3 ms·
You can run a dnsmasq locally with "--stop-dns-rebind". I have this enabled on my router.
by jfroma 10y ago
You can run a dnsmasq locally with "--stop-dns-rebind".
I have this enabled on my router.
- solidninja 10y agoI was also going to mention this (https://doc.pfsense.org/index.php/DNS_Rebinding_Protections https://doc.pfsense.org/index.php/DNS_Rebinding_Protections has a few notes). dnsmasq has many other uses like tunneling all your DNS traffic through dnscrypt (https://www.opendns.com/about/innovations/dnscrypt/ https://www.opendns.com/about/innovations/dnscrypt/)
- twr 10y agoUbiquiti router owners (I know there are a few on HN) can enable this option like so: ssh <router> configure set service dns forwarding options stop-dns-rebind commit save /var/log/dnsmasq.log should contain the resolution failures after that. e.g.: Sep 1 21:48:41 dnsmasq[26479]: possible DNS-rebind attack detected: www.dropboxlocalhost.com