home.social

#dns — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #dns, aggregated by home.social.

fetched live
  1. “How an expired nameserver let me take over e164.arpa zones for multiple territories, and why I probably should have checked my logs sooner.”

    #dns #arpa #nameserver

    lina.sh/blog/hijacking-e164-ar

  2. 📡 NetworkManager 1.58.1 a fost lansat: Remedii importante pentru WPA3, gestionarea DNS și stabilitatea modemurilor!

    A fost lansată versiunea NetworkManager 1.58.1, prima actualizare de mentenanță din seria 1.58 a utilitarului standard utilizat de majoritatea distribuțiilor Linux pentru gestionarea conexiunilor de rețea (Wi-Fi, Ethernet, VPN, conexiuni mobile).

    ✨ Principalele remedii și noutăți din NetworkManager 1.58.1:

    🔒 Corecții pentru conexiunile securizate WPA3 / Wi-Fi:
    • Rezolvă probleme legate de reconectarea pe rețelele Wi-Fi care folosesc profilul de securitate WPA3-Personal (SAE) sau Enterprise, prevenind deconectările neașteptate și eșecurile la autentificare la ieșirea din modul de pauză (suspend).

    🌐 Stabilitate sporită pentru rezoluția DNS:
    • Ajustări la nivelul integrării cu systemd-resolved și dnsmasq, asigurând că actualizarea serverelor DNS la comutarea între rețele (ex. trecerea de la Wi-Fi la Ethernet sau VPN) se face corect, fără a lăsa în cache adrese vechi.

    📱 Fix-uri pentru modemuri celulare (WWAN / 4G / 5G):
    • Îmbunătățiri ale comunicării cu modulul ModemManager, oferind o mai bună gestionare a stărilor de semnal, o inițializare mai rapidă a conexiunilor de date mobile și suport mai stabil pentru cartele eSIM.

    ⚙️ Mici optimizări interne:
    • Corecții de memorie (memory leaks) și rezolvarea unor probleme la procesarea fișierelor de configurare .nmconnection utilizate de administratori în linia de comandă (nmcli).

    O actualizare recomandată pentru toate sistemele Linux pentru a garanta o conectivitate stabilă și securizată! 🚀

    #NetworkManager #Linux #SysAdmin #Networking #WPA3 #DNS #Linuxiac #TechNews #OpenSource #FOSS

  3. @lina Thanks for writing this up. Whenever product teams EOL things I always make them permanently park any #DNS domains and they often complain, but this is a great example as to why it's necessary.

  4. RE: ohai.social/@lina/117133187934

    A story of #DNS, #ENUM and #VoIP … and also why you need to not let domains expire….

    (“Oh, we stopped using that service, right? So we can just not renew those domain names, correct?” 🤦‍♂️ Or more likely… people moved on and absolutely no one even *thought* about the domain names..)

  5. @scattershot

    Fascinating excursion into a case of forgotten servers using forgotten network conventions, and how no one wanted to own the associated security vulnerabiliies. Not my field, so I can't comment, but certainly an enjoyable read.

    #e164 #DNS #DiegaGarcia

    EDIT: As it happens, Lina, the cheerful e164.arpa explorer who takes us on this journey, is on the Fedi, @lina.

  6. ENUM-Domains gekapert: Wie eine Hackerin beinahe militärische Telefonate abhörte

    Einige Inselnationen hatten geschlampt und ihre Telefonie angreifbar gemacht. Die Sicherheitsbehörden reagierten erst spät und nach einem Raketenangriff.

    heise.de/hintergrund/ENUM-Doma

    #DNS #Hacking #IT #Security #news

  7. ENUM domains hijacked: How a hacker almost eavesdropped on military calls

    Some island nations had been negligent and made their telephony vulnerable. Security authorities only reacted late and after a missile attack.

    heise.de/en/background/ENUM-do

    #DNS #Hacking #IT #Security #news

  8. @shaft @bortzmeyer pour l'instant je reste en ED25519 pour toutes les zones de production que je gère mais justement j'aurais voulu tester les problèmes en ML-DSA-44 (en signant du-mlsdsa44.teste.des.services)

    #DNS #DNSSEC #PQC

  9. How Peer2Profit and Astroproxy Turn Your Bandwidth Into Someone Else's Product

    Investigation into residential proxy networks reveals that bandwidth-sharing applications like PEER2PROFIT recruit users to share internet connections for payment, then monetize this bandwidth through commercial proxy service ASTROPROXY at up to 27 times the original cost. Over 72 hours, researchers identified 117,224 unique IPs across residential, mobile, and datacenter pools, with residential pools adding over 1,000 new IPs hourly. These applications install through official channels with user consent, making them invisible to traditional security tools. Reverse engineering of the Windows SDK revealed the communications protocol and backconnect infrastructure coordinating proxy sessions. Testing demonstrated that proxy networks could access internal network resources through simple DNS entries resolving to internal IPs, potentially exposing corporate assets. The scale, legitimacy, and internal network access capabilities present significant risks to organizations where employees may unknowingly expose co...

    Pulse ID: 6a8734bb1e57bed1c101e5e9
    Pulse Link: otx.alienvault.com/pulse/6a873
    Pulse Author: AlienVault
    Created: 2026-08-20 17:09:15

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CyberSecurity #DNS #InfoSec #Mac #OTX #OpenThreatExchange #Proxy #RAT #RCE #Windows #bot #AlienVault

  10. I released v1.7.1 of gonemaster that now can verify ML-DSA-44. Based on miekg/dns that also released support for it today. #DNS #dnssec #pqc

  11. It's always either , , or

  12. Liked those short Curve RRSIG's in DNSSEC?

    Well, that time is over, good lord. Post quantum RRSIGs with MLDSA44, codeberg.org/miekg/dns/pulls/9

    #go #dns

  13. Der zweite DNS-Server fürs Homelab, das sollte doch straightforward sein. Aber Redundanz ist nur dann gut, wenn sie die Verfügbarkeit verdoppelt und nicht die Fehlerquellen 😄

    Über die Fallstricke beim Aufbau eines zweiten Technitium habe ich hier geschrieben:
    tim-bartel.de/secondary-dns-im

    #Homelab #DNS #SelfHosted #Technitium

  14. Hi,

    I am looking to use PiHole to block more than ads. I am hoping to find a regularly-updated blocklist of malicious URLs, like the ones that can exfiltrate sensitive information. I came across,

    * github.com/Tempest-Solutions-C
    * github.com/tweedge/emerging-th

    But it's not clear to me if they are being regularly updated. Reason, I searched for the exfiltration URLs used during the Shai-Hulud attack, and I don't think they are in their block list.

    Thank you.

    #pihole #security #selfhosting #malware #hacking #dns #infosec

  15. 📢 New #updates · 20 Aug #1

    · firecrawl v1.10.0
    · e2b [email protected] — Sandbox outbound TCP now routes through SOCKS5 proxy
    · convex precompiled-2026-08-19-2cbcf81
    · fluxer [email protected]
    · lightdash 1.208.0 — Enables merge queries composition behind feature flag

    Check out more on selfhost.directory

    #privacymatters #dns #import

  16. Что делать, если сервер доступен по SSH, а сайт не открывается

    Мониторинг шлёт тревогу, пользователи пишут, что «всё лежит», но SSH пускает на сервер. Значит, машина включена и 22-й порт доступен. О домене, портах 80 и 443, TLS, веб-сервере и приложении это пока ничего не говорит… Кажется, что нужно просто перезапустить nginx, но перезапуск стирает часть следов и может превратить частичную аварию в полную беду. Под катом расскажу, как пройти путь запроса сверху вниз и найти место, где он остановился. Читать

    habr.com/ru/companies/ruvds/ar

    #Linux #SSH #nginx #системное_администрирование #серверное_администрирование #DNS #TLS #VDS #вебсерверы #ruvds_статьи

  17. #RFC 3901 is now obsoleted

    “This document provides guidelines and documents best current practice for operating authoritative #DNS servers, recursive resolvers, and stub resolvers in a mixed #IPv4 / #IPv6 environment."

    RFC 10001: Operational Guidelines for DNS Transport in Mixed IPv4/IPv6 Environments
    rfc-editor.org/info/rfc10001/

  18. Es sieht so aus als wäre #Codeberg der Plan B für #Hagezi #DNS #blocklisten und eine neue Heimat. Wie #dnsbunker damit zusammenhängt, kann ich nicht sagen. Wird spannend.

    codeberg.org/hagezi/mirror2

  19. Автоматизация wildcard-сертификатов

    Рано или поздно в инфраструктуре появляется задача автоматического обновления TLS-сертификатов. В простом случае она решается установкой certbot: один домен, один сервер, cron-задание и дальше можно не вспоминать об этом годами. Сложности начинаются, когда инфраструктура вырастает…

    habr.com/ru/articles/1071764/

    #angie #devops #acme #challenge #ns #dns #wildcard

  20. Сказ про домен AD, ДНС, сетевого инженера и архитектора

    В некотором царстве, в некотором государстве… Историю расскажу, как сказочку, из тех соображений, что в сказочника камней не кидают, аллергия на камни :) Ибо, ну что с него взять? Он же сказочник! Так вот. Жила была компания, давненько это было, домен AD, w2k3 сервера, филиалы по области штук 15-20, в каждом по контроллеру домена для надежности, и объединялись они с головным офисом каналами ВПН. В некоторых ранних версиях даже через GSM-модемы. И настали трудные времена, да так что пара филиалов задумали уйти к Шведам отпочковаться в самостоятельность. Или компанию разрывать начали за долги из-за взаимных неплатежей, я уже не помню. История покрылась патиной. Архитектор в том домене был человеком незлобивым. Рассудил, что проще всего, при отключении филиала — долгосрочное падение линка — это как умерли, ну и потом просто удалить из домена и контроллеры, и сайты. И делу конец. И для филиалов, тоже нормально — погасили ВПН и захватили роли FSMO на свои контроллеры, и дальше жить поживать. Зеркально удалив все лишнее, за ненадобностью. Рабочий вариант. Но пришли к архитектору старшие и намекнули так прозрачно, что негоже отпускать филиалы просто так, придумай, говорят, что-нибудь этакое. Видимо, у них свои резоны были :) . Почитать, чего надумал архитектор

    habr.com/ru/articles/1071614/

    #Active_Directory #dns #системное_администрирование #fsmo #таски

  21. In Go dns v2 I am making the handlers class aware codeberg.org/miekg/dns/pulls/9

    This fixes a long standing annoyance with chaos queries... Either all handlers need to needlessly check the class or ignore the class all together. Clearly this belonged in the server all along.

    (Also fuck DNS classes, was a fun idea, didn't work, deprecate this shit)

    #go #dns

  22. Cavern C2 Uses DNS and Google Apps Script to Blend Into Legitimate Traffic

    Indicators extracted from public reporting. Source: securelist.com/project-cav3rn-

    Pulse ID: 6a8367506b41736758a8d45b
    Pulse Link: otx.alienvault.com/pulse/6a836
    Pulse Author: CyberHunter_NL
    Created: 2026-08-17 19:56:00

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CyberSecurity #Cyberespionage #DNS #Espionage #Google #HTTP #HTTPS #InfoSec #OTX #OpenThreatExchange #Outlook #RCE #SecureList #bot #CyberHunter_NL

  23. Einordnung: DNS Cache Poisoning klingt nach 2006, ist aber offenbar noch nicht erledigt. Besonders unschön ist, dass der Angriff ohne eigenen autoritativen Server auskommen kann. Wer BIND9 betreibt, sollte deshalb nicht nur auf DNSSEC vertrauen, sondern sicherstellen, dass die veröffentlichten Patches tatsächlich eingespielt sind.

    2/2

    #DNS #BIND9 #Patchmanagement #KuketzAugust