Welcome Guest ( Log In | Register )

Outline · [ Standard ] · Linear+

 It seems TM Unifi has finally implemented, transparent DNS proxy

views
     
SUSheadache
post Sep 5 2024, 09:37 PM

Getting Started
**
Junior Member
282 posts

Joined: Mar 2005

user posted image
SUSheadache
post Sep 6 2024, 01:53 AM

Getting Started
**
Junior Member
282 posts

Joined: Mar 2005


SUSheadache
post Sep 6 2024, 01:48 PM

Getting Started
**
Junior Member
282 posts

Joined: Mar 2005

It's Gobind la mangkok!

lol.gif

QUOTE(dawho @ Sep 6 2024, 11:09 AM)
dont think madani so critical bout this...but this fahmi fucker very chibai one..
*
SUSheadache
post Sep 6 2024, 02:31 PM

Getting Started
**
Junior Member
282 posts

Joined: Mar 2005

The block has been there for the longest time lah. Way before Fahmi.

Only people are were using these public DNSs to circumvent them. Now they are blocking these loopholes.

So why cry mader fader? Still many ways to circumvent it. They are only blocking access to these (unauthorised) public DNSs.

lol.gif

QUOTE(isr25 @ Sep 6 2024, 01:58 PM)
MCMC is under Fahmi’s purview, hence the backwards thinking of all decisions lately
*
This post has been edited by headache: Sep 6 2024, 02:33 PM
SUSheadache
post Sep 6 2024, 02:43 PM

Getting Started
**
Junior Member
282 posts

Joined: Mar 2005

Technically, the sites are not blocked per se. U won't be able to access them unless using something like SOCKS5 or VPN (like WARP).

They just remove ur ability to reach them via DNS.

QUOTE(Sichiri @ Sep 6 2024, 02:36 PM)
My own solution for now:
-removed all dns on router, browser and OS.
-install cloudflare Warp, and only turn on if want to check blocked sites.
*
SUSheadache
post Sep 6 2024, 02:44 PM

Getting Started
**
Junior Member
282 posts

Joined: Mar 2005

Knowledgeable few won't cry mader fader la.

lol.gif
QUOTE(mcchin @ Sep 6 2024, 02:43 PM)
standard user wouldnt know how to circumvent
no closing loopholes mean going on the offense to the knowledgeable few

if that is not dictatorship characteristic then I dunno what is
*
SUSheadache
post Sep 6 2024, 02:55 PM

Getting Started
**
Junior Member
282 posts

Joined: Mar 2005

Erm, because they see this coming?

Blocking these Public DNSs that circumvent ISPs' DNSs is natural progression. It's very simple to implement.

Freedom? Don't make me laugh. If u r not knowledgeable, u don't deserve it.

QUOTE(mcchin @ Sep 6 2024, 02:49 PM)
why is that?
the knowledgeablecan see far into the future if no kbkp now
it will mean the end of true freedom
*
SUSheadache
post Sep 6 2024, 03:00 PM

Getting Started
**
Junior Member
282 posts

Joined: Mar 2005

They are not blocking the whole Cloudflare just their famous and Public DNS server, same with Google. There are other DNS servers on Cloudflare that are not so Public.

smile.gif

QUOTE(soonwai @ Sep 6 2024, 02:55 PM)
Poor Cloudflare. First the DNS got stolen then the website blocked. Next probably Warp. Just lie there and kena butsek by TM.
*
SUSheadache
post Sep 6 2024, 03:05 PM

Getting Started
**
Junior Member
282 posts

Joined: Mar 2005

Apa u merepek Bob?

U can't reach 1.1.1.1, 8.8.8.8 or others (blocked) if u r using Unifi even if using other unblocked DNS servers. U need tunneling to reach them from MY. iherb and others still can without tunnels.

Well, they are not authorised now.

lol.gif

QUOTE(axoloke @ Sep 6 2024, 02:58 PM)
That is not entirely correct. It's not about being reachable, users cannot resolve the name to IP of the actual site which is what DNS is for.

The public DNS servers are neither authorised or not authorised, it's a service for the public Internet. Companies and individuals utilise it for faster name resolution, uptime, etc. Our ISP DNS servers were notoriously slow in the past as well.
*
SUSheadache
post Sep 6 2024, 03:30 PM

Getting Started
**
Junior Member
282 posts

Joined: Mar 2005

Yes that is what I'm saying, sites are not blocked per se. Only access to these public DNS servers are blocked. Don't go off tangent and fall for the (un)authorised nonsense. Tak faham bahasa is it?

You can't reach these "blocked" sites because the PUBLIC DNS servers redirecting your traffic is now blocked (inaccessible).

I'm on unifi and digi fibre (which is even worse) and still can access these "blocked" sites but honestly don't care much, except may be iHerb.

So why cry mader fader?

QUOTE(axoloke @ Sep 6 2024, 03:14 PM)
And what nonsense are you saying as well mate? No need to act like that, we are talking about sites and now you pivot to the actual DNS servers itself.  cool2.gif

You are conflating site access with DNS server access,  of course you can reach the sites if you can resolve the name from another DNS server or if you can query the DNS servers bypassing the transparent proxy. That's the DNS proxy in effect.

Another issue is blocking the IP itself (like 8.8.8.8). That's on the route or site which has nothing to do with the DNS resolution.

For most people, the main problem is they are redirecting the DNS queries. The site is alive but they can't get the IP to go to it.
*
SUSheadache
post Sep 6 2024, 03:54 PM

Getting Started
**
Junior Member
282 posts

Joined: Mar 2005

So who authorised those Public servers, ur mother or ur boyfriend? Too many idiots trying to show off their cleverness.

Oh well.

lol.gif

QUOTE(axoloke @ Sep 6 2024, 03:44 PM)
Huh? You're the one who brought up the authorised servers phrase in the first place.  Didn't check your own posts is it? blink.gif

I think you got the wrong user, where in my post did I "cry father mother, add on grandfather" ?

Ok lah, since you want to argue for the sake of arguing on the Net, I'll let it stop here. Was just lurking anyway and the other folks posts are much more constructive... whistling.gif
*
SUSheadache
post Sep 6 2024, 03:56 PM

Getting Started
**
Junior Member
282 posts

Joined: Mar 2005

Aiyoh, so many other DNS servers.

QUOTE(rooney723 @ Sep 6 2024, 03:53 PM)
i have tried all ways and this is my conclusion

1) DNS over TLS - not working
2) DNS over HTTPS - not working

the only one that is working now for me is the 1.1.1.1 app on android (only filter DNS queries setting) and the cloudflare WARP application on windows (1.1.1.1 setting)

and without using VPN
*
SUSheadache
post Sep 6 2024, 04:00 PM

Getting Started
**
Junior Member
282 posts

Joined: Mar 2005

Ok mangkok...and what does this prove?

Might as well says PMX is responsible and inadvertently, PH, BN, GPS, etc. supporters.

lol.gif

QUOTE(dawho @ Sep 6 2024, 03:39 PM)
mangkok whistling.gif

user posted image
*
SUSheadache
post Sep 6 2024, 04:03 PM

Getting Started
**
Junior Member
282 posts

Joined: Mar 2005

I don't know. U tell me or u another tak faham bahasa?

lol.gif

QUOTE(isr25 @ Sep 6 2024, 03:56 PM)
Since when DNS servers or servers need to be authorised? laugh.gif
*
SUSheadache
post Sep 6 2024, 04:06 PM

Getting Started
**
Junior Member
282 posts

Joined: Mar 2005

May be they're hijacking at ur end if u r not using DOH or DOT.

They are blocking at my end. They're not rerouting queries at all. I don't use 'em DNS servers anyway.

QUOTE(silverhawk @ Sep 6 2024, 04:01 PM)
They are not blocking, they are hijacking your DNS queries. Very different approach.

If you don't see why this is dangerous, then you are simply lacking in knowledge.
*
SUSheadache
post Sep 6 2024, 06:42 PM

Getting Started
**
Junior Member
282 posts

Joined: Mar 2005

Yes, finally!

Don't go sharing those, okay?

lol.gif

QUOTE(yushin @ Sep 6 2024, 03:56 PM)
Seem like TM has hijacked the whole 1.1.1.1 IP.
Can use other DNS that support DOH. No need die die go on 1.1.1.1?
*
SUSheadache
post Sep 6 2024, 06:53 PM

Getting Started
**
Junior Member
282 posts

Joined: Mar 2005

Really? Kesian.

I don't even use Public DNS.

lol.gif
QUOTE(soonwai @ Sep 6 2024, 06:51 PM)
Finally? you really serowpoke.
*
SUSheadache
post Sep 6 2024, 08:17 PM

Getting Started
**
Junior Member
282 posts

Joined: Mar 2005

Ok mangkok.

lol.gif

QUOTE(dawho @ Sep 6 2024, 08:02 PM)
already salah then play "what does this prove" card...lol...next time go research first before mangkok other people...bodo punya mangkuk...minister incharge of this shit also dont know, wanna act cool la
*

 

Change to:
| Lo-Fi Version
0.0532sec    0.75    7 queries    GZIP Disabled
Time is now: 20th December 2025 - 08:07 PM