how to stop dns poison attack? - EVO 4G Q&A, Help & Troubleshooting

I'm not 100% sure this is what's happening but from my basic knowledge it looks like someone is poisoning my dns and in so doing so DOS's my network. I was using Google dns and the person was able to hijack it and switch it to sighroyal.com please don't visit this site as I'm 100% sure its malicious. I am using cyanogenmod7 on my HTC EVO 4g I edited my resolv.conf file I believe that's what its called, it let's you edit the dns name servers. I installed setdns and tried to change my dns but it stays at 8.8.8.8, does cyanogenmod7 for HTC EVO 4g use custom dns servers? Everytime I first log on packets always come from gtalk and I blocked all internet to it but still its able to communicate. Is the gtalk coming from me or my carrier? From my studies it seems gtalk is the source of my grief. What exactly is it and why does it always send packets when I first start the internet? I never get any replies here, I hope somebody can possibly help. Thank you

dave198803 said:
I'm not 100% sure this is what's happening but from my basic knowledge it looks like someone is poisoning my dns and in so doing so DOS's my network. I was using Google dns and the person was able to hijack it and switch it to sighroyal.com please don't visit this site as I'm 100% sure its malicious. I am using cyanogenmod7 on my HTC EVO 4g I edited my resolv.conf file I believe that's what its called, it let's you edit the dns name servers. I installed setdns and tried to change my dns but it stays at 8.8.8.8, does cyanogenmod7 for HTC EVO 4g use custom dns servers? Everytime I first log on packets always come from gtalk and I blocked all internet to it but still its able to communicate. Is the gtalk coming from me or my carrier? From my studies it seems gtalk is the source of my grief. What exactly is it and why does it always send packets when I first start the internet? I never get any replies here, I hope somebody can possibly help. Thank you
Click to expand...
Click to collapse
Hes probably DDosing you you can change your ip address it should and stop
Sent from my PC36100 using XDA App

I did change my ip and the poison dns logs are still there. It's just on one phone, the other phones are fine. Somehow they have me locked in. I've thought about every possible scenario and I can't think of how its being done.:l

Related

[Q] Specific website not loading?

So, I recently updated my ROM to ◄ Stock Plus ► v3.01 and while I'm not sure if this is what caused the problem I thought I'd mention it. Anyways, I've been trying to access "megaupload.com" and no matter how many times I try it just doesn't work. Any other website I try works, but not that one. I've tried restarting my phone, clearing everything in the android browser and toggling some of the settings the browser has (block pop-ups and the like). I'm at a dead end now and am just wondering if anyone else has had the same problem or knows how to fix it. Thanks!
Are you using any add blockers, or have you made any edits to the host file?
Also not that it should matter but have you tried changing your user agent string?
cmlusco said:
Are you using any add blockers, or have you made any edits to the host file?
Also not that it should matter but have you tried changing your user agent string?
Click to expand...
Click to collapse
I learn...
cmlusco said:
Are you using any add blockers, or have you made any edits to the host file?
Also not that it should matter but have you tried changing your user agent string?
Click to expand...
Click to collapse
I'm not using any ad blockers, and I haven't made any changes to the host file. Could those have been changed by the creator of the ROM? I did try changing the user agent string but had no luck there.
pcwolff said:
I'm not using any ad blockers, and I haven't made any changes to the host file. Could those have been changed by the creator of the ROM? I did try changing the user agent string but had no luck there.
Click to expand...
Click to collapse
They could have been but most devs leave that to the user. Does it happen on wifi and 3g? Could you have been baned by the site for something?
cmlusco said:
They could have been but most devs leave that to the user. Does it happen on wifi and 3g? Could you have been baned by the site for something?
Click to expand...
Click to collapse
Just tried it on WiFi and it works fine, 3g still doesn't however. And I don't think megaupload ever bans people as far as I know.
I might try restoring to another ROM just to see if that's causing the problem.
pcwolff said:
Just tried it on WiFi and it works fine, 3g still doesn't however. And I don't think megaupload ever bans people as far as I know.
I might try restoring to another ROM just to see if that's causing the problem.
Click to expand...
Click to collapse
Well if you can connect thru wifi i would say verizon, or who ever your thru is somehow blocking it, but i have no clue why they would. Actually i just tried on 3g and it wont work either. Verizon is blocking it for some reason.
Oh, well that's that I suppose. Thanks for your help anyways!
That kind of makes me mad. I pay all that money for data, and i cant go to websites verizon decides is using to much data: BS
I just tried it too. Verizon must not want anyone uploading huge files, especially if you're grandfathered in to the unlimited data plan.
Sent from my ADR6300 using XDA App
There are a couple ways you might be able to get around this.
1. Install "Set DNS" (Free, android market)
2. Manually configure your DNS servers (requires terminal/CL knowledge, not sure if easily made permanent)
3. Set up a VPN. I have a personal server that I am running a VPN service on. This allows me to browse as if I'm on my personal LAN.
I'm running Stock+ v3.0 and Set DNS is working for me. I've just loaded megaupload.com over 3g by switching to google DNS servers (8.8.8.8 and 8.8.4.4).
lackskill said:
There are a couple ways you might be able to get around this.
1. Install "Set DNS" (Free, android market)
2. Manually configure your DNS servers (requires terminal/CL knowledge, not sure if easily made permanent)
3. Set up a VPN. I have a personal server that I am running a VPN service on. This allows me to browse as if I'm on my personal LAN.
I'm running Stock+ v3.0 and Set DNS is working for me. I've just loaded megaupload.com over 3g by switching to google DNS servers (8.8.8.8 and 8.8.4.4).
Click to expand...
Click to collapse
Using set dns does work for allowing megaupload on 3g.

[Q] HTCdev login problems

Does anyone else have problems staying logged into htcdev? Every time I log in, the site says I've logged in but on redirecting me to another page, logs me out.
According to their FAQ,
"Our site requires a single IP authentication, and if you are behind a more complicated network that may alter your IP depending on loading, certain features may not work as intended. We suggest you connect to our site via a direction connection, such as via a home network. We are sorry about the inconvenience and thank you for your patience."
Thing is I am at home. Can anyone point me in the right direction? Since I can't really unlock my bootloader if I can't access htcdev...
I had troubles using Chrome browser. I actually had to use IE to get it to work properly. Have you tried using a different browser?
wnp_79 said:
I had troubles using Chrome browser. I actually had to use IE to get it to work properly. Have you tried using a different browser?
Click to expand...
Click to collapse
Yes, I've tried Chrome, Opera and IE, all have the same problem.
Hmmm. Perhaps a router issue. Have you tried bypassing your router and connecting directly to your modem with ethernet cable?
I did try accessing the site from my phone and got the same problem. Also my computer isn't near the router so I can't try that.
Did you use wifi when accessing the site using your phone? If so, try using 3G with your provider ...?
zenbloke said:
Did you use wifi when accessing the site using your phone? If so, try using 3G with your provider ...?
Click to expand...
Click to collapse
I used 3G, didn't work. Same problem.
i have another problem with HTCdev, after trying to log in many times, i managed to send the token. but they never send me back an email telling me how to unlock.
tatsit said:
i have another problem with HTCdev, after trying to log in many times, i managed to send the token. but they never send me back an email telling me how to unlock.
Click to expand...
Click to collapse
Have you tried clearing the browser cache?
Sent from my GT-P7510 using Tapatalk 2
Am I really the only one with this problem? I emailed HTC but they just said they would forward my comment to their technical department... Where I imagine it will be lost in bureaucratic hell for a few months...
Having the same issue. Keep saying I am not login in when I click the
"Unlock Bootloader" button but in fact I already login. I also emailed the
support but tell me to try some other time.
I take it no one has a solution?
Sent from my HTC One X using xda premium
ugh............
Everytime i log in, it will confirm my account before it boots me out (even if the account name is right), on every browser i tried..............
i'm getting tired of this..............
Mohammad Aliff said:
Everytime i log in, it will confirm my account before it boots me out (even if the account name is right), on every browser i tried..............
i'm getting tired of this..............
Click to expand...
Click to collapse
Yes, I'm having the same problem too - Chrome, Firefox, IE on Singtel broadband.
What isp are the people on who it isn't working for?
Sent from my HTC One X using xda app-developers app
Maybe you should make sure that your browser's cookie settings are correct. Also, if you are using a proxy, chances are, that cookies are not processed properly. Also, if your IP address constantly changes, it may cause problems logging in as well.
I'm having the same problem. I've tried Chrome, IE, Safari, Dolphin HD, etc. Nothing has worked. Its quite frustrating.
nope im havin the same prob. got hboot 1.58 so idk. get a message sayin " indicates hboot update required"
HTC
Uziel126 said:
Am I really the only one with this problem? I emailed HTC but they just said they would forward my comment to their technical department... Where I imagine it will be lost in bureaucratic hell for a few months...
Click to expand...
Click to collapse
I had the same exact problem when trying to login to HTC dev. It would kick me out every time i would login. I found out that the date on my computer was wrong so i changed it and boom, it worked! Make sure that your date and time is accurate and see if it works. Hope this helps
I have been trying this on multiple computers, multiple browsers, with correct time settings I might add...and to no avail. Maybe this is there way of telling us to piss off and not mod our phones...might possibly be the last HTC I buy honestly. Great phone, but I have no way to make it better after it has hit the 1 year mark and my warranty is up.

Can't view the forum at home.

The strange thing is when I try to see the forum at home - I get huge lags and the forum looks as if they do not connect the CSS styles. In Chrome, Mozilla, Opera is the same.
Switching on the XDA2010 theme doesn't help.
Can be a problem in the Internet provider? How can I fix this?
Might be a problem with our CDN provider. What do you get when you visit this url? http://debug-14.netdna-cdn.com/
Can't open it on home comp.
Sent from my GT-I9300 using xda app-developers app
Sounds like it might be a problem with your computer, firewall/router, or ISP. I can open that page fine. It says "You are hitting the NetDNA New York Datacenter"
BretonGirl said:
Sounds like it might be a problem with your computer, firewall/router, or ISP. I can open that page fine. It says "You are hitting the NetDNA New York Datacenter"
Click to expand...
Click to collapse
I get the same thing at work and phone. At home I'm not getting anything. And earlier (about a couple of weeks ago) forum worked fine.
So strange. I would understand if the forum is not open at all. But it opens, but very slowly and very crooked looks.
Something must have changed within your browser, router, or firewall settings. Since the rest of us are having no problems it has to be something in your computer. Flush your DNS, reboot your router, and check your firewall settings. Also try different browsers and see if you get the same results. You can also try OpenDNS, which will solve the problem if it lies with your ISP.
We've just changed CDN providers last night. OP, let us know if you still have this issue.
bitpushr said:
We've just changed CDN providers last night. OP, let us know if you still have this issue.
Click to expand...
Click to collapse
It's OK now! Big thanks!!!
The previous issue was being caused by some ISP Dns servers. Often these kinds of issues can be alleviated by switching your DNS to something better
pulser_g2 said:
The previous issue was being caused by some ISP Dns servers. Often these kinds of issues can be alleviated by switching your DNS to something better
Click to expand...
Click to collapse
I have gotten good results from Google's DNS servers. 8.8.8.8 and 8.8.4.4. We even point to them from my work instead of the ISP's DNS servers.
Level3's DNS servers are ok too, 4.2.2.2 and 4.2.2.1.

Installing ROMs breaks data because I have a static IP with Verizon?

I have had problems installing various ROMs on my Verizon GNex for a while now and it just occured to me that my phone might be somewhat uniques because it has a static ip from verizon. I was on with tech support today and when they took off the static ip and switched it to dhcp, it got the ip and worked fine, but when they put it back on static ip, the phone would not get an ip. They told me to go get another sim card, but the phone works fine if I restore it to locked, unrooted stock.
Basically, after I unlock & root stock and then install a ROM, my 4g data would not work. In settings, IP address is 'unavailable' where before the ROM, my static IP was there.
Anyone else have a static ip with verizon and have any issues or have any ideas why this might be an issue?
Old post about this problem: http://forum.xda-developers.com/showthread.php?t=1935957
My question is, why do you have static IP? For remote connections and such?
Static IP has to be manually set in the phone and changing ROMs is like changing operating systems on a PC, you'll lose network settings in doing so. I think....
Sent from my Galaxy Nexus using xda app-developers app
jimmyco2008 said:
My question is, why do you have static IP? For remote connections and such?
Static IP has to be manually set in the phone and changing ROMs is like changing operating systems on a PC, you'll lose network settings in doing so. I think....
Sent from my Galaxy Nexus using xda app-developers app
Click to expand...
Click to collapse
This is a work phone and our firewall is set to only allow a specific range of IPs in on port 25 for email. If I could manually set it I would, but I don't see where, I'm pretty sure it's pushed out from Verizon. Right now I have it working on Eclipse, but for whatever reason it just wont work on any others (JBSourcery, PA Android, Xenon, etc.), it's got to be something small/subtle that people just aren't thinking of. And since this isn't a widespread problem, having a static ip from Verizon is the only thing that makes my situation any different.
I just don't know enough about how the phone communicates to verizon to get the connection and static IP. Maybe certain APNs, RIL, etc. I tried making a backup of the /system/etc/apns-conf.xml file while the data was working. Then I installed a new ROM and overwrote it's apns-conf.xml and rebooted, but that didn't fix it.
I read somewhere that there is a bug that would make your Mac address change every time you flash a ROM, though that would affect Wi-Fi only but maybe other things too?
Swype'ed on my CM10 Galaxy Nexus
do you know how verizon is assigning the static IP? is it by ESN/MEID, MAC address or what?
Zepius said:
do you know how verizon is assigning the static IP? is it by ESN/MEID, MAC address or what?
Click to expand...
Click to collapse
I do not know, but none of those things should be changed by a ROM should they?
aldar5 said:
I do not know, but none of those things should be changed by a ROM should they?
Click to expand...
Click to collapse
the 2 i listed no... but as a previous poster mentioned, there was a bug that changed your mac address all the time
call verizon and ask them. they will know.
Zepius said:
the 2 i listed no... but as a previous poster mentioned, there was a bug that changed your mac address all the time
call verizon and ask them. they will know.
Click to expand...
Click to collapse
I called and they said it is by the ESN/MEID, the MAC can be anything, VZW doesn't care.
aldar5 said:
I called and they said it is by the ESN/MEID, the MAC can be anything, VZW doesn't care.
Click to expand...
Click to collapse
the only thing i can think of is the sim isnt properly getting authd to the network and therefore not giving you an IP
Zepius said:
the only thing i can think of is the sim isnt properly getting authd to the network and therefore not giving you an IP
Click to expand...
Click to collapse
Yeah, but what would various ROMs be doing that could effect that. It works again when I restore a working backup of stock or Eclipse, same sim, so it's got to be software right?
This is a really weird and frustrating issue.

[Q] VPN Client app?

I'm trying to search this forum, but it seems to be down right now.
I am just wondering what exactly the VPN client app on our phone could be used for. I have a general idea of what it is, and possibly some uses for it, but the uses I'm thinking of make me suprised that it comes stock on our phone.
Anyways, when I try to check the "about" on the app, it wants me to set up a password..... I'd just like to know more about it before I get all into creating passwords etc. Is anyone using this?
Thanks
I was able to get into the "about" section of the app, and then Google the version and dev of the app. So I have a better understanding of it. But just curious, is anyone using it?
Sent from my SGH-T889 using xda app-developers app
You use it to establish a secure connection to a server. Your data is encrypted between you and the server to keep it private and hide where you're going as well, since all traffic is through the VPN.
The client is useless to without server to connect it to. Always a very good idea to use a vpn if you're on a public open wifi hotspot.
I use OpenVPN to connect to GigaNews VPN Service.
Sent from my SGH-T889 using Tapatalk 2
distortedloop said:
You use it to establish a secure connection to a server. Your data is encrypted between you and the server to keep it private and hide where you're going as well, since all traffic is through the VPN.
The client is useless to without server to connect it to. Always a very good idea to use a vpn if you're on a public open wifi hotspot.
I use OpenVPN to connect to GigaNews VPN Service.
Sent from my SGH-T889 using Tapatalk 2
Click to expand...
Click to collapse
I was looking into some servers last night. In your opinion, is the only difference between "Free" and monthly fee servers with the size limit? Or is it also a security preference. Honestly, the reason I became aware of this was because of threads talking about TPB.
Is there a reason you don't use the app that came on the phone?

Categories

Resources