Jump to content

DNS-Rebind


kevwhite

Recommended Posts

Posted

Hi,

 

I am using a raspberry pi as a gateway for my CCTV to go through so that I can get my CCTV on my firestick network devices. However it is noticing it as a possible dns-rebind attack. Is there a way I could disable this? The domain in question should go to an internal network address of mine.

Sun Jan 31 13:49:48 2021 daemon.warn dnsmasq[3884]: possible DNS-rebind attack detected: *****{REMOVED}*****.mproxy.io

Thanks.

  • Administrators
Posted

Hey, welcome to the forum!

Does it actually work and is it just an entry in the log file? If it's not causing a problem then you can just ignore it. 

Posted

Hi Fraser - Already disabled

I'm watching the monocle log as i attempt to view my camera and its getting the request but its not bringing back the mproxy.io part which it should as that would forward it onto my internal IP.

Screenshot 2021-01-31 at 16.14.25.png

  • Administrators
Posted

Adblocker I believe is enabled by default so disable that, if that doesn't help could you disable QoS fully from the Congestion Control menu please? That's the other thing that could be interfering that you could adjust, otherwise I'll need to pass it on to the devs I think.

  • Administrators
Posted

Just to clarify, is the Pi connected to the R2 and on the R2 you've given it the DNS address of the Pi? If so make a Traffic Controller rule to allow ALL traffic to the Pi and see if that helps please.

Posted

The PI is connected to the R2. Are you meaning changing the whole DNS server for the R2 to the PI IP?

  • Administrators
Posted

Ahh I see thank you for that. Okay so I can probably get a developer to connect to your router and add an exception for that but in the meantime try enabling Adblocker and adding a whitelist entry for *.mproxy.io and see if that works. If not enable remote support in WAN settings. What is your exact physical setup - what is the R2 connected to, a pure modem or modem/router?

Posted

Thanks ill try that. Its connected into a 

300Mbps Wireless N USB VDSL/ADSL Modem Router

Model No. TD-W9970

 

I'll enable remote support aswell let me know anything else you need.

  • Administrators
Posted

Okay and have you changed any settings on that router to ensure all traffic passes straight through to the R2, modem, bridge mode or DMZ for example?

  • Administrators
Posted

Does it still output WiFi like that? If so can you put it into just modem mode and if not take the WAN IP from the R2 System Information page and enter it into the DMZ on the modem please.

Posted

Done and retested - still the same

 

 

Sun Jan 31 22:59:39 2021 daemon.warn dnsmasq[3884]: possible DNS-rebind attack detected: 28c83855-ed3e-44aa-b61b-fcd897bc16fa.mproxy.io

Sun Jan 31 22:59:37 2021 daemon.warn dnsmasq[3884]: possible DNS-rebind attack detected: 28c83855-ed3e-44aa-b61b-fcd897bc16fa.mproxy.io

Sun Jan 31 22:59:36 2021 daemon.warn dnsmasq[3884]: possible DNS-rebind attack detected: 28c83855-ed3e-44aa-b61b-fcd897bc16fa.mproxy.io

  • Administrators
Posted

Sorry I should have been clear, that was just to make you accessible for the dev to have a look, so assuming you've enabled remote tech support I'll ask a dev to try and do this tomorrow.

  • Administrators
Posted

I've chased the dev and it is something they can do for you so just waiting on them to get it done. Once they have I'll let you know.

Archived

This topic is now archived and is closed to further replies.

×
×
  • Create New...