Re: DNS weirdness on IPCop for new laptop
"Kevin W. Wall" <[email protected]>
| Newsgroups | gmane.comp.security.ipcop.user |
|---|---|
| Message-ID | <CAOPE6PhyqKqVjjP-4bAr9msf6EX=Q7mGwGEWXLURE7UYrpdrnQ@mail.gmail.com> |
On Jul 29, 2016 15:52, "G.W. Haywood" <[email protected]> wrote: > > Hi there, > > On Fri, 29 Jul 2016, Kevin W. Wall wrote: > > > ... This is not looking good at all. If this is a "feature" of AT&T, > > I'll be looking for a new ISP. > > https://forums.malwarebytes.org/topic/173092-198105244114/#entry991074 GW...thanks for the link. I think I figured this out. I had recently rebuilt my IPCop host because I had a hard drive crash. When I ran setup, I forgot to punch in the primary and secondary DNS servers under 'setup', so the end result is that it was using AT&T's DNS. (I had previously set it to use OpenDNS and Google's public DNS respectively.) I went back, reran setup to put those DNS servers it and the problems I was having disappeared. I am beginning to think that this problem has existed ever since I switched to AT&T some years ago, but I never noticed it before because I was using alternate DNS servers. I probably was thinking I'd go back and rerun 'setup' latter and then forgot. I also am beginning to believe that this was an AT&T "feature" for them to make some additional money by hijacking DNS NXDOMAIN responses. The paragraph under the section "DNS Hijacking And NXDOMAIN" in this article at https://www.dnsknowledge.com/whatis/nxdomain-non-existent-domain-2/ would seem to support that theory. It states: "A few ISPs such as Optimum Online, Comcast, Time Warner, Cox Communications, RCN, Rogers, Charter Communications, Verizon, Virgin Media, Frontier Communications, Bell Sympatico, Airtel, and many others started the bad practice of DNS hijacking on non-existent domain name for making money by displaying the internet advertisements." so apparently, this is a common practice. Maybe one of these days, when I have more time to waste, I'll actually call up AT&T Tech Support and try to find someone with a clue to admit that this is what they are doing. (If they didn't do it, then I'd pretty much blame them for the compromise anyway as there does not appear to be a way to update the firmware on their 2Wire device.) But if this problem is common with major ISPs, switching to WOW or TWC is not likely to improve things. I've also done some additional OS customized hardening on IPCop and may plan on doing some more. I'd like to update to 2.1.9, but I'd really prefer to test it out first. If I can find another weekend when my son is away (being a Millennial, he it not very tolerant of being without the Internet except when he is sleeping), I may experiment with 2.1.9, especially if I can find another spare unused drive, which would allow me to test it use my current hardware NIC configuration by just swapping HDD. Anyhow, thanks to all who replied with ideas / feedback. -kevin -- Blog: http://off-the-wall-security.blogspot.com/. | Twitter: @KevinWWall NSA: All your crypto bit are belong to us. ------------------------------------------------------------------------------ _______________________________________________ IPCop-user mailing list [email protected] Manage your subscription or unsubscribe https://lists.sourceforge.net/lists/listinfo/ipcop-user