med-mastodon.com is one of the many independent Mastodon servers you can use to participate in the fediverse.
Medical community on Mastodon

Administered by:

Server stats:

365
active users

#dns

28 posts24 participants0 posts today

Just a quickie from one of our @DomainTools researchers today that I know @cR0w will enjoy.

Malware in DNS - specifically, malware seen being assembled from DNS TXT records.

Not a "zomg new thing!" so much as a neat example in the wild.

#infosec #cybersecurity #DNS

dti.domaintools.com/malware-in

DomainTools Investigations | DTI · Malware in DNS - DomainTools Investigations | DTIBecause it's always DNS, we wanted to share this fun finding of malware stored across DNS TXT records.

#BGP #routage Hier, Cloudflare a cessé d'annoncer son préfixe 1.1.1.0/24 (pour une raison inconnue). Les nombreuses annonces « pirates » de ce préfixe ont alors été davantage visibles, amenant certains, apparemment à tort, à croire qu'elles étaient la cause de la panne du résolveur #DNS 1.1.1.1.

mastodon.gougere.fr/@bgp/11485

Car, oui, il y a encore des réseaux (Tata, par exemple) qui annoncent ce préfixe, qui ne leur appartient pourtant pas.

Mastodon - Gougère NetworkBGP WhichASN (@bgp@mastodon.gougere.fr)@bortzmeyer 1.1.1.0/24 13335 Details: On prefix: https://stat.ripe.net/ui2013/1.1.1.0/24 On AS: https://stat.ripe.net/ui2013/AS13335
Replied in thread

@socketwench ah right - so where I left mDNS I was working out how to write nftables rules that would force any outbound traffic back to localhost to the systemd-resolved stub, which I could THEN enforce prioritizing mDNS responses, but also mDNS isn't kindof a closed and done thing like DNS is, it can just kinda, hang open for a but waiting for replies to the broadcast, and slowing everything down.

...yea I didn't get as far as investigating mDNS caching before this smelled awful

Replied in thread

@namedbird @drscriptt personally, I think #CPE / #Router manufacturers should've standardized upon *.router.local (i.e. fritzbox.router.local) since .local has been reserved for such purposeS... per #IETF via #IANA & #ICANN...

  • Espechally since the average "#normie #consoomer" isn't gonna own their own domain or even setup an internal #DNS resolver to manage their #LAN at home under *.local.domain.example to make it work.

In fact most corporate users don't even enroll #FQDN|s on their network (#Universities do based off my observation!)…

en.wikipedia.org.local - Wikipedia
Replied in thread

@drscriptt granted, we all want 203.0.113.1¹ to have #SSL / #TLS (even if it's just @letsencrypt ) work than not work or have no #encryption.

  • That is not up for debate!

I just think that this will reward previously standards-violating behaviours when i.e. Xavier Sample Solutions don't get nudged to use i.e. api.solutions.example² but can just use their IP addresses.

¹ Example as per RFC5737
² Example as per RFC2606

1.1.1.11.1.1.1 — The free app that makes your Internet faster.Install the free app that makes your phone’s Internet more fast, private, and reliable.
Replied in thread

@drscriptt Naive question: WHEN does the average #Internet #user ever open up a webpage with an #IP address instead of a #domain or even #FQDN?

  • Seriously, the only cases I saw were either some old, non-public - facing server in some B2B/API setting or a test that #httpd / #ngnix / #ssh / … function properly on like a #VPS and that the #DNS hasn't been updated (yet!) to include said host / FQDN in the records, and even then it's bad cuz you'd rather want to use it's FQDN instead because with #IPv4 shortages on one hand and tools like #Portainer on the other, one should not use an #IPaddress as addressing method because #WAF / #Proxies used to "#MUX" / "#NAT" services under one IP address or #IPv6 block may need that distinction by being queried for a specific FQDN...

The Idea if !SSL / #TLD for #IPaddresses makes me feel like Jeff Goldblum!

Der #Windows 10 PC von meiner Mutter hat das #Problem nur ca. 50% aller #DNS Auflösungen hinzubekommen.

Dabei ist es egal welche Anwendung die Anfrage stellt.
Egal ob Windows selbst, ein Browser oder "nslookup" in der cmd.

Egal welchen DNS Server ich einstelle, die FritzBox per DHCP, per Hand oder ein alternativer interner oder externer DNS Server.

Der Systemcheck via dism.exe findet keine Fehler.

Was ist da los?!

Ich bin komplett ratlos.

Ideen?

Upgrade auf Win11 ist eine Option?

Are you interested in building a (personal) website? Maybe you thought about it but you are not sure where to start?

Check out my post about „how to build a website“ and find yourself hosting a static site built by Hugo and hosted on GitHub for free within an afternoon!

rawomb.at/posts/build_a_websit

(Some programming experience is recommended)

#website #github #dns #hugo

P.S. Thank you for mentioning Hugo in your podcasts, @mkennedy

Rafael Weingartner-OrtnerRafael Weingartner-Ortner - How to build a website

Kann es sein, dass der "alternative" #DNS Server, der in #Windows einstellbar ist gar nicht alternativ (also wenn der primäre versagt) ist, sondern beide in einem mehr oder weniger zufälligen Verfahren gefragt werden?

Habe hier gerade so einen Fall, der das vermuten lässt...

Ist Windows wirklich so?

#PiHole #DNS #Filter blocks #Discord email verification - what the heck, man!?!

What else do they use clickDOTdiscordDOTcom for?

edit: well, technically that'd be on ME (not on PiHole); i've chosen the filter lists. I mightn't've chosen wisely enough. Over-blocking is totally a thing to be aware of! 😅

edit2: sometimes, other people know more than me - i'll un-whitelist this subdomain - it didn't benefit me

this #PerfekBlue thing is pretty wild:

and you know i get super excited when #DNS is involved:

> "Establishing a command-and-control (C2) channel over DNS allowed us to maintain a covert, persistent link with the vehicle, enabling full remote control. By compromising an independent communication CPU, we could interface directly with the CAN bus, which governs critical body elements, including mirrors, wipers, door locks, and even the steering."

thehackernews.com/2025/07/perf

Freitag: Basketball-Profi als Cyberkrimineller? Alterskontrolle bei Bluesky

Profisportler unter Ransomware-Verdacht + Bluesky prüft Alter britischer Nutzer + Bestechungsvorwürfe wegen Spyware + Probleme mit Outlook + Datenschutz-Podcast

heise.de/news/Freitag-Basketba

heise online · Freitag: Basketball-Profi als Cyberkrimineller? Alterskontrolle bei BlueskyBy Frank Schräer