3 ms·
It doesn't. You are correct. For any unencrypted WiFi but with a paywall / login page for actual usage - if the software is worth anything, DNS is hijacked and
by pudquick 12y ago
It doesn't. You are correct. For any unencrypted WiFi but with a paywall / login page for actual usage - if the software is worth anything, DNS is hijacked and re-routed for unapproved clients.
- hueving 12y agoIt is really terrible software if it does hijack the DNS queries. That messes with all kinds of clients that cache DNS records. A good system will allow DNS instead of poisoning the clients with thresholds to block DNS tunneling.
- sk5t 12y agoI would think non-NXDOMAIN answers with very short TTLs (to avoid contaminating the negative lookup cache) ought to be harmless to all but the very sloppiest clients, no?
- hueving 12y agoNo. First, clients may be sloppy or may have alerts triggered if the IP doesn't fall into the right range. The latter has nothing to do with poor code quality. That's the problem with hijacking DNS, you've moved well beyond web browsers into all kinds of applications that are loaded with custom code that have completely undefined behavior from your perspective. For all you know, the DNS responses you've tweaked will make the user's software completely unusable until the whole thing is restarted. Second, what do you do when the client is configured to require DNSSEC responses?