3 ms·
There's a page about transparent DNS proxies [0] on the same site. They also have a page about how to fix dns leaks when using OpenVPN [1]. One way to ensure t
by ploggingdev 9y ago
There's a page about transparent DNS proxies [0] on the same site. They also have a page about how to fix dns leaks when using OpenVPN [1].
One way to ensure that DNS responses have not been tampered with is to use DNSCrypt [2].
Can someone confirm that I understand this correctly : if I don't use DNSCrypt and if my DNS responses are tampered with in a phishing attempt, on a site that uses https, the browser will raise a cert error since the attacker won't have a valid certificate. So phishing attempts by spoofing DNS responses are only effective when the site uses plain http.
[0] https://www.dnsleaktest.com/what-is-transparent-dns-proxy.html https://www.dnsleaktest.com/what-is-transparent-dns-proxy.ht...
[1] https://www.dnsleaktest.com/how-to-fix-a-dns-leak.html https://www.dnsleaktest.com/how-to-fix-a-dns-leak.html
[2] https://dnscrypt.org/ https://dnscrypt.org/
- simcop2387 9y agoNot just http, any unencrypted channel is vulnerable to this. So SMTP or pop without encryption would also let someone into your email.