Skip to Content.
Sympa Menu

discuss - Re: [opennic-discuss] [URGENT] [ROUND-ROBIN] DNS POISONING/POSSIBLE MITM ATTACK

discuss AT lists.opennicproject.org

Subject: Discuss mailing list

List archive

Re: [opennic-discuss] [URGENT] [ROUND-ROBIN] DNS POISONING/POSSIBLE MITM ATTACK


Chronological Thread  
  • From: Se7en <se7en AT cock.email>
  • To: discuss AT lists.opennicproject.org
  • Subject: Re: [opennic-discuss] [URGENT] [ROUND-ROBIN] DNS POISONING/POSSIBLE MITM ATTACK
  • Date: Wed, 1 Sep 2021 17:18:50 -0700

On 21-09-02 02:12:47, Lennart Seitz wrote:
> On 02.09.2021 02:02, Se7en wrote:
> > On 21-09-02 01:58:21, Lennart Seitz wrote:
> >> The Server were operated by Fusl / Katie, but it seems like the servers
> >> are withdrawn (only explanation i have for not beeing in the serverlist)
> >> and the Wiki should be updated.
> > Yes, it should! You are advertising fraudulent DNS servers with a MITM
> > attack, which have been abandoned an unknown amount of time ago!
>
> This is yet to be proven. You are sending to the anycast, any party
> within your traceroute can manipulate DNS-Requets. This is not related
> to OpenNIC.

You have just said that the DNS servers I'm using, which are listed on
the wiki, are /not/ Anycast servers belonging to the
OpenNICProject. You are contradicting yourself. I hope you realize
that this is potentially a major scandal, and you should put out a
press release and a security alert as this is a /major/ problem!

If you believe that I /am/ using the correct Anycast servers, what do
you suggest I do to detect if it is external to the DNS problem? I
have already performed analysis and shown that the only reason I was
getting the MITM to facebook, and the fradulent chinese domain
register was by using the Anycast DNS servers listed on the
wiki. These are the same servers I have used since 2015/2016 on a
multitude of devices.

Is it or is it not the Anycast server? If it is the result of
something else, what else could it be when all other DNS Providers I
put into my configuration do not have this issue?

> For me Katies Anycast DNS (if active or not) is resolving every domain
> you send correctly. So the EU Servers are working fine.

Which one? 185.121.177.177 or 169.239.202.202? I am in the United
States.

> I agree that the wiki should be updated.

--
|-----/ | Se7en
/ The One and Only! | se7en AT cock.email
/ | 0x0F83F93882CF6116
/ | https://se7en-site.neocities.org

Attachment: signature.asc
Description: PGP signature




Archive powered by MHonArc 2.6.24.

Top of Page