BIG news this week as we welcome Simon Forster (@f0r573r) to the Quad9 family as General Manager!
https://quad9.net/news/press/quad9-appoints-simon-forster-as-new-general-manager
BIG news this week as we welcome Simon Forster (@f0r573r) to the Quad9 family as General Manager!
https://quad9.net/news/press/quad9-appoints-simon-forster-as-new-general-manager
Folks who run their own DNS these days: What is your preferred DNS server? #LazyWeb #OpenSource #DNS
A list of Digital Service Providers outside the jurisdiction of the United States of America.
https://codeberg.org/Linux-Is-Best/Outside_Us_Jurisdiction
This is a group project, so feel free to reach out if you have any suggestions, or learn any new information.
#Vpn #Email #Dns #Domain #Messenger #WebHosting #PasswordManager #WebSearch #UsJurisdiction #Project2025 #UnitedStates
Bad idea: mess with DNS on your own domain.
Good idea: mess with DNS on https://messwithdns.net/
We love this site from @b0rk that lets you mess with DNS and learn by doing (and breaking things).
@daj @hryggrbyr #Gandi broke its promise regarding the free email addresses you could have with a domain for which they were the registrar, and they've insanely increased their prices in the last year or so. Oh, they've been bought by TWS in February 2023; that's probably just a coincidence!
I've switched to #Infomaniak 6-9 months ago first for email then for domains, FWIW. The commercial offers may be a bit hard to read, but the service works well for me (I only wish they'd shut up about “AI”...).
My #Android #Nextcloud client keeps failing to auto-upload to my local LAN instance!
I'm noticing "applovin.com", in my #DNS #filter #logs - is this you, @nextcloud?
Do I need to resolve applovin, In order to upload to my LOCAL LAN instance?
Why does the client keep telling me that I don't have an internet connection?
I DO NOT NEED AN internet CONNECTION, for my local LAN instance!
Dear #fediverse could you please recommend me a EU-based alternative to Cloudflare to use as nameservers?
Thank you in advance.
Discovered another new app that actually is pretty useful. I use #NextDNS but occasionally I need to switch to the default DNS and that is where this handy open source utility comes in to play:
DNS Easy Switcher (for MacOS)
Our GM, John Todd, sat down with Jeremy Snyder for an episode of Modern Cyber talking all things #DNS.
While setting up PiHole last night, I decided to also switch the DNS servers at home to use the CIRA Public servers instead of Google or Cloudflare's DNS.
No need to send that traffic through a US company. Plus, CIRA's servers block malware too.
https://www.cira.ca/en/canadian-shield/configure/home-router/
A list of digital service providers outside the jurisdiction of the United States of America.
https://codeberg.org/Linux-Is-Best/Outside_Us_Jurisdiction
This is a group effort so, if you have any suggestions, please let me know.
#UsJurisdiction #Overseas #WebHost #Vpn #Dns #Cdn #PasswordManager #Email #SearchEngine
A list of digital service providers outside the jurisdiction of the United States of America.
https://codeberg.org/Linux-Is-Best/Outside_Us_Jurisdiction
My list was getting bigger than a Fedi post could hold, so it is now hosted on Codeberg, an alternative to GitHub or GitLab, but based out of Germany.
A question for the #server and #dns experts. If you would be so kind as to have a read and give me some help
This will run over a few posts, so carry on reading.
I have a server, lets say the main domain is zxc.com, I also have lots of client domain. These are set up as their domain, client.com, and as a sub domain of the main domain, so client.zxc.com.
This is done because Cpanel wants a sub-domain specified.
In the DNS for zxc.com I use a wild card for sub domains; A * serverip.
cont.
NLnet Labs celebrates twenty-five years as an independent, non-profit foundation working on #opensource and #openstandards.
Our mission remains to make the core of the Internet a better, safer place by developing open-source software, through applied research and by promoting and contributing to open standards.
Have you been along for the ride as a user of our #DNS or #routing software, worked with us on #IETF standardisation, applied research or policy advocacy? Share your story!
My list of digital service providers outside the jurisdiction of the United States of America.
https://codeberg.org/Linux-Is-Best/Outside_Us_Jurisdiction
The list is now hosted on Codeberg, an alternative to GitHub or GitLab, but based out of Germany.
#Vpn #Dns #Cdn #WebHosting #Email #PasswordManager #WebSearch #Privacy #Security #Project2025 #Fascism #Nazis
The hack that turned the US government website of the Center for Disease Control into a porn site turns out to be more interesting than I originally thought. And that's not just because the CDC has not done anything to fix the problem 24 hours later...
Yesterday we found that a number of universities, enterprises and other government sites have been hacked by the same actor. Visiting the specific URLs takes you into a malicious adtech traffic distribution system (TDS). Depending on your device and location, you might get the pornography. bud, you also might get other scams like scareware. From my sacrificial phone, I was able to trigger a bunch of push notification requests.
Bottom Line: malicious adtech pays, their TDS allow actors to hide, and hackers are quite happy to compromise well known websites to get that money. But it's not just about scams, these types of techniques are frequently used for delivering information stealers, which lead to breaches.
Here's a few notes about the attack:
* The site is modified to add pages which attempt to load a specific image name. If that isn't there, then it redirects to the actor controlled malicious domain which funnels into the TDS
* The actor seems to be using blogspot for this now, but previously used a tiny URL. From here they will go to adtech TDS.
* There were what seemed possible to be dangling CNAME records in many cases, but in some of them didn't appear to be any issues with the DNS records. I suspect combo of accesses.
* In cases where there's no apparent DNS record issue, the legit site seems to be hosting in GitHub. Perhaps they have a credential compromised.
* I saw at least two adtech companies used, Adsterra and Roller Ads. these are checking for VPN and anonymous proxies before serving the final landing page.
* This image redirect actor seems to be riding off of a different actor who originally hacked the site, uses SEO poisoning techniques, and hacked universities to host porn content.
I put a bunch of images in imgur.
Thanks Krebs for the lead.
#dns #cybercrime #cybersecurity #infosec #adtech #malware #scam #threatintel #tds #InfobloxThreatIntel
https://imgur.com/a/cdc-website-hijack-leads-to-malicious-adtech-XfguIcN
**Setting up a Synology router and wifi mesh – was it a mistake?**
Read it on my blog, it has a nicer image/text layout.
TL;DR
The problem:
My ISP’s (Telekom SI) modem/router (#Innobox G92) was having serious problems and ISP didn’t (want/know) how to fix it. It froze at least one time every day. It showed internet is connected, but it refused to transfer the data. Of course they (ISP) didn’t admit there is anything wrong with it. But I had logs in my HomeAssistant that showed exactly when the data transfer stopped.
They even replaced it and the new one started to behave exactly like the old one after only a week of use. They also blamed me – they said I should hire a ‘computer specialist’ to check my network.
I have only about 30 network devices.
So I decided (too late) that I want a router that I can control.
The next issue was some of my wifi gadgets didn’t have good wifi connection (e. g. in the basement). I used an old Linksys WRT54G as a separate access point, but I wanted a central management of all my gadgets.
Synology – the solution to ISP’s modem/router connectivity, which itself became a problem
I researched a bit and asked around, which routers are good nowadays. I heard about Ubiquity (and almost decided for it), Asus, TP-Link, OpenWRT (compatible) and Mikrotik. And Synology.
Finally I decided for a Synology. I have their NAS for 13 years, it has a nice UI, hasn’t failed yet and that was a deciding factor.
I went with their top offer: Synology RT6600ax router + WRX560 access point.
Installation of the router was dead easy. I just turned it on, connected to its wifi, created a user, connected WAN port to modem’s LAN port, called Telekom to put the modem in the bridge mode, entered PPPoE user/pass and voila, it worked.
SRM (the management UI) is really nice. I can see traffic by clients/protocols/apps/…
Wifi mesh access points and traffic:
Issues with internal web pages load times … was it DNS?
I tested the network a bit, added WRX560 as a mesh access point. And then the issues started.
Internal web pages accessed via browser / domain names were slow or there was a timeout when loading.
It looks like the network doesn’t handle http/s request to internal web pages well AFTER adding wrx560 and creating a mesh.
Before adding WRX, the access to internal web pages was quick. Even before, when I was using only my ISP modem/router, everything was quick.
Firmware: SRM 1.3.1-9346 Update 12
Symptoms:
When I tried to load a webpage that is on my webserver in my LAN via my domain (e. g. this page, https://blog.rozman.info and some others), it took 1-30 seconds for a page to load (or there was a timeout). Especially if I reloaded the page in a sequence or clicked links on the same page in short time.
Setup:
GPON –> Modem (bridge mode) –> rt6600ax (router) –> wrx560 (ap)
I have static IPv4 (and IPv6). My web domain points to the router static ip –> port forwarding –> reverse proxy (in my LAN) –> web server (in my LAN).
If I connected wirelessly or wired directly to rt6600ax, there was no timeout or delay. If I accessed it from external network (e. g. via mobile data), no timeout or delay.
If I connected wirelessly or wired to the access point WRX, there WAS a delay or timeout. Even if I put wrx on the last place in lan (after a dumb switch) and connected to the same switch, there was a delay. It got worse if I clicked refresh on a web page quickly several times in a row.
I ran countless tests without success.
Everything else worked fast and ok. Speedtest showed 300/100 Mbs, ping was 2-5ms, traceroute was 3ms to my modem, dig was fine, nslookup was fine).
Response of the webpages via IP – also no problem – loaded quickly, under 100ms.
But when I accessed it via domain name, it stuttered. Browser / Developer mode / Network / Timings showed:
If the page loads quickly via IP and stutters via domain name … it must be DNS, right?
Then I wrote a little curl script that measures the response time to exclude browser issues:
curl -w "\nDNS Lookup: %{time_namelookup}s\nConnect: %{time_connect}s\nStart Transfer: %{time_starttransfer}s\nTotal: %{time_total}s\n" -o /dev/null -s
https://blog.rozman.info
that returns (when it’s ok):
DNS Lookup: 0.005905s
Connect: 0.007009s
Start Transfer: 0.838036s
Total: 0.838527s
when it choked, it returned:
DNS Lookup: 0.008007s
Connect: 1.009419s //or 2, 3, 10 seconds
Start Transfer: 1.952299s //or 2, 3, 10 seconds
Total: 1.952632s
when there wasa timeout, it returned:
DNS Lookup: 0.006191s
Connect: 0.000000s //timeout
Start Transfer: 0.000000s //timeout
Total: 21.034533s
DNS lookup looks quick, but after that (waiting and connecting) it chokes.
It felt like that wrx560 (or mesh setup) added some kind of recursive loop to the (DNS?) request. NAT Loopback? I don’t know, I’m not a networking professional.
Failed attempts
I was desperate and tried many things without success:
Temporary workaround solution – split DNS
I temporary solved slow response/load times by adding my web site domain names to my local DNS records on my Pihole (‘split DNS’). I wasn’t very happy, because this is no real solution, only a bad workaround. But it worked.
I waited some more for the support to fix it.
At this moment I was sure I didn’t fuck it up. There must be something in the mesh setup that disturbes connection response.
And finally:
After a week of a chat with the support, they suggested to check out some obscure setting hidden deep in the menus and turn it off:
Control panel / System / SRM settings / Enhance the roaming compatibility of clients between Wi-Fi systems (turn it off).
AND IT WORKED!
Immediately after unchecking this setting, the my web pages became responsive. Whoah.
At the end, all good.
But then I started to play with IPv6…
till the next time!
Disclaimer
The links to the products (or mentioning them) are not affiliate links and I don’t receive any compensation for linking.
Hashtags: #synology #srm #homelab #mesh #selfhosting #dns #network
https://blog.rozman.info/setting-up-a-synology-router-and-wifi-mesh-was-it-a-mistake/
List of service providers outside the United States jurisdiction.
The list has moved to a place where it can expand beyond the character limits of the Fediverse, to an easy to navigate index list, on Codeberg (an alternative to GitHub or GitLab)
https://codeberg.org/Linux-Is-Best/Outside_Us_Jurisdiction
#Vpn #Dns #Cdn #Email #WebHosting #SearchEngine #PasswordManager #RuleOfLaw #Justice #FreedomOfSpeech #Project2025 #Facism #Nazis #CodeBerg #GitHub #GitLab
We researched the domains involved and found that some had been registered at NiceNIC, which we recognize as a problematic registrar located in China. This connection to China aligns with the type of pig-butchering / fake crypto platform scams that we're seeing. What makes this case unique is the use of political disinformation as a lure.
An important lesson here is how adtech is being misused to facilitate disinformation and fraud. This is a trend you're probably familiar with if you've been following our content.
Sample of identified domains: ecno26r4jj[.]com, affiltrack5681[.]com, client[.]fx-trinity[.]com, smartbrokerreviews[.]top
#pigbutchering #scam #disinformation #canada #dns #mastodon #threatintel #cybercrime #threatintelligence #cybersecurity #infosec #infoblox #infobloxthreatintel
3/3