#DNS

Перевіряючи протермінованість доменів #Alfis #DNS, задався питанням: що є раціональним

  1. забілдитись, налаштувати резольвар та змайнити ключ, а потім домен(и) - на дифіцитній енергії
  2. миттєво і назавжди прописати ото усьо в /etc/hosts без ризику сходити не туди через протермінованість і сквотинг
JP Mensjpmens
2026-03-01

Most of us have gone to some effort to change the language we use in , for reasons, and RFC 9499 is now two years old.

I find it's time for the US American Red Hat company to stop using the term master and slave in their BIND configuration files

rfc-editor.org/rfc/rfc9499.html

a screenshot from RHEL 10 documentation showing "type slave;" on a zone as well as a directory "/var/named/slaves/.."
2026-02-28

Hello everyone, I'm looking to be #Fedihired. I'm looking for #Linux #DevOps work. I have 5 years software industry experience, and a B. Sc, in Computer Science. My resume is on my website, as is linked in my Bio. I'm excellent at #SelfHosting, cloud administration, all things networking, #Wireguard, and infrastructure design. I've been recently doing #infosec consulting; looking for more. I'm a #Canadian. I have lots of experience with technologies like #postgresql, #MariaDB, #nginx, #dns, #ssl, forums, #containers, #docker, etc. Also, recently automating things with #ansible. I'm posting this from my own #gotosocial instance. The #fediverse and #DataSovereignty are things I care about, and I give back to these things.
#Fedihire

2026-02-28

#TIL that *.example.com doesn't include example.com

#ItsAlwaysDNS #DNS

LΞX/NØVΛ 🇪🇺lexinova@cyberplace.social
2026-02-28

So on my codeberg i've added the first version of my ip block list, and port list to prevent unauthorized DNS on my network.

As more and more app integrate DOH in their code to bypass adblocking on the network level.

if you find other ip / port please open an issue.

also if you find DOH / DOT that is not on hagezi's DOH blocklist please report it to him.

#dns #adblock #pihole #ip #firewall #privacy #security #linux

Stéphane Bortzmeyerbortzmeyer@mastodon.gougere.fr
2026-02-28

"I think i should be able to come up with something that improves caching, reduces server load and eliminates some major security gaps while still keeping the decentralized aspect." (He talks about replacing the #DNS …)

(This was in a comment to blog.apnic.net/2026/02/25/towa)

Will he have more success than the guy who claimed he could rewrite curl in one week-end?

2026-02-27

@dnsoarc has released an update to dnscap with the following fixes:

Compatibility with GNU/Hurd

Parallel test execution issues

If you’re using dnscap in your DNS analysis workflow, you can grab the latest version here:

🔗 codeberg.org/DNS-OARC/dnscap/r

#dnscap #DNS #OpenSource #LoveDNS ^RP

JP Mensjpmens
2026-02-27

SIDN’s new open dashboard is called RootViz and shows real-time data from all RIPE Atlas probes.

rootviz.sidnlabs.nl

Blog post: sidnlabs.nl/en/news-and-blogs/

🆘Bill Cole 🇺🇦grumpybozo@toad.social
2026-02-27

Someday I will get through the first quarter of a year without having to direct a client to kb.isc.org/docs/aa-01640

2026 is not that year. 18 in a row. Had to explain it to marketoons for my prior employer as well, for both major brands.

I don’t *like* making their other vendors look like idiots but I do not really have a choice.

#Sysadminnery #DNS

HessenheldenHexangon
2026-02-27

Zur zeit nutze ich unter mit den eingebauten Blocklisten. Was mir aber auffällt dass es keine speziellen Soziale Listen existieren um z.B Facebook zu blockieren. Finde ich schade und nervt. Die Filterlisten als URL eingebunden funktionieren auch nicht wie ich es mag, kann aber auch sein das die Listen einfach nicht UnboundDNS kompatibel sind. Bin etwas genervt.

𝕂𝚞𝚋𝚒𝚔ℙ𝚒𝚡𝚎𝚕kubikpixel@chaos.social
2026-02-27

Ein IT-Rebell wehrt sich gegen Website-Sperren

Der Init7-Gründer Fredy Künzler kämpft mit seiner Firma wieder einmal vor Gericht. Dieses Mal wehrt er sich gegen Netzsperren, die ihm Staatsanwaltschaften aus der Westschweiz aufdrücken wollen.

🤨 wnti.ch/a/ein-it-rebell-wehrt-

#winti #init7 #schweiz #winterthur #chpol #websperre #swisscom #sunrise #dns #netztwerk #sperrung #web #redefreiheit

Recevoir un #spam par #SMS avec un lien pour faire du #phishing vers un nom de domaine dont la configuration #DNS n'a pas encore été propagée. 🤡

Afnicafnic
2026-02-27

🔔 Plus que quelques jours pour vous inscrire à la formation « Sécuriser son courrier électronique grâce au DNS avec DKIM, DMARC, SPF » (12–13 mars).

📚 2 jours pour maîtriser le DNS, comprendre les abus liés à l'email et déployer DKIM, DMARC, SPF.

Inscription afnic.fr/produits-services/for

Formation Sécuriser son courrier électronique grâce au DNS avec DKIM, DMARC, SPF
2026-02-27

Abusing .arpa: The TLD That Isn't Supposed to Host Anything

Threat actors have discovered a novel method to bypass security controls by abusing the .arpa top-level domain (TLD) in conjunction with IPv6 tunnels. They are exploiting a feature in DNS record management of certain providers to add IP address records for .arpa domains, allowing them to host phishing content on domains that should not resolve to an IP address. The phishing campaigns use spam emails impersonating major brands, with hyperlinked images leading to malicious websites through traffic distribution systems. This technique weaponizes trusted infrastructure essential for network operations, making it challenging for security tools to detect suspicious domains based on reputation, registration information, or policy blocklists.

Pulse ID: 69a163a059457844f52c2502
Pulse Link: otx.alienvault.com/pulse/69a16
Pulse Author: AlienVault
Created: 2026-02-27 09:28:00

Be advised, this data is unverified and should be considered preliminary. Always do further verification.

#CyberSecurity #DNS #Email #InfoSec #OTX #OpenThreatExchange #Phishing #RAT #Rust #Spam #bot #AlienVault

2026-02-27

New Dohdoor malware campaign targets education and health care

A malicious campaign by threat actor UAT-10027 has been targeting education and healthcare sectors in the United States since December 2025. The campaign utilizes a new backdoor called Dohdoor, which employs DNS-over-HTTPS for stealthy command-and-control communications and can download and execute payloads reflectively. The multi-stage attack chain likely begins with phishing emails, followed by PowerShell scripts, batch files, and DLL sideloading techniques. Dohdoor uses various evasion methods, including API obfuscation, encrypted communications, and EDR bypasses. The campaign's infrastructure leverages Cloudflare services for stealth. While some techniques overlap with North Korean APT groups, the targeting differs from their typical focus.

Pulse ID: 69a1649bf2952cacd54d98fb
Pulse Link: otx.alienvault.com/pulse/69a16
Pulse Author: AlienVault
Created: 2026-02-27 09:32:11

Be advised, this data is unverified and should be considered preliminary. Always do further verification.

#BackDoor #Cloud #CyberSecurity #DNS #EDR #Education #Email #HTTP #HTTPS #Healthcare #InfoSec #Korea #Malware #NorthKorea #OTX #OpenThreatExchange #Phishing #PowerShell #SideLoading #UnitedStates #bot #AlienVault

2026-02-27

Henry IV, Hotspur, Hal, and hallucinations

This article draws parallels between Shakespeare's Henry IV and modern cybersecurity challenges, particularly focusing on the adoption of AI. It emphasizes the importance of taking calculated risks, learning from failures, and surrounding oneself with knowledgeable peers. The piece also highlights a new campaign by UAT-10027 using the 'Dohdoor' backdoor, which leverages DNS-over-HTTPS for stealthy communications and targets education and healthcare sectors in the US. The author encourages security teams to stay vigilant, update detection tools, and monitor for unusual activities to combat sophisticated threats.

Pulse ID: 69a0dfeb9760c4f36290ec61
Pulse Link: otx.alienvault.com/pulse/69a0d
Pulse Author: AlienVault
Created: 2026-02-27 00:06:03

Be advised, this data is unverified and should be considered preliminary. Always do further verification.

#AWS #BackDoor #CyberSecurity #DNS #ELF #Edge #Education #HTTP #HTTPS #Healthcare #InfoSec #OTX #OpenThreatExchange #bot #AlienVault

2026-02-27

Und ich dachte, die Richter hätten sich in der Zwischenzeit etwas weitergebildet. 😒
wnti.ch/a/ein-it-rebell-wehrt- #init7 #dnssperren #dns #digitalegesellschaft #cccch #cccbasel

Doktor Overcomma :vepi:bobcromwell@dobbs.town
2026-02-26

@thomas_klopf @gurple Anything jamming Gilgamesh & Enkidu into an absurd setting would be of interest to me: an "Odd Couple" reboot, another "Starsky & Hutch" remake, "The Good, The Bad, The Heroic, and The Monstrous", "Dr Gilgamesh and Mr Enkidu", whatever. But again, as fortold by the prophets, it's DNS.
#DNS #ItsDNS #Mesopotamia

2026-02-26

Bah, evening spent messing with DoH only to realise that nginx won't proxy to a HTTP/2 only backend

(edit: OK as of about January v1.29.4 it will, but that version isn't going to end up in debian/raspbian repos until the next release)

#DoH #DNS #nginx

Client Info

Server: https://mastodon.social
Version: 2025.07
Repository: https://github.com/cyevgeniy/lmst