't stream.

The painful part is one of my nuclear codes drive died shortly before they started implementing Great Firewall. Not sure if I'll have the chance to recollect everything.
*
TAN WENG
post Sep 5 2024, 09:48 AM

Getting Started
**
Junior Member
145 posts

Joined: Jun 2015


QUOTE(raynman @ Sep 2 2024, 05:23 AM)

My Cloudfare secure DNS on TM Unifi does not work anymore

After disabling Cloudflare secure DNS in my browser, most of my ahem websites are inaccessible.

Anyone facing the same problem?

It seems VPN is the only way out now
*
Damn many normal website load very 🦥 slow. Play game halfway keep disconnecting 😡

This post has been edited by TAN WENG: Sep 5 2024, 09:56 AM
JohnL77
post Sep 5 2024, 09:50 AM

Regular
******
Senior Member
1,887 posts

Joined: Mar 2013


QUOTE(tokroni76 @ Sep 5 2024, 09:43 AM)
Remember Mulmedia Super Corridor  mid 90s pledge of no Internet censorship , ever?

Unker remembes

PMX and Fahmi needs to remember that it was the Internet that kept their reformasi movement alive for decades. Without site like Laman Reformasi and SangKancil newsgorup,  we will never know about the weekly  street protests in 1998-1999.

The mass mainstream media absolutuley thrashes Anwar and his team back then. For sure, Fami was still a schoolboy back then

This technology that kept the Reformasi movement alive compared to KuLi, Tunku and Hussein Onn's rebellion in mid to late 80s. Madey really kept his promise .
Now having power, they gostan and try to censor the tech that they used to great effect in the first place.

Irony of ironies
*
It's not irony, it's HYPOCRISY.
haturaya
post Sep 5 2024, 09:51 AM

Look at all my stars!!
Group Icon
Elite
2,556 posts

Joined: Jan 2003
QUOTE(cms @ Sep 5 2024, 09:31 AM)
Chill lah, of it's instruction from MCMC then all ISP will follow soon.

Fuck PMX and Fahmi should be more accurate.
*
Kick them out in coming GE. thumbup.gif Whoever fee up our internet as it should be, get my vote.
soonwai
post Sep 5 2024, 09:56 AM


********
All Stars
11,459 posts

Joined: Oct 2007
From: KL


QUOTE(Grape Seed X @ Sep 5 2024, 09:22 AM)
web.netmovies.to ❌
netmovies.to ✅


seatux
post Sep 5 2024, 09:59 AM

Getting Started
**
Junior Member
233 posts

Joined: May 2007
I read somewhere even Nvidia account also cannot login. Buy GPU also now cannot access online account lol.
andrekua2
post Sep 5 2024, 10:03 AM

10k Club
********
All Stars
13,483 posts

Joined: Jan 2012


The problem is not the DNS filtering. I dont care if they filter bad contents.

The problem is whether our ISP can handle this workload or not. Playing game is so fucking lag now... unplayable. I still can access binance on my phone on both hotlink and xox.

Does VPN helps?

This post has been edited by andrekua2: Sep 5 2024, 10:04 AM
Grape Seed X
post Sep 5 2024, 10:05 AM

Getting Started
**
Junior Member
200 posts

Joined: Nov 2022


QUOTE(soonwai @ Sep 5 2024, 09:56 AM)
web.netmovies.to ❌
netmovies.to ✅
*
sori unker, but also can't access. chrome, firefox, edge, etc. got to go the VPN route i guess. dun gif them too many ideas,

Min of Com. probably tracking this thread.

QUOTE(seatux @ Sep 5 2024, 09:59 AM)
I read somewhere even Nvidia account also cannot login. Buy GPU also now cannot access online account lol.
*
They cannot blanket ban like this lar! Madness, I tell you!

fuck this shait, gonna go take a break & go somewhr.
thankyou
post Sep 5 2024, 10:07 AM

Regular
******
Senior Member
1,941 posts

Joined: Jan 2003
One thing I don't like about public VPN is that it always trigger the CAPTCHA verification
CPURanger
post Sep 5 2024, 10:12 AM

Enthusiast
*****
Senior Member
889 posts

Joined: Jun 2008


QUOTE(Grape Seed X @ Sep 5 2024, 09:22 AM)
blocked my movies also nvm.

https://web.netmovies.to/the-lord-of-the-rings-the-rings-of-power/ ://https://web.netmovies.to/the-lord-o...ings-of-power/ ://https://web.netmovies.to/the-lord-o...ings-of-power/

but now, even Binance also cannot access!  blink.gif  blink.gif  bangwall.gif  bangwall.gif

Diu liama ka hai TM® vmad.gif

Breaking people's rice bowl is akin to killing their parents.

Implementing a blanket ban like this is so god damn stupid!

seriously Fuck u 9 9 TM/Unifi o0o

*
Works fine with TM Unifi, over here. I use CloudFare DNS with Mac. No VPN.

Binance and onlyfans can access also (front page test only).

soonwai
post Sep 5 2024, 10:14 AM


********
All Stars
11,459 posts

Joined: Oct 2007
From: KL


QUOTE(Grape Seed X @ Sep 5 2024, 10:05 AM)
sori unker, but also can't access. chrome, firefox, edge, etc. got to go the VPN route i guess. dun gif them too many ideas,

Min of Com. probably tracking this thread.
They cannot blanket ban like this lar! Madness, I tell you!

fuck this shait, gonna go take a break & go somewhr.
*
You know how to edit hosts file or not? Or add as static DNS entry in your router if you're using router as your dns.
For web.netmovies.to add the IPs 172.67.178.61 & 104.21.31.158
then should work liao
wong_86
post Sep 5 2024, 10:14 AM

DUDE
****
Junior Member
565 posts

Joined: Oct 2007
From: MARS


hmm..maxis fibre business in JB area cannot access certain website
soonwai
post Sep 5 2024, 10:21 AM


********
All Stars
11,459 posts

Joined: Oct 2007
From: KL


QUOTE(wong_86 @ Sep 5 2024, 10:14 AM)
hmm..maxis fibre business in JB area cannot access certain website
*
Maxis should be just DNS port 53 redirection to their own DNS server. DoH or DoT should take care of this. DoT may be blocked since it's easy to do so but DoH should still work.

This post has been edited by soonwai: Sep 5 2024, 10:21 AM
wong_86
post Sep 5 2024, 10:29 AM

DUDE
****
Junior Member
565 posts

Joined: Oct 2007
From: MARS


user posted image

haiya...
soonwai
post Sep 5 2024, 10:31 AM


********
All Stars
11,459 posts

Joined: Oct 2007
From: KL


How come we dun see the mcmc webpage already? At least I don't on Unifi.

user posted image
*this is the butthurt version.

This post has been edited by soonwai: Sep 5 2024, 10:32 AM
BladeRider88
post Sep 5 2024, 10:32 AM

On my way
****
Junior Member
554 posts

Joined: Nov 2006


user posted image

LOL!
Maxis Business Line with Maxis DNS
soonwai
post Sep 5 2024, 10:33 AM


********
All Stars
11,459 posts

Joined: Oct 2007
From: KL


QUOTE(wong_86 @ Sep 5 2024, 10:29 AM)
user posted image

haiya...
*
Maxis can still go to https://8.8.8.8 right?
wong_86
post Sep 5 2024, 10:36 AM

DUDE
****
Junior Member
565 posts

Joined: Oct 2007
From: MARS


QUOTE(soonwai @ Sep 5 2024, 10:33 AM)
Maxis can still go to https://8.8.8.8 right?
*
yes, can loading, once enable secure dns in chrome, can access any website.

This post has been edited by wong_86: Sep 5 2024, 10:37 AM
JohnL77
post Sep 5 2024, 11:24 AM

Regular
******
Senior Member
1,887 posts

Joined: Mar 2013


Planet tsuji blocked liao.
PJng
post Sep 5 2024, 11:28 AM

10k Club
********
All Stars
12,052 posts

Joined: Oct 2017


QUOTE(BladeRider88 @ Sep 5 2024, 10:32 AM)
user posted image

LOL!
Maxis Business Line with Maxis DNS
*
Just type nslookup then url?
SUSdattebayo
post Sep 5 2024, 11:30 AM

Look at all my stars!!
*******
Senior Member
5,366 posts

Joined: Aug 2005


i tried in Apple platform
if you removed all DNS servers in the network connections

iOS will route all DNS queries to iCloud private relay laugh.gif

so when would FuckMe Madani block iCloud network? whistling.gif
SUSdattebayo
post Sep 5 2024, 11:44 AM

Look at all my stars!!
*******
Senior Member
5,366 posts

Joined: Aug 2005


to check what's your effective DNS servers currently are

go to https://dnsleaktest.com/

This post has been edited by dattebayo: Sep 5 2024, 11:45 AM
JohnL77
post Sep 5 2024, 11:48 AM

Regular
******
Senior Member
1,887 posts

Joined: Mar 2013


QUOTE(dattebayo @ Sep 5 2024, 11:44 AM)
to check what's your effective DNS servers currently are

go to https://dnsleaktest.com/
*
Is this good?

user posted image
ListenToTheWind
post Sep 5 2024, 11:52 AM

Casual
***
Junior Member
453 posts

Joined: Feb 2014
Semalam my Maxis suddenly cannot access sukebei.Nyaa already.

So, I quickly follow /k/tard advice turn on DNS over HTTPS on my browser.

Now I can access Nyaa again. I am a happy man.
BladeRider88
post Sep 5 2024, 11:54 AM

On my way
****
Junior Member
554 posts

Joined: Nov 2006


QUOTE(PJng @ Sep 5 2024, 11:28 AM)
Just type nslookup then url?
*
user posted image

Here you go

Sorry have to censor the server name due to privacy. I turn off the DoH just to prove that Maxis Business Line with Maxis DNS already being hijacked as per Maxis official announcements
BladeRider88
post Sep 5 2024, 11:55 AM

On my way
****
Junior Member
554 posts

Joined: Nov 2006


QUOTE(JohnL77 @ Sep 5 2024, 11:48 AM)
Is this good?

user posted image
*
Can you verify from here as well?

https://one.one.one.one/help/

Based on your screenshot you are "technically" safe
SUSKaya Butter Toast
post Sep 5 2024, 11:56 AM

Casual
***
Junior Member
325 posts

Joined: Feb 2022

Fark me is playing with fire.


JohnL77
post Sep 5 2024, 11:57 AM

Regular
******
Senior Member
1,887 posts

Joined: Mar 2013


QUOTE(BladeRider88 @ Sep 5 2024, 11:54 AM)
user posted image

Here you go

Sorry have to censor the server name due to privacy. I turn off the DoH just to prove that Maxis Business Line with Maxis DNS already being hijacked as per Maxis official announcements
*
Dei, why u all simp KipasSaja? You know you (used) to be able to get udang for free? And smart guys will pool funds to subscribe KipasSaja then download everything and share it.
JohnL77
post Sep 5 2024, 11:59 AM

Regular
******
Senior Member
1,887 posts

Joined: Mar 2013


QUOTE(BladeRider88 @ Sep 5 2024, 11:55 AM)
Can you verify from here as well?

https://one.one.one.one/help/

Based on your screenshot you are "technically" safe
*
Any info I should censor before sharing?


BladeRider88
post Sep 5 2024, 12:00 PM

On my way
****
Junior Member
554 posts

Joined: Nov 2006


QUOTE(JohnL77 @ Sep 5 2024, 11:59 AM)
Any info I should censor before sharing?
*
Nothing to hide for this one. No IP will be shown
BladeRider88
post Sep 5 2024, 12:01 PM

On my way
****
Junior Member
554 posts

Joined: Nov 2006


QUOTE(JohnL77 @ Sep 5 2024, 11:57 AM)
Dei, why u all simp KipasSaja? You know you (used) to be able to get udang for free? And smart guys will pool funds to subscribe KipasSaja then download everything and share it.
*
TBH, i never subscribe or simp KipasSaja. I know this KipasSaja very popular and i think it will be on the target list, so just try to see the output result tongue.gif
JohnL77
post Sep 5 2024, 12:02 PM

Regular
******
Senior Member
1,887 posts

Joined: Mar 2013


QUOTE(BladeRider88 @ Sep 5 2024, 12:00 PM)
Nothing to hide for this one. No IP will be shown
*
Can't use WARP on desktop, right? Another user mentioned suckabee sudah blocked, cannot tortilla nuke codes anymore.

user posted image

This post has been edited by JohnL77: Sep 5 2024, 12:03 PM
hafiziza
post Sep 5 2024, 12:03 PM

Getting Started
**
Junior Member
131 posts

Joined: Jul 2011


QUOTE(dattebayo @ Sep 5 2024, 12:30 PM)
i tried in Apple platform
if you removed all DNS servers in the network connections

iOS will route all DNS queries to iCloud private relay laugh.gif

so when would FuckMe Madani block iCloud network? whistling.gif
*
Note that iCloud private relay only works with Safari. It doesn't work with other browsers and apps.
fbiotai93
post Sep 5 2024, 12:06 PM

New Member
*
Junior Member
11 posts

Joined: Mar 2010
Use this dns its still can bypass

https://controld.com/free-dns

RIP Adguard
beverlykho
post Sep 5 2024, 12:07 PM

On my way
****
Junior Member
501 posts

Joined: Dec 2007


QUOTE(kwss @ Sep 4 2024, 07:25 PM)

For people wondering what is my "DoH-fronting" policy, here is it:
user posted image
*
How do I create this?
BladeRider88
post Sep 5 2024, 12:09 PM

On my way
****
Junior Member
554 posts

Joined: Nov 2006


QUOTE(JohnL77 @ Sep 5 2024, 12:02 PM)
Can't use WARP on desktop, right? Another user mentioned suckabee sudah blocked, cannot tortilla nuke codes anymore.

user posted image
*
I never use WRAP so cannot comment
But i am using DoH with multi stream of DNS combined

JohnL77
post Sep 5 2024, 12:09 PM

Regular
******
Senior Member
1,887 posts

Joined: Mar 2013


QUOTE(fbiotai93 @ Sep 5 2024, 12:06 PM)
Use this dns its still can bypass

https://controld.com/free-dns

RIP Adguard
*
For now.

Should teach people how to independently find DNS that still works, instead of posting it here then later Minister of Truth will block it.

But even if you use DNS, Minister of Truth still knows you visit falungong fark news websites.
brkli
post Sep 5 2024, 12:30 PM

On my way
****
Junior Member
592 posts

Joined: Oct 2018
QUOTE(andrekua2 @ Sep 5 2024, 10:03 AM)
The problem is not the DNS filtering. I dont care if they filter bad contents.

The problem is whether our ISP can handle this workload or not. Playing game is so fucking lag now... unplayable. I still can access binance on my phone on both hotlink and xox.

Does VPN helps?
*
depend on how the filtering works. if they just merely redirecting DNS traffic, it can work better as u by pass that checking and able to really use better DNS server than ISP's shitty ones.
Grape Seed X
post Sep 5 2024, 01:21 PM

Getting Started
**
Junior Member
200 posts

Joined: Nov 2022


QUOTE(JohnL77 @ Sep 5 2024, 11:57 AM)
Dei, why u all simp KipasSaja? You know you (used) to be able to get udang for free? And smart guys will pool funds to subscribe KipasSaja then download everything and share it.
*
QUOTE(BladeRider88 @ Sep 5 2024, 12:01 PM)
TBH, i never subscribe or simp KipasSaja. I know this KipasSaja very popular and i think it will be on the target list, so just try to see the output result  tongue.gif
*
geee, i've only ever heard my koliks call it HanyaKipas. I guess both translations are legit tongue.gif
soonwai
post Sep 5 2024, 01:58 PM


********
All Stars
11,459 posts

Joined: Oct 2007
From: KL


QUOTE(JohnL77 @ Sep 5 2024, 12:02 PM)
Can't use WARP on desktop, right? Another user mentioned suckabee sudah blocked, cannot tortilla nuke codes anymore.

...
*
Can. Still working.
user posted image
JohnL77
post Sep 5 2024, 02:08 PM

Regular
******
Senior Member
1,887 posts

Joined: Mar 2013


QUOTE(soonwai @ Sep 5 2024, 01:58 PM)
Can. Still working.
user posted image
*
How to use WARP on desktop? Is it browser only?
xyz_cityhunter
post Sep 5 2024, 02:35 PM

Getting Started
**
Junior Member
238 posts

Joined: Dec 2010
From: Kedah


QUOTE(soonwai @ Sep 5 2024, 01:58 PM)
Can. Still working.
user posted image
*
The key generated by bot only works until Nov 1 and it will fallback to regular Warp later?

Saw others comment about WireGuard but seems like it also need the Warp/Warp+ key to work so this is just alternative to use Warp/Warp+ without installing the Cloudflare software? rclxub.gif
haya
post Sep 5 2024, 02:55 PM

Sarawakian first!
*******
Senior Member
2,067 posts

Joined: Jan 2003

MCMC orders DNS redirection for businesses, govts, enterprises by Sept 30, according to Maxis FAQ
By Angelin Yeoh and Christopher Fam
Internet
Thursday, 05 Sep 2024
2:20 PM MYT

PETALING JAYA: According to an FAQ posted by Maxis, the Malaysian Communications and Multimedia Commission (MCMC) is requiring all Internet service providers to implement public DNS (Domain Name System) redirection for businesses, enterprises, and governments by Sept 30.

In the FAQ titled ‘Maxis Business DNS Redirection’, the telco stated that this will affect entities using public DNS services, such as Google's DNS (8.8.8.8 or 8.8.4.4) and Cloudflare's DNS (1.1.1.1 or 1.0.0.1).

DNS is a system that turns easy-to-remember website names (like www.thestar.com.my) into the numeric IP addresses that computers use to locate websites on the Internet.

A public DNS can be used to bypass government blocks on certain websites. However, with DNS redirection, requests to access these websites are rerouted to the DNS servers of a local service provider, effectively blocking access to the intended sites.

Maxis said that DNS redirection is being adopted to block harmful websites and uphold Malaysian laws. It added that this measure is particularly important for businesses and government entities, as it helps protect their reputation and avoid accidental legal breaches.

“Under the current direction, this method helps to block access to websites involved in online gambling, pornography, copyright violations, scams, and other illegal activities,” it said.

In cases where websites are blocked by the MCMC, the telco states that users will be redirected to the mcmc-redirect.maxis.com.my webpage instead.

The company also posted that “MCMC will closely monitor and enforce the implementation of DNS redirection to ensure that all Internet service providers comply with the regulations and directions by MCMC”.

“As an Internet service provider, we are required to report our progress and address any issues that arise,” it added.

However, it said this will not impact entities using “private DNS or encrypted traffic, including encrypted DNS and other data traffic”.

Businesses using self-hosted private DNS servers or with DNS over HTTPS (DoH) enabled in the browser settings will also not be affected by the DNS redirect.

Private DNS servers refer to a business- or company-managed DNS service, allowing its administrators to control and configure settings directly, while DoH encrypts DNS queries sent by devices, enhancing privacy and security.

In a statement on Aug 8, MCMC said it will take measures to ensure restrictions to harmful or prohibited websites remain in place by collaborating with service providers on a number of preventive measures, including “in the management of domain name systems (DNS)”.

The regulatory body said from Jan 1, 2022, to Aug 1, 2024, a total of 10,423 websites were blocked due to violations of the law.

From the total number of blocked websites, 95.7% are in the following five categories: online gambling (4,484), online pornography (3,271), online copyright infringement (1,654), scams in the form of online investment (316), and online sex prostitution (249).

Source: https://www.thestar.com.my/tech/tech-news/2...ng-to-maxis-faq
soonwai
post Sep 5 2024, 03:17 PM


********
All Stars
11,459 posts

Joined: Oct 2007
From: KL


QUOTE(JohnL77 @ Sep 5 2024, 02:08 PM)
How to use WARP on desktop? Is it browser only?
*
It's system wide. Since 1.1.1.1 not working, can download from https://developers.cloudflare.com/cloudflar.../download-warp/

QUOTE(xyz_cityhunter @ Sep 5 2024, 02:35 PM)
The key generated by bot only works until Nov 1 and it will fallback to regular Warp later?

Saw others comment about WireGuard but seems like it also need the Warp/Warp+ key to work so this is just alternative to use Warp/Warp+ without installing the Cloudflare software? rclxub.gif
*
Not sure about the bot key, just install to try.
soonwai
post Sep 5 2024, 03:20 PM


********
All Stars
11,459 posts

Joined: Oct 2007
From: KL


ControlD got offer. No experience with this software so unsure if it's a good discount but the timing is right.
https://www.bitsdujour.com/software/control-d
mhyug
post Sep 5 2024, 03:21 PM

Regular
******
Senior Member
1,553 posts

Joined: May 2009
QUOTE(Grape Seed X @ Sep 5 2024, 09:22 AM)
blocked my movies also nvm.

https://web.netmovies.to/the-lord-of-the-rings-the-rings-of-power/ ://https://web.netmovies.to/the-lord-o...ings-of-power/ ://https://web.netmovies.to/the-lord-o...ings-of-power/

but now, even Binance also cannot access!  blink.gif  blink.gif  bangwall.gif  bangwall.gif

Diu liama ka hai TM® vmad.gif

Breaking people's rice bowl is akin to killing their parents.

Implementing a blanket ban like this is so god damn stupid!

seriously Fuck u 9 9 TM/Unifi o0o

*
salah org la bro. should be MCMC and the gov. TM ikut saja.
h@ksam
post Sep 5 2024, 03:26 PM

@ is a
*******
Senior Member
3,460 posts

Joined: Nov 2009
From: KL
QUOTE(Grape Seed X @ Sep 5 2024, 09:22 AM)
blocked my movies also nvm.

https://web.netmovies.to/the-lord-of-the-rings-the-rings-of-power/ ://https://web.netmovies.to/the-lord-o...ings-of-power/ ://https://web.netmovies.to/the-lord-o...ings-of-power/

but now, even Binance also cannot access!  blink.gif  blink.gif  bangwall.gif  bangwall.gif

Diu liama ka hai TM® vmad.gif

Breaking people's rice bowl is akin to killing their parents.

Implementing a blanket ban like this is so god damn stupid!

seriously Fuck u 9 9 TM/Unifi o0o

*
nice website, seems to work and can watch during work brows.gif
SUSlurkingaround
post Sep 5 2024, 03:29 PM

Rule of Law
*******
Senior Member
7,066 posts

Joined: Sep 2019
From: South Klang Valley suburb




QUOTE(haya @ Sep 5 2024, 02:55 PM)
MCMC orders DNS redirection for businesses, govts, enterprises by Sept 30, according to Maxis FAQ
By Angelin Yeoh and Christopher Fam
    Internet
    Thursday, 05 Sep 2024
    2:20 PM MYT

PETALING JAYA: According to an FAQ posted by Maxis, the Malaysian Communications and Multimedia Commission (MCMC) is requiring all Internet service providers to implement public DNS (Domain Name System) redirection for businesses, enterprises, and governments by Sept 30.

In the FAQ titled ‘Maxis Business DNS Redirection’, the telco stated that this will affect entities using public DNS services, such as Google's DNS (8.8.8.8 or 8.8.4.4) and Cloudflare's DNS (1.1.1.1 or 1.0.0.1).

DNS is a system that turns easy-to-remember website names (like www.thestar.com.my) into the numeric IP addresses that computers use to locate websites on the Internet.

A public DNS can be used to bypass government blocks on certain websites. However, with DNS redirection, requests to access these websites are rerouted to the DNS servers of a local service provider, effectively blocking access to the intended sites.

Maxis said that DNS redirection is being adopted to block harmful websites and uphold Malaysian laws. It added that this measure is particularly important for businesses and government entities, as it helps protect their reputation and avoid accidental legal breaches.

“Under the current direction, this method helps to block access to websites involved in online gambling, pornography, copyright violations, scams, and other illegal activities,” it said.

In cases where websites are blocked by the MCMC, the telco states that users will be redirected to the mcmc-redirect.maxis.com.my webpage instead.

The company also posted that “MCMC will closely monitor and enforce the implementation of DNS redirection to ensure that all Internet service providers comply with the regulations and directions by MCMC”.

“As an Internet service provider, we are required to report our progress and address any issues that arise,” it added.

However, it said this will not impact entities using “private DNS or encrypted traffic, including encrypted DNS and other data traffic”.

Businesses using self-hosted private DNS servers or with DNS over HTTPS (DoH) enabled in the browser settings will also not be affected by the DNS redirect.

Private DNS servers refer to a business- or company-managed DNS service, allowing its administrators to control and configure settings directly, while DoH encrypts DNS queries sent by devices, enhancing privacy and security.

In a statement on Aug 8, MCMC said it will take measures to ensure restrictions to harmful or prohibited websites remain in place by collaborating with service providers on a number of preventive measures, including “in the management of domain name systems (DNS)”.

The regulatory body said from Jan 1, 2022, to Aug 1, 2024, a total of 10,423 websites were blocked due to violations of the law.

From the total number of blocked websites, 95.7% are in the following five categories: online gambling (4,484), online pornography (3,271), online copyright infringement (1,654), scams in the form of online investment (316), and online sex prostitution (249).

Source: https://www.thestar.com.my/tech/tech-news/2...ng-to-maxis-faq
*
.
Looks like Fibre Internet ISPs like Maxis, CelcomDigi, TIME, etc will also do like what TM Unifi Fibre is doing as per this thread, ie additional IP blocking of the common Public DNS servers like Google8888, Cloudflare1111 and Quad9999, in order to block the DoH and DoT bypass methods.

Will Mobile 4G/5G ISPs also do the same like TM Unifi Fibre.? Has TM Unifi Mobile implemented such additional IP blocking.?

Will it be a cat-and-mouse game between MCMC and ISP-subscribers.?
.
xyz_cityhunter
post Sep 5 2024, 03:31 PM

Getting Started
**
Junior Member
238 posts

Joined: Dec 2010
From: Kedah


QUOTE(soonwai @ Sep 5 2024, 03:17 PM)
It's system wide. Since 1.1.1.1 not working, can download from https://developers.cloudflare.com/cloudflar.../download-warp/
Not sure about the bot key, just install to try.
*
Yeah, just did both the WARP software and also the WireGuard. Manage to get either working. thumbup.gif

user posted image

user posted image

Confirmed can access to Torrent site like Nyaa with either but the funny stuff was it's blocked on the image uploader of Lowyat forum. doh.gif
Need to turn off to access:

user posted image
user posted image

Not sure if something wrong with my config hmm.gif
JohnL77
post Sep 5 2024, 03:35 PM

Regular
******
Senior Member
1,887 posts

Joined: Mar 2013


QUOTE(lurkingaround @ Sep 5 2024, 03:29 PM)
.
Looks like Fibre Internet ISPs like Maxis, CelcomDigi, TIME, etc will also do like what TM Unifi Fibre is doing as per this thread, ie additional IP blocking of the common Public DNS servers like Google8888, Cloudflare1111 and Quad9999, in order to block the DoH and DoT bypass methods.

Will Mobile 4G/5G ISPs also do the same like TM Unifi Fibre.? Has TM Unifi Mobile implemented such additional IP blocking.?

Will it be a cat-and-mouse game between MCMC and ISP-subscribers.?
.
*
Maxis mobile internet kena liao.
SUSM4A1
post Sep 5 2024, 03:35 PM

[*#^♥SONE♥^#]
******
Senior Member
1,365 posts

Joined: Aug 2005



parking here for the lulzzzzzzzzzz
SUSraynman
post Sep 5 2024, 03:36 PM

Look at all my stars!!
*******
Senior Member
4,333 posts

Joined: Jan 2003


QUOTE(JohnL77 @ Sep 5 2024, 03:35 PM)
Maxis mobile internet kena liao.
*
Hotlink too?
SUSlurkingaround
post Sep 5 2024, 03:39 PM

Rule of Law
*******
Senior Member
7,066 posts

Joined: Sep 2019
From: South Klang Valley suburb




QUOTE((lurkingaround @ Sep 5 2024, 03:29 PM)
.
Looks like Fibre Internet ISPs like Maxis, CelcomDigi, TIME, etc will also do like what TM Unifi Fibre is doing as per this thread, ie additional IP blocking of the common Public DNS servers like Google8888, Cloudflare1111 and Quad9999, in order to block the DoH and DoT bypass methods.

Will Mobile 4G/5G ISPs also do the same like TM Unifi Fibre.? Has TM Unifi Mobile implemented such additional IP blocking.?

Will it be a cat-and-mouse game between MCMC and ISP-subscribers.?
.
*
QUOTE(JohnL77 @ Sep 5 2024, 03:35 PM)
Maxis mobile internet kena liao.
*
.
Kena like TM Unifi Fibre.? ie additional IP blocking of the common Public DNS servers.?
.

supsupsui
post Sep 5 2024, 03:43 PM

Getting Started
**
Junior Member
77 posts

Joined: Jun 2019


QUOTE(Grape Seed X @ Sep 5 2024, 09:22 AM)
blocked my movies also nvm.

https://web.netmovies.to/the-lord-of-the-rings-the-rings-of-power/ ://https://web.netmovies.to/the-lord-o...ings-of-power/ ://https://web.netmovies.to/the-lord-o...ings-of-power/

but now, even Binance also cannot access!  blink.gif  blink.gif  bangwall.gif  bangwall.gif

Diu liama ka hai TM® vmad.gif

Breaking people's rice bowl is akin to killing their parents.

Implementing a blanket ban like this is so god damn stupid!

seriously Fuck u 9 9 TM/Unifi o0o

*
wonderful website. terima kasih
mhyug
post Sep 5 2024, 03:43 PM

Regular
******
Senior Member
1,553 posts

Joined: May 2009
Probably needs some sort of socmed/online old scholl media huha to get this to be u-turned by the jackasses.

Hopefully whatever they done have lead to some unintended disruptions that may lead them(the ISP providers) to get the flack from the subscribers/businesses la kot.

tho im not having any of hope has or will happen at all.

This post has been edited by mhyug: Sep 5 2024, 03:43 PM
JohnL77
post Sep 5 2024, 03:46 PM

Regular
******
Senior Member
1,887 posts

Joined: Mar 2013


QUOTE(lurkingaround @ Sep 5 2024, 03:39 PM)
.
Kena like TM Unifi Fibre.? ie additional IP blocking of the common Public DNS servers.?
.
*
QUOTE(raynman @ Sep 5 2024, 03:36 PM)
Hotlink too?
*
Yes. Cannot open iherb, cannot open planet tsuji.
mhyug
post Sep 5 2024, 03:47 PM

Regular
******
Senior Member
1,553 posts

Joined: May 2009
Anyone so far tested gaming on the current blocks etc? Console and PC mainly, read a post few pages back but not detailed enough, what game? platform? etc
TAN WENG
post Sep 5 2024, 03:49 PM

Getting Started
**
Junior Member
145 posts

Joined: Jun 2015


QUOTE(mhyug @ Sep 5 2024, 03:47 PM)
Anyone so far tested gaming on the current blocks etc? Console and PC mainly, read a post few pages back but not detailed enough, what game? platform? etc
*
Genshin impact keep disconnecting 😡
Cannot view gdex tracking
khelben
post Sep 5 2024, 03:56 PM

I love my mum & dad
*******
Senior Member
6,056 posts

Joined: Jan 2003
From: Suldanessellar



QUOTE(mhyug @ Sep 5 2024, 03:47 PM)
Anyone so far tested gaming on the current blocks etc? Console and PC mainly, read a post few pages back but not detailed enough, what game? platform? etc
*
I don't mind them blocking porn but if they screw up my online gaming, I'm gonna flip.
mcchin
post Sep 5 2024, 03:56 PM

SLAVA UKRAINI !
*******
Senior Member
3,902 posts

Joined: Jul 2005
From: Sin Lor, B'worth,Pg.
QUOTE(xyz_cityhunter @ Sep 5 2024, 03:31 PM)

Confirmed can access to Torrent site like Nyaa with either but the funny stuff was it's blocked on the image uploader of Lowyat forum.  doh.gif
Need to turn off to access:

user posted image
user posted image

Not sure if something wrong with my config  hmm.gif
*
yes but only for those guest upload

as per se7en said

QUOTE(se7en @ Mar 6 2019, 05:03 PM)
not too sure what you are asking, but the only thing changed is that we have disabled registration, and guest uploads are limited to MY/SG/AU IP's only.
*
not sure if it has change

SUSlurkingaround
post Sep 5 2024, 03:59 PM

Rule of Law
*******
Senior Member
7,066 posts

Joined: Sep 2019
From: South Klang Valley suburb




QUOTE((lurkingaround @ Sep 5 2024, 03:39 PM)
.
Maxis Mobile kena like TM Unifi Fibre.? ie additional IP blocking of the common Public DNS servers.?
.
*
QUOTE(JohnL77 @ Sep 5 2024, 03:46 PM)
Yes. Cannot open iherb, cannot open planet tsuji.
*
.
I'm on U Mobile - still can access iHerb with Secure DoH.
.

This post has been edited by lurkingaround: Sep 5 2024, 03:59 PM
dawnreaver
post Sep 5 2024, 04:06 PM

On my way
****
Junior Member
661 posts

Joined: Jan 2005
From: Legio Titanicus


Why iHerb kena block? rclxub.gif
mcchin
post Sep 5 2024, 04:12 PM

SLAVA UKRAINI !
*******
Senior Member
3,902 posts

Joined: Jul 2005
From: Sin Lor, B'worth,Pg.
Hotlink Penang
I herb still can

user posted image

Dunno it's this one or a secret name for another website

One.one.one.one also working as of 5 September 2024
issac99289928
post Sep 5 2024, 04:43 PM

Getting Started
**
Junior Member
291 posts

Joined: Sep 2016
From: muar, johor


say goodbye to network congestion by end September. TM thumbs up.
SUSlurkingaround
post Sep 5 2024, 04:45 PM

Rule of Law
*******
Senior Member
7,066 posts

Joined: Sep 2019
From: South Klang Valley suburb




QUOTE(dawnreaver @ Sep 5 2024, 04:06 PM)
Why iHerb kena block?  rclxub.gif
*
.
Likely bc Malaysian buyers got their health supplement sent from USA via iHerb, ie it is illegal for Malaysians to import health supplements, medicinal drugs, etc without a license.

So, they should buy online from local retailers like Guardian, Watson, GNC, etc.
.

This post has been edited by lurkingaround: Sep 5 2024, 05:09 PM
lkyoong
post Sep 5 2024, 04:47 PM

Getting Started
**
Junior Member
188 posts

Joined: Jan 2011
Looks like need to sub paid Smart DNS services in the future.

Any recommendations?
SUSlurkingaround
post Sep 5 2024, 05:07 PM

Rule of Law
*******
Senior Member
7,066 posts

Joined: Sep 2019
From: South Klang Valley suburb




QUOTE(raynman @ Sep 4 2024, 05:57 PM)
There is a limited number of VPN servers to choose from
*
.
Seems the free ProtonVPN will disallow selection of server (= default to the nearest server) and will impose data limit (eg 200MB per day) after a period of use, eg after 6 months.
.
SUSraynman
post Sep 5 2024, 05:13 PM

Look at all my stars!!
*******
Senior Member
4,333 posts

Joined: Jan 2003


QUOTE(lurkingaround @ Sep 5 2024, 05:07 PM)
.
Seems the free ProtonVPN will disallow selection of server (= default to the nearest server) and will impose data limit (eg 200MB per day) after a period of use, eg after 6 months.
.
*
user posted image

I have changed it to browser-based extension VeePN

3 Pages  1 2 3 >Top
 

Change to:
| Lo-Fi Version
0.1304sec    1.08    6 queries    GZIP Disabled
Time is now: 18th December 2025 - 06:45 AM