LinuxQuestions.org

LinuxQuestions.org (/questions/)
-   Linux - Security (https://www.linuxquestions.org/questions/linux-security-4/)
-   -   Is this definite evidence of DNS interception? (https://www.linuxquestions.org/questions/linux-security-4/is-this-definite-evidence-of-dns-interception-4175551673/)

Ulysses_ 08-25-2015 06:01 AM

Is this definite evidence of DNS interception?
 
Have been using 4.2.2.4 as the DNS server for a long time.

Suddenly a site that worked before does not work, it says "Server not found". Thought the site's server was down but then another site did not work either, saying "Server not found". But google still worked.

Changed the DNS server to 208.67.222.222 and both sites worked.

Then changed it back to 4.2.2.4 and neither of the two sites worked.

If not a wild coincidence, what is going on here?

Tried setting the browser to go through a local HTTP/HTTPS proxy (ultrasurf running under wine). Both DNS servers worked then. Does DNS go through the proxy when you set an HTTP proxy?

PS. Now, minutes later, 4.2.2.4 works. Do I put on my second aluminum hat?

rtmistler 08-25-2015 06:19 AM

Those here who have arbitrarily changed their network settings and then found that the network alternatively works and then doesn't; please raise your hands. (Hand raised)

Sitting here wondering how you even knew about the 208 address at all.

If this is your ISP network, well they can option it however they wish and they can choose to use secondary or tertiary servers as they wish.

If you're seriously concerned, I'd raise the question with them.

It's not proof of anything in my opinion.

Ulysses_ 08-25-2015 09:00 AM

Neither is my ISP's DNS server, they are both public, chosen with a tool that benchmarks lots of public DNS servers and tells you the fastest for your location.


All times are GMT -5. The time now is 04:02 PM.