4 ms·
Easy: https://dnsprivacy.org/wiki/display/DP/DNS+Privacy+Clients#DNSPrivacyClients-Localforwarders https://dnsprivacy.org/wiki/display/DP/DNS+Privacy+Clients#D.
by cuillevel3 5y ago
Easy: https://dnsprivacy.org/wiki/display/DP/DNS+Privacy+Clients#DNSPrivacyClients-Localforwarders https://dnsprivacy.org/wiki/display/DP/DNS+Privacy+Clients#D...
I want to add, that you can't run your own public DNS server nowadays, because it can be misused for DOS and hosting providers scan for open DNS servers.
So if you want your own public DNS resolver, DOH is much easier.
- csunbird 5y ago> because it can be misused for DOS and hosting providers scan for open DNS servers Can you elaborate? I am thinking of doing exactly that, in case of need.
- lights0123 5y agohttps://blog.cloudflare.com/deep-inside-a-dns-amplification-ddos-attack/#opendnsresolversbaneoftheinternet https://blog.cloudflare.com/deep-inside-a-dns-amplification-...
- csunbird 5y agoVery, very interesting… I forgot the fact that ip addresses can be spoofed in the UDP packets, essentially making DNS resolvers to carry out the attack for botnets.
- vengefulduck 5y agoDNS servers can be used in an DOS amplification attack by sending requests with spoofed ip addresses. So if you don’t take measures to prevent this it’s likely your server will be used in DOS attacks. https://us-cert.cisa.gov/ncas/alerts/TA13-088A https://us-cert.cisa.gov/ncas/alerts/TA13-088A
- cuillevel3 5y agoYou could try to run an IPv6 only DNS server, harder to find.
- outloudvi 5y agoOne reason is that DNS is UDP based, on which source IP spoofing is possible.
- e12e 5y agoBut it's not possible to configure via DHCP/network level autoconfiguration, is it?
- Spivak 5y agoNo and it probably shouldn’t be going forward, by default the local network administrator is an untrusted assumed-malicious entity. Can you imagine if your network administrator could just tell your computer to send all your unencrypted HTTP traffic to a proxy they control?