LinuxQuestions.org
Visit Jeremy's Blog.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 08-25-2015, 06:01 AM   #1
Ulysses_
Senior Member
 
Registered: Jul 2009
Posts: 1,303

Rep: Reputation: 57
Is this definite evidence of DNS interception?


Have been using 4.2.2.4 as the DNS server for a long time.

Suddenly a site that worked before does not work, it says "Server not found". Thought the site's server was down but then another site did not work either, saying "Server not found". But google still worked.

Changed the DNS server to 208.67.222.222 and both sites worked.

Then changed it back to 4.2.2.4 and neither of the two sites worked.

If not a wild coincidence, what is going on here?

Tried setting the browser to go through a local HTTP/HTTPS proxy (ultrasurf running under wine). Both DNS servers worked then. Does DNS go through the proxy when you set an HTTP proxy?

PS. Now, minutes later, 4.2.2.4 works. Do I put on my second aluminum hat?

Last edited by Ulysses_; 08-25-2015 at 06:08 AM.
 
Old 08-25-2015, 06:19 AM   #2
rtmistler
Moderator
 
Registered: Mar 2011
Location: USA
Distribution: MINT Debian, Angstrom, SUSE, Ubuntu, Debian
Posts: 9,883
Blog Entries: 13

Rep: Reputation: 4930Reputation: 4930Reputation: 4930Reputation: 4930Reputation: 4930Reputation: 4930Reputation: 4930Reputation: 4930Reputation: 4930Reputation: 4930Reputation: 4930
Those here who have arbitrarily changed their network settings and then found that the network alternatively works and then doesn't; please raise your hands. (Hand raised)

Sitting here wondering how you even knew about the 208 address at all.

If this is your ISP network, well they can option it however they wish and they can choose to use secondary or tertiary servers as they wish.

If you're seriously concerned, I'd raise the question with them.

It's not proof of anything in my opinion.
 
Old 08-25-2015, 09:00 AM   #3
Ulysses_
Senior Member
 
Registered: Jul 2009
Posts: 1,303

Original Poster
Rep: Reputation: 57
Neither is my ISP's DNS server, they are both public, chosen with a tool that benchmarks lots of public DNS servers and tells you the fastest for your location.
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
Exim DKIM DNS exploit Any evidence in logs? or else where zhjim Linux - Security 2 11-06-2012 01:19 AM
Definite good news from the The Man himself... dhave Slackware 2 12-19-2004 08:23 AM
All bells should be sent on the definite unit ukrainet Linux - Newbie 0 11-26-2004 06:45 AM
The Definite Power Management Question navarre9 Linux - Newbie 4 12-26-2003 04:30 PM
Definite Beginner Questions yisi Linux - Newbie 7 03-24-2002 10:45 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 06:01 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration