Some Fritz!Box modems might have been hijacked
crapts.org
crapts.org
Expected result, resolved by the box itself:
$ host fritz.box.
fritz.box has address 192.168.178.1
fritz.box has IPv6 address fd00::e72:74ff:fece:6656
fritz.box has IPv6 address 2a02:908:616:a8c0:e72:74ff:fece:6656
Result if for some reason, DNS resolution fails on the box (e.g. you're not connected to your own network, someone disabled the resolver on the box, someone configured a non-box DNS on your machine): $ host fritz.box.
fritz.box has address 45.76.93.104
fritz.box has IPv6 address 2001:19f0:6c00:1b0e:5400:4ff:fecd:7828https://duckduckgo.com./ - blank page
https://www.google.com./ - 301 redirect to non-trailing-dot
https://www.amazon.com./ - works
But even "works" means that the page makes lots of requests to other subdomains etc which do not have the trailing dot, so are still vulnerable for DNS hijack if you have search domains set on your system. So while using domains with a trailing dot is a strongly good idea for calling APIs, etc. it is not a practical solution for the end user with a web browser.
So this shouldn't really be an issue for most people, but highlights once again that you should never ever use a domain in your infrastructure that you do not own or at the very least use one of the suffixes from https://www.rfc-editor.org/rfc/rfc6762#appendix-G
It's Monday morning here and I just started the laptop. It's still doing lookups on fritz.box.
Does anyone know where and why Windows is requesting this?
Fritz box allows you to capture traffic towards the ISP too and there I never see such a suffix query in either case. So I assume the fritz resolver directly responds to those.
That does not really match the behavior described in the OP but I would be very surprised if the behavior described there wouldn't have lead to a big outcry much earlier.
I love my wrt54gl as much as the next guy, but I hate having two devices to connect to the internet instead of just one.
For OpenBSD on Orange France FTTH: https://lafibre.info/remplacer-livebox/remplacer-sa-livebox-... or https://try.popho.be/securing-home2.html
The last time I searched for open hardware, even the implementations running Linux on a desktop PC with a caux adapter were not DOCSIS 3.X compatible.
The companies that multiplex the signal down the cables keep updating their standards, both a blessing (for speed) and a curse for maintained code
VDSL2 Modem with Kernel support. With OpenWRT and mainline Kernel its able to push roughly 100Mbit/s over WAN.
I wonder if I can find a device not fully upgraded
"the DHCP server on these modems hands out leases with the DNS suffix fritz.box, which means that domains in DNS requests are appended with the suffix. Unfortunately, this setting cannot be modified...
...The only proper way to resolve this matter in my opinion is to disable the DNS suffix by default. So far there is no indication that AVM is planning to enable this option in the near future."
I query google.com and get google.com.fritz.box every fucking time? Shit.
If your upstream recursive resolver doesn't do QNAME minimization, then yes.
Edit: I stand corrected, see downthread
Edit: actually, I'm wrong, "NS? com.fritz.box" returns a NOERROR + fritz.box SOA instead of a NXDOMAIN, which causes QNAME minimization to make the full query, which returns an A. QNAME minimization indeed doesn't actually help.
com.fritz.box. 3514 IN AAAA 2001:19f0:6c00:1b0e:5400:4ff:fecd:7828
com.fritz.box. 3600 IN A 45.76.93.104
Server: fritz.box Address: fd00::[etc]
Non-authoritative answer: Name: google.com Addresses: 2a00:1450:4001:80b::200e 172.217.19.78
So that's still a mess, but no mess of "rip apart the entire home network right now".
1: https://www.freedesktop.org/software/systemd/man/latest/syst...
If there's a list of falsehoods programmers believe(d) about DNS, "that TLD will never ever resolve, not ever" should be somewhere near the top.
There are domains that will never be sold, but none of them are very sexy. RFC2606+RFC6761 list .example, .invalid, .localhost, and .test, but none of those are practical and some come with certain behavioural expectations. There's .home.arpa as well (RFC8375), which may be the most technically correct TLD to use for these domains, but also is one of the least marketable ones.
Then there are the IDN test TLDs (إختبار, آزمایشی, 测试, 測試, испытание, परीक्षा, δοκιμή, 테스트, טעסט, テスト, பரிட்சை, let's hope my browser+HN did the RTL mixing right) that also probably won't resolve, but most users probably won't be able to enter any of those websites.
AVM could've offered mDNS (if they don't already) and just use .local.
- Does configuring a custom DNS server (like Cloudflare one) on your local computers solve it?
- On the reddit linked at the bottom of the article, someone mentions you can easily use this tool https://www.mengelke.de/Projekte/FritzBox-JSTool to edit the configuration file and change the domain. If that's true, why is the article claiming it's impossible to change?
No. If anything, that'd make it worse. The issue reported in TFA is that Fritz!Boxes by default resolve the domain `fritz.box` to themselves for their admin interface, even if that domain has been registered on the public internet by someone else. If you configure cloudflare, you'll prevent that, which will _always_ get you the potentially attacker controlled DNS results.
If you have a local machine called "myshare" and you mistype "myhsare", it may resolve to the attacker's machine.
(PS. I am the author. The article is my understanding of the situation but if I'm wrong on some parts please correct me.)
we're only talking about the cost of a commodity modem, so buy a new modem, disconnect old is a potential solution
Switching to something else is not as easy as buying a new modem for most normal people.
Setup a local DHCP server, and don't set the fritz.box search domain.
Ensure that DNS-over-HTTP (DoH) is enabled where it can be.
Set upstream DNS servers that block malware, such as 1.1.1.2 or NextDNS
Delete "fritz.box" from the domain search list in DNS settings.
Educate your parents to be cautious about directly typing domain names or searching from the OmniBox.
https://blog.cloudflare.com/introducing-1-1-1-1-for-families...
There is a class of internet users that doesn't use a search engine, and instead types things like "usedcarsdetroit.com" in the URL bar until they find something they want.
And there is the class that starts with a single word search like "cars", which can't go straight to Google. It instead has to see if "cars.fritz.box" exists, because perhaps there's a server called "cars" on your network.
And god forbid that your parent types "bankofmerica.com" instead of using a bookmark or their smart phone app.
First it was not clicking links. Now it's not typing addresses?
Jesus Bloody Christ my dude, maybe it really was a mistake to make sand think.
I am running my own DNS server and configured the fritz.box zone.
Very unprofessional of the vendor to assign a public domain. Good reminder to always use https://www.iana.org/domains/reserved and maybe https://www.theregister.com/2018/02/12/icann_corp_home_mail_...
They should just release a firmware update that replaces the domain suffix and ultimately to make it configurable.
I'm surprised that this company didn't realise that this was problematic before this happened. Also, if the response in the article is actually their only one so far, that's a "I'll never touch this company again" response. If they deal with it properly then it's just a bug.
To me the root problem still seems to be that we use FQDNs virtually nowhere even though that is the intention. Linux and macOS not applying the suffix for multiple labels is just an implementation detail. Maybe we should standardise the behaviour and maybe it’s better to turn it around: consider everything an FQDN and provide an escape mechanism (e.g. an xx-- prefix or an escape TLD)?
If I were someone trying to spy on specific users, or collecting data maliciously, I would host this HTML on my own server to confuse journalists.
Currently, every subdomain (up to any level, as far as I can tell) resolves to an IPv4 and an IPv6 address. I doubt ICANN would do this for seized domains.
For those who know they can use their own modems, sufficient information must be available, but only a sliver of the people with AVM modems will have that kind of knowledge.
But this is something that ask the non-obvious things will get explained to you if you walk into a MediaMarkt to where modern routers are and queue in line for the area's sales person to get to you and tell you what to buy, and how to get your hands on the relevant access credentials/how to get the new one to connect to the ISP. You're forgetting that most installs of non-ISP-provided moderns for residential Internet are set up by the tech person of the household who quite possibly never heard of what a NAS is and why they may want one. Often the only paper manual thing in the box is literally the quick start guide that a motivated person who has what could be called "common sense" on treatment of/interaction with computing equipment. You know, the person who knows to check the plugs because they don't consider themselves above it but do know that it's one of if not the first thing they are asked if they can support.
https://de.wikipedia.org/wiki/Routerzwang#Rechtslage_in_Deut...
Because I had *.fritz.box DNS blocked on my Cloudflare Zero Trust Gateway, these were returning NXDOMAIN, causing the NAS to fail during some operations (checking for software and packages updates, backups).
I've disabled the option "Apply the domain name provided by DHCP server" (Network | DNS | Advanced) and the NAS stopped these.
Now, this is a worry because that option is checked by default so how many Synology NAS could be trying to connect to these sub-domains? What if the block is removed and the new owner can actually create some of these?
More details: https://www.geekzone.co.nz/forums.asp?forumid=66&topicid=312...
"You can also specify a local domain name (like fritz.box) to ensure queries to devices ending in your local domain name will not leave your network, however, this is optional."
This is in the Conditional Forwarding section to the Pi-Hole, so I assume it's OK.
It should be enough to fix that issue
Should I keep it? What are uses cases for such a 'misguided' domain? I thought about putting a blog on it but fear it’d get flagged as malicious left and right. It’d look odd to say the least.
If I don’t renew, scammers might get their hands on the domain.
Anyone who has invoice.zip on an email should see that as a clickable link if the url detection is right
Then for example you put a file on / of your domain that downloads a malicious .zip file
See where this is going?
And I don’t buy into .zip being made part of automatic URL detection in tools, for all the illegitimate reasons it’ll be used for. Vendors of email clients, messengers and chat applications tend to stick to a core of well-known TLDs.
'Course, that could still backfire this way if someone establishes the Republic of Boxsylvania and won't accept "bx". (Also not great if we enter into an era of unprecedented national mergers, splits, and renames.)
If I ping "google.com" It just queries google.com If I ping a domain I have never visited it just does a query for that domain.
It only appends .fritz.box if I, e.g. only ping "google".
So maybe they fixed it? I also changed quite a lot of settings throughout the years.
HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows NT\DNSClient\AppendToMultiLabelName
[default value - 0 (Do not Append Suffix)]
which resolver built into Windows (DNS Client) respects.nslookup contains its own DNS resolver and does not rely on the resolver built into the operating system. The DNS (multi-label) query packets sent by the nslookup tool will append the domains listed in the suffix search order (or primary DNS suffix if the list is empty) irrespective of that registry key.
In summary, don't use nslookup to try to get insight into what actually happens when apps/services try to resolve names. ping is probably a better bet, at least it uses Windows resolver which honours the above registry key.
The Domain Name you have entered is not available. It has been taken down as a result of dispute resolution proceedings pursuant to the Uniform Rapid Suspension System (URS).
The fritz.box name servers also point to URS[2] name servers:
Name Server: ursns1.viagenie.ca
Name Server: ursns2.viagenie.ca
[1] https://web.archive.org/web/20240305162200/https://fritz.box... > nslookup google.com
Server: fritz.box
Address: fd00::[redacted]
Non-authoritative answer:
Name: google.com
Addresses: 2a00:1450:4001:828::200e
142.250.181.238
Update: the connection does have the DNS suffix, so according to the superuser answer linked in OP (which is the first result when looking up what a DNS suffix is), it should get appended to lookups on windows, but it looks like it isn't in my case. > ipconfig
[...]
Connection-specific DNS Suffix . : fritz.box [DHCPv4]
UseDNS=false
[DHCPv6]
UseDNS=false
But you will have to type the IP of the fritz box when you want to access the admin interface.I am no expert in this subject
https://newgtlds.icann.org/en/program-status/sunrise-claims-...
But it seems that they had
Trademark Claims Period: 13 September 2023 to 17 January 2024
To be fair, .box domains didn't have that much noise attached to them and 4 months is a relatively short period, but if this possible vulnerability had known then it's a little more negligent.
Best case scenario for them seem to be that they pay an undisclosed amount to a "random" that got lucky and bought that domain.
I find it interesting how a decision that may have looked totally innoxious something like 15 years before, was not future proof enough, I for one back then would not have imagined that ICANN would start registering every single TLD under the sun.
That on top of the fact that my linuxes won't use the search domain unless explicitly asked for with a single-label DNS makes this a lot less scary.
PS C:\Users\Marco> nslookup google.com
Server: UnKnown
Address: 192.168.0.200
Non-authoritative answer:
Name: google.com.fritz.box
Addresses: 2001:19f0:6c00:1b0e:5400:4ff:fecd:7828
45.76.93.104
How is this not bad?
Other option, run your own DNS + DHCP stack, a pihole is pretty turn-key if you have a straight forward network.
I tried to do that a few months ago too, as I'm already running a homelab server 24/7, but couldn't find any cards supporting vdsl nor cable
Or do you mean just as a wan connection/router? In that case... Sure, you can do that. I just don't see the value in that, personally.
When I had DSL (and later DOCSIS), I just bought my own modems that weren't routers, and used ethernet to connect the Linux router (a raspberry pi 3 originally, yes the DSL was so slow it wasn't a bottleneck!). It was economical because Time Warner charged me something like $5/month to use their modem.
There's a lot of reasons I like having a Linux router, a short list:
* I have 10G internet from Sonic, in 2020 building a small Linux machine with ixgbe cards was cheaper than any commercially available 10G router with as many ports as I needed (4+). I get line rate through it, no problem.
* It runs an open source NAT implementation that is actually correct (although this is less of a problem with commercial routers now than it was back in the day...). Sadly, I don't have IPv6, but the same argument would apply there.
* I can run whatever DHCP server implementation I want.
* No web GUIs: I SSH to the thing and write config files.
* If it blows up, it's just Linux, and all the config files are in git: any machine will do, I don't have to worry about some commercial product disappearing and forcing me to waste an afternoon reinventing the wheel.
* I can build and run recent vanilla kernels with all the hardening options enabled. A Linux router spends 99% of its time in the kernel.
* The machine is actually fast enough to scan 10G traffic at line rate in software when I want to do that (it's doing all the routing in software, after all).
It's really easy, I'd estimate I spend 1-2 hours a year maintaining it.
If you want to run BitTorrent and game at the same time, the router can e.g. limit the BitTorrent flows to something below the minimum guaranteed TX rate, so you know there's no queueing on the modem.
Last time I had cable was on Time Warner in the US. It was interesting because they didn't do the token bucket style ratelimiting I've seen from every ISP I've had since: they'd play games with TCP to try and slow down big flows instead. It was weird.
So I wrote a little program that transferred files by sending the data over UDP at a constant rate disregarding loss, then reconciling lost bits later over TCP. That allowed me to get almost double the upload bandwidth I was theoretically paying for at the time!
But on Verizon FIOS, it didn't work at all, because they really limit bandwidth at the packet level instead of trying to trick TCP into slowing down.
Guess they didn't expect a .box-tld
FWIW is it not easy for Fritz to remotely change the default DNS of their devices, similar to what Virgin/Sky/Vodafone modems have been doing for the past decade?
Fritz used to be open source, but they're not since also around a decade, so I would think it would be easy to for them to have a backdoor to all their modems like every other company does.
The fact is that currently DNS requests are forwarded to an unknown entity. The matter is not resolved yet and there is no guarantuee it will be resolved. Imo there's no FUD here. I will happily correct any factual errors ofcourse.
Also, this should be worth an email to abuse@namesilo.com, no?
(PS. I am the author.)