Comcast Intercepts and Redirects Port 53 Traffic
An anonymous reader writes "An interesting (and profane) writeup of one frustrated user's discovery that Comcast is actually intercepting DNS requests bound for non-Comcast DNS servers and redirecting them to their own servers. I had obviously heard of the DNS hijacking for nonexistent domains, but I had no idea they'd actually prevent people from directly contacting their own DNS servers." If true, this is a pretty serious escalation in the Net Neutrality wars. Someone using Comcast, please replicate the simple experiment spelled out in the article and confirm or deny the truth of it. Also, it would be useful if someone using Comcast ran the ICSI Netalyzr and posted the resulting permalink in the comments.
someone is intercepting my DNS requests.
When Comcast took over from Time Warner here, I bailed.
I mean, Time Warner is evil. AT&T (who I switched to), is evil.
But Comcast is Motherfucking Sith Lord EVIL.
Scary fucking eeeeevil. Nazi evil. RIAA evil.
I'm a comcast user and it works for me...perhaps his home network is the problem. A Linux user having a misconfigured network?!??! Oh wait this is Slashdot...nevermind.
screen shot or it didn't happen ;)
-=[ Who Is John Galt? ]=-
wow, it as if Comcast was trying to set a record of some sort for bad customer relations.
Last time I had some spare time in an airport, I found that the T-Mobile hotspot allowed 53/UDP traffic out, so I was thinking of setting up openvpn on port 53 (instead of its usual 1194) in order to access my home machines (without a T-Mobile login). If Comcast intercepts this traffic, my evil plan won't work!
The real "Libtards" are the Libertarians!
Why are people suddenly so obsessed with pointing to the reply button?
Somebody screwed up posting this.
Posted by kdawson on 02:11 PM -- Tuesday June 09 2009
Why am I not surprised.
I would reply to that but I can't reply to something that doesn't exist (i.e. AC).
The answer to your question is here:
|||
\\
\|
|
|
V
Perhaps he wanted to mask his IP? ;)
Pretty essential if he is running on HyperVM...
Violence is the last refuge of the incompetent. Polar Scope Align for iOS
Or, more simply, query something you know doesn't exist (like asdfdsafdsafhdsds.com) against your server
Thanks alot. Now I'm going to get slashdotted.
Prove it.
> Or, more simply, query something you know doesn't exist (like asdfdsafdsafhdsds.com)
1) Quickly registered non-existing domain mentioned on Slashdot and put up an ad-serving site.
2) Wait for bored Slashdotters to try the link.
3) Profit.
Thanks Slashdot :-)
Yep. His quota is "as many as possible".
I don't trust DNS.
My /etc/hosts is REEEEEEEEEEEEEEAAAAAAAAAAAALLLLLLLLLLLLLLLLY long.
Every once in a while, a site doesn't work anymore.
When that happens, I call my parents to get the new IP address.
Was gonna type something snarky here but it's best to let thing's go for now.
Then that's even worse! It means Comcast must have hacked his server to falsify the logs! /s
dance or you dont alien. eat or you dont starving. make love or go war. fly airplanes or flying saucer. listen Elvis or BB King.
Great, so now we can add "-1, Meatpuppet" to the list of needed moderation tags.
I can see the fnords!
^
|
|
\
\
\
\
I clicked on that and all I got was a lousy web form.
Every time I start to have faith in humanity, I ruin it by driving to work between 7 and 8 am.
ComcastBonnie can be reached at comcast.bonnie@verizon.com...