3 ms·
This is also a handy way to see if your outbound DNS requests are being hijacked and sent to another resolver instead of your chosen ones. One router I tested r
by ehPReth 9y ago
This is also a handy way to see if your outbound DNS requests are being hijacked and sent to another resolver instead of your chosen ones. One router I tested redirected everything to OpenDNS if parental controls were in use, some networks redirect everything to their internal resolvers, etc. Mainly for interest purposes/spotting configuration mistakes than anything else.
- ploggingdev 9y agoThere's a page about transparent DNS proxies [0] on the same site. They also have a page about how to fix dns leaks when using OpenVPN [1]. One way to ensure that DNS responses have not been tampered with is to use DNSCrypt [2]. Can someone confirm that I understand this correctly : if I don't use DNSCrypt and if my DNS responses are tampered with in a phishing attempt, on a site that uses https, the browser will raise a cert error since the attacker won't have a valid certificate. So phishing attempts by spoofing DNS responses are only effective when the site uses plain http. [0] https://www.dnsleaktest.com/what-is-transparent-dns-proxy.html https://www.dnsleaktest.com/what-is-transparent-dns-proxy.ht... [1] https://www.dnsleaktest.com/how-to-fix-a-dns-leak.html https://www.dnsleaktest.com/how-to-fix-a-dns-leak.html [2] https://dnscrypt.org/ https://dnscrypt.org/
- simcop2387 9y agoNot just http, any unencrypted channel is vulnerable to this. So SMTP or pop without encryption would also let someone into your email.