Re: DNS weirdness on IPCop for new laptop

"Kevin W. Wall" <[email protected]>
Newsgroups gmane.comp.security.ipcop.user
Message-ID <CAOPE6PhyqKqVjjP-4bAr9msf6EX=Q7mGwGEWXLURE7UYrpdrnQ@mail.gmail.com>
On Jul 29, 2016 15:52, "G.W. Haywood" <[email protected]> wrote:
>
> Hi there,
>
> On Fri, 29 Jul 2016, Kevin W. Wall wrote:
>
> > ... This is not looking good at all. If this is a "feature" of AT&T,
> > I'll be looking for a new ISP.
>
> https://forums.malwarebytes.org/topic/173092-198105244114/#entry991074

GW...thanks for the link.

I think I figured this out. I had recently rebuilt my IPCop host because I had
a hard drive crash. When I ran setup, I forgot to punch in the primary and
secondary DNS servers under 'setup', so the end result is that it was using
AT&T's DNS. (I had previously set it to use OpenDNS and Google's public
DNS respectively.) I went back, reran setup to put those DNS servers it
and the problems I was having disappeared. I am beginning to think that
this problem has existed ever since I switched to AT&T some years
ago, but I never noticed it before because I was using alternate DNS
servers. I probably was thinking I'd go back and rerun 'setup' latter and
then forgot.

I also am beginning to believe that this was an AT&T "feature" for them to
make some additional money by hijacking DNS NXDOMAIN responses.
The paragraph under the section "DNS Hijacking And NXDOMAIN" in
this article at
  https://www.dnsknowledge.com/whatis/nxdomain-non-existent-domain-2/
would seem to support that theory.  It states:
    "A few ISPs such as Optimum Online, Comcast, Time Warner, Cox
    Communications, RCN, Rogers, Charter Communications, Verizon, Virgin
    Media, Frontier Communications, Bell Sympatico, Airtel, and many
    others started the bad practice of DNS hijacking on non-existent
    domain name for making money by displaying the internet
    advertisements."

so apparently, this is a common practice. Maybe one of these days, when
I have more time to waste, I'll actually call up AT&T Tech Support and try
to find someone with a clue to admit that this is what they are doing. (If
they didn't do it, then I'd pretty much blame them for the compromise anyway
as there does not appear to be a way to update the firmware on their
2Wire device.) But if this problem is common with major ISPs, switching
to WOW or TWC is not likely to improve things.

I've also done some additional OS customized hardening on IPCop and
may plan on doing some more. I'd like to update to 2.1.9, but I'd really prefer
to test it out first. If I can find another weekend when my son is away (being
a Millennial, he it not very tolerant of being without the Internet except when
he is sleeping), I may experiment with 2.1.9, especially if I can find another
spare unused drive, which would allow me to test it use my current
hardware NIC configuration by just swapping HDD.

Anyhow, thanks to all who replied with ideas / feedback.

-kevin
--
Blog: http://off-the-wall-security.blogspot.com/.   | Twitter: @KevinWWall
NSA: All your crypto bit are belong to us.

------------------------------------------------------------------------------
_______________________________________________
IPCop-user mailing list
[email protected]
Manage your subscription or unsubscribe
https://lists.sourceforge.net/lists/listinfo/ipcop-user
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.