[100712] in North American Network Operators' Group

home help back first fref pref prev next nref lref last post

Re: Hey, SiteFinder is back, again...

daemon@ATHENA.MIT.EDU (Stefan Bethke)
Tue Nov 6 00:38:36 2007

Cc: nanog@merit.edu
From: Stefan Bethke <stb@lassitu.de>
To: Stephane Bortzmeyer <bortzmeyer@nic.fr>
In-Reply-To: <20071105161608.GA18239@nic.fr>
Date: Tue, 6 Nov 2007 06:37:39 +0100
Errors-To: owner-nanog@merit.edu


Am 05.11.2007 um 17:16 schrieb Stephane Bortzmeyer:

> 3) Provide DNS recursors which do the mangling *and* block users,
> either by filtering out port 53 or by giving them a RFC 1918 address
> with no NAT for this port.
>
> I've seen 1) and 2) in the wild and I am certain I will see 3) one day
> or the other.

Just recently in NYC, the hotel "internet" connection did intercept  
any UDP traffic to *:53, redirecting it to their resolver.  Which did  
not only serve their own A records for names that should have returned  
NXDOMAIN, but also returned "better" answers than you normally would  
get (requesting pages from www.weather.com delivered pages from www.accuweather.com 
).  Of course it even did that after I had paid and clicked through  
their walled garden site.


Stefan

-- 
Stefan Bethke <stb@lassitu.de>   Fon +49 170 346 0140



home help back first fref pref prev next nref lref last post