How to fix DNS hijacking

Discussion in 'Computers and The Internet' started by AceK, Mar 20, 2014.

  1. AceK

    AceK Scientia Potentia Est

    Messages:
    7,824
    Likes Received:
    960
    My ISP does this shit. Domain names that don't exist somehow get redirected to an IP address with adds and shit. I don't trust their DNS servers...is there a way I can configure my router to use different DNS servers. I'm on time warner cable by the way and I'm pretty sure all ISPs probably do this. Is there any way to use more trusted higher level DNS servers instead?

    This shit ought to be considered criminal! It's basically the same thing as rewriting my hosts file to redirect to fake domains! Yea, I've phished a little before and this comes kinda close to that!

    They also seem to know when a MAC address is spoofed and rejects it even when it's set to a legit vendor. Maybe it's my wifi card...I need a good USB wifi card that supports packet injection (I could throw it away if I needed to). Starbucks seems to reject spoofed MACs too and I know I'm doin it right, same way I've always done it it just don't work now?

    Trying to learn some shit today, can't seem to get much else done right now :/
     
  2. NoxiousGas

    NoxiousGas Old Fart

    Messages:
    8,382
    Likes Received:
    2,388
  3. AceK

    AceK Scientia Potentia Est

    Messages:
    7,824
    Likes Received:
    960
    Yeah, I know how to configure it, it's not much of a network I got here ;). Thing is they can go in and update ur firmware w/o u knowing. I need to buy my own router and modem instead of using the leased one, no way can I trust those things. Probably got some kinda backdoor in it that u can't see or reconfigure cuz it's in the firmware.
     
  4. AceK

    AceK Scientia Potentia Est

    Messages:
    7,824
    Likes Received:
    960
    It looks like they have some kind of tunnel set up but it shows as disconnected...I don't like that
     
  5. NoxiousGas

    NoxiousGas Old Fart

    Messages:
    8,382
    Likes Received:
    2,388
    Even if you use your own modem, I think they still need to be able to access it.
    I use my own router and TW's modem. What pissed me off is they now do a thing where if your late with your bill they release you IP lease, hijack the browser, put up a page saying your bill is past due and you have to fucking reboot the machine to continue doing anything. I lost 30 minutes of work on my daughters FAFSA application because of it the other day!

    The Motorola modem are the best out there right now and TW does support them. I have a TP-Link TL-WR1043ND router and have been very happy with it so far. Lots of nice features and security.:2thumbsup:
     
  6. AceK

    AceK Scientia Potentia Est

    Messages:
    7,824
    Likes Received:
    960
    Way better with those DNS servers...still not sure about the tunnel adapter, it's IPv6 and I don't really know shit about that or what it's doing...might need to look into it further
     
  7. AceK

    AceK Scientia Potentia Est

    Messages:
    7,824
    Likes Received:
    960
    Are they sure they are actually hijacking the browser, or just setting up a DNS relay that redirects anything to that page? (Which I suppose would do the hijacking?) Shit freaks me out what ISPs do, can't trust 'em.
     
  8. NoxiousGas

    NoxiousGas Old Fart

    Messages:
    8,382
    Likes Received:
    2,388
    Not exactly sure what/how they do it, probably a relay. Was doing my thing, clicked on a link and BAM! up came a TW page about my bill and I had to reboot to re-establish an internet connection, dirty bastards!
     
  9. AceK

    AceK Scientia Potentia Est

    Messages:
    7,824
    Likes Received:
    960
    See that's the thing about this country, anything is legal as long as you got paper that says you can do it but it's illegal for anyone else
     
  10. lode

    lode Banned

    Messages:
    21,697
    Likes Received:
    1,677
  11. lode

    lode Banned

    Messages:
    21,697
    Likes Received:
    1,677
    It works like you asking a guy what the phone number for a pizza place is. When he tells you that phone number, it's actually the phone number of your internet company asking for money.

    DNS works essentially like a phone book. It's UDP, which is connectionless, so there's no handshake really confirming that the response is from the name server. There's a little security added to this, but essentially the cache can be easily flooded, this was known about it 2008, and is near the top of most the most severe bugs in the history of the internet.

    A full solution was made in 2008 which is dnssec, which is a cryptographic signature from websites, associating the websites and IP addresses. The problem, is that it hasn't been accepted very quickly, in fact, much worse.

    http://www.networkworld.com/news/2013/012913-dnssec-266197.html
     
  12. raysun

    raysun D4N73_666 4861786f72

    Messages:
    931
    Likes Received:
    10
    Hi all,
    this is a link to dns servers it is quitte handy there are also secure servers included

    Code:
     http://wiki.ipfire.org/en/configuration/dns_list 
    take care peace
     
  13. AceK

    AceK Scientia Potentia Est

    Messages:
    7,824
    Likes Received:
    960
    So what do u gurus suggest, open DNS name servers, google name servers or what?

    Thank to all who have posted :)
     

Share This Page

  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.
    Dismiss Notice