Welcome Guest ( Log In | Register )

Outline · [ Standard ] · Linear+

 It seems TM Unifi has finally implemented, transparent DNS proxy

views
     
Yuuyatails
post Sep 6 2024, 06:10 PM

New Member
*
Junior Member
42 posts

Joined: May 2012
From: Ipoh, Perak


I can confirm that TM had started doing DNS hijacking on DoH and DoT queries here in Ipoh, Perak, resulting in timed out.
Yuuyatails
post Sep 6 2024, 06:29 PM

New Member
*
Junior Member
42 posts

Joined: May 2012
From: Ipoh, Perak


QUOTE(hsyong @ Sep 6 2024, 06:26 PM)
Kinda confused. Some saying DOH blocked, some saying DOH not blocked.

It depends on luck? It's blocked for some and not for others? Or TM hasn't finished implementing yet?

For me (using 8888 on TM Unifi), I can access the "useful" sites when Secure DNS in browser is ON (tried Chrome, Edge, Opera). Otherwise, not accessible. Just as simple as that.
*
I believe it is implemented in stages. Some areas might not affected until much later.
Yuuyatails
post Sep 6 2024, 06:41 PM

New Member
*
Junior Member
42 posts

Joined: May 2012
From: Ipoh, Perak


QUOTE(soonwai @ Sep 6 2024, 06:39 PM)
DoH not blocked. But their DNS server is getting overloaded already.
CODE

% dig @8.8.8.8 +https onlyfans.com
;; Connection to 8.8.8.8#443(8.8.8.8) for onlyfans.com failed: connection refused.
;; no servers could be reached
;; Connection to 8.8.8.8#443(8.8.8.8) for onlyfans.com failed: connection refused.
;; no servers could be reached
;; Connection to 8.8.8.8#443(8.8.8.8) for onlyfans.com failed: connection refused.
;; no servers could be reached
% dig @8.8.8.8 +https onlyfans.com
;; Connection to 8.8.8.8#443(8.8.8.8) for onlyfans.com failed: connection refused.
;; no servers could be reached
;; Connection to 8.8.8.8#443(8.8.8.8) for onlyfans.com failed: connection refused.
;; no servers could be reached
;; Connection to 8.8.8.8#443(8.8.8.8) for onlyfans.com failed: connection refused.
;; no servers could be reached
% dig @8.8.8.8 +https onlyfans.com
;; Connection to 8.8.8.8#443(8.8.8.8) for onlyfans.com failed: connection refused.
;; no servers could be reached
;; Connection to 8.8.8.8#443(8.8.8.8) for onlyfans.com failed: connection refused.
;; no servers could be reached

; <<>> DiG 9.20.1 <<>> @8.8.8.8 +https onlyfans.com
; (1 server found)
;; global options: +cmd
;; Got answer:
;; ->>HEADER<<- opcode: QUERY, status: NOERROR, id: 33943
;; flags: qr rd ra; QUERY: 1, ANSWER: 1, AUTHORITY: 0, ADDITIONAL: 1

;; OPT PSEUDOSECTION:
; EDNS: version: 0, flags:; udp: 512
;; QUESTION SECTION:
;onlyfans.com.   IN A

;; ANSWER SECTION:
onlyfans.com.  0 IN A 175.139.142.25

;; Query time: 9 msec
;; SERVER: 8.8.8.8#443(8.8.8.8) (HTTPS) <----- DoH
;; WHEN: Fri Sep 06 18:37:46 +08 2024
;; MSG SIZE  rcvd: 57

*
That sounds like a DDoS attack to the DNS server to me.

 

Change to:
| Lo-Fi Version
0.0387sec    0.71    7 queries    GZIP Disabled
Time is now: 22nd December 2025 - 11:26 PM