discuss AT lists.opennicproject.org
Subject: Discuss mailing list
List archive
Re: [opennic-discuss] [URGENT] [ROUND-ROBIN] DNS POISONING/POSSIBLE MITM ATTACK
Chronological Thread
- From: Lennart Seitz <mail AT lseitz.de>
- To: discuss AT lists.opennicproject.org
- Subject: Re: [opennic-discuss] [URGENT] [ROUND-ROBIN] DNS POISONING/POSSIBLE MITM ATTACK
- Date: Thu, 2 Sep 2021 02:53:44 +0200
On 02.09.2021 02:46, Se7en wrote:
> # First run before changing DNS back (on Quad9 with DNSSEC)
> $ dig duckduckgo.com @185.121.177.177 +short
> 157.240.7.34
>
> # Second run after changing DNS back
>
> $ dig duckduckgo.com @185.121.177.177 +short
> 69.171.246.9
>
>
>
> After switchback, duckduckgo is no longer MITM but is completely
> unreachable.
>
> Switch back to Quad9 (temporary) with DNSSEC
>
> $ dig duckduckgo.com @185.121.177.177 +short
> 103.39.76.66
>
>
> These tests were performed as I was drafting this email just now.
>
Something certainly is odd here: the "@" part of dig defines the used
server. So you dont need to "change back" anything. If you put
dig duckduckgo.com @185.121.177.177 +short
in your cli. It will always query at 185.121.177.177, so it should
always give you the same results (lets keep dns-roundrobin out for now,
the 69.171.246.9 is certainly wrong)
It seems like something on your system is locally redirecting querys.
--
Mit freundlichen Grüßen,
Lennart Seitz
PGP-Schlüssel: 0x187abd76a5660379 (https://pgp.lseitz.de/key.asc)
--
-
Re: [opennic-discuss] [URGENT] [ROUND-ROBIN] DNS POISONING/POSSIBLE MITM ATTACK
, (continued)
-
Re: [opennic-discuss] [URGENT] [ROUND-ROBIN] DNS POISONING/POSSIBLE MITM ATTACK,
Se7en, 09/01/2021
-
Re: [opennic-discuss] [URGENT] [ROUND-ROBIN] DNS POISONING/POSSIBLE MITM ATTACK,
Lennart Seitz, 09/02/2021
-
Re: [opennic-discuss] [URGENT] [ROUND-ROBIN] DNS POISONING/POSSIBLE MITM ATTACK,
Se7en, 09/02/2021
- Re: [opennic-discuss] [URGENT] [ROUND-ROBIN] DNS POISONING/POSSIBLE MITM ATTACK, binbash shebang, 09/02/2021
-
Re: [opennic-discuss] [URGENT] [ROUND-ROBIN] DNS POISONING/POSSIBLE MITM ATTACK,
Lennart Seitz, 09/02/2021
- Re: [opennic-discuss] [URGENT] [ROUND-ROBIN] DNS POISONING/POSSIBLE MITM ATTACK, Se7en, 09/02/2021
- Re: [opennic-discuss] [URGENT] [ROUND-ROBIN] DNS POISONING/POSSIBLE MITM ATTACK, Lennart Seitz, 09/02/2021
- Re: [opennic-discuss] [URGENT] [ROUND-ROBIN] DNS POISONING/POSSIBLE MITM ATTACK, Se7en, 09/02/2021
- Re: [opennic-discuss] [URGENT] [ROUND-ROBIN] DNS POISONING/POSSIBLE MITM ATTACK, Lennart Seitz, 09/02/2021
- Re: [opennic-discuss] [URGENT] [ROUND-ROBIN] DNS POISONING/POSSIBLE MITM ATTACK, Se7en, 09/02/2021
- Re: [opennic-discuss] [URGENT] [ROUND-ROBIN] DNS POISONING/POSSIBLE MITM ATTACK, Lennart Seitz, 09/02/2021
- Re: [opennic-discuss] [URGENT] [ROUND-ROBIN] DNS POISONING/POSSIBLE MITM ATTACK, Lennart Seitz, 09/02/2021
- Re: [opennic-discuss] [URGENT] [ROUND-ROBIN] DNS POISONING/POSSIBLE MITM ATTACK, Se7en, 09/02/2021
- Re: [opennic-discuss] [URGENT] [ROUND-ROBIN] DNS POISONING/POSSIBLE MITM ATTACK, Se7en, 09/02/2021
- Re: [opennic-discuss] [URGENT] [ROUND-ROBIN] DNS POISONING/POSSIBLE MITM ATTACK, Lennart Seitz, 09/02/2021
- Re: [opennic-discuss] [URGENT] [ROUND-ROBIN] DNS POISONING/POSSIBLE MITM ATTACK, eric, 09/02/2021
- Re: [opennic-discuss] [URGENT] [ROUND-ROBIN] DNS POISONING/POSSIBLE MITM ATTACK, Se7en, 09/02/2021
- Re: [opennic-discuss] *** SPAM *** Re: [URGENT] [ROUND-ROBIN] DNS POISONING/POSSIBLE MITM ATTACK, Lennart Seitz, 09/02/2021
- Re: [opennic-discuss] [URGENT] [ROUND-ROBIN] DNS POISONING/POSSIBLE MITM ATTACK, Se7en, 09/02/2021
- Re: [opennic-discuss] *** SPAM *** Re: [URGENT] [ROUND-ROBIN] DNS POISONING/POSSIBLE MITM ATTACK, mail, 09/02/2021
- Re: [opennic-discuss] *** SPAM *** Re: [URGENT] [ROUND-ROBIN] DNS POISONING/POSSIBLE MITM ATTACK, Lennart Seitz, 09/02/2021
-
Re: [opennic-discuss] [URGENT] [ROUND-ROBIN] DNS POISONING/POSSIBLE MITM ATTACK,
Se7en, 09/02/2021
-
Re: [opennic-discuss] [URGENT] [ROUND-ROBIN] DNS POISONING/POSSIBLE MITM ATTACK,
Lennart Seitz, 09/02/2021
-
Re: [opennic-discuss] [URGENT] [ROUND-ROBIN] DNS POISONING/POSSIBLE MITM ATTACK,
Se7en, 09/01/2021
Archive powered by MHonArc 2.6.24.