Level 3 are now hijacking failed DNS requests for ad revenue on 4.2.2.x
james.bertelson.me
james.bertelson.me
Here's a blog post with some background on these servers: http://www.tummy.com/articles/famous-dns-server/
"[...] DNS infrastructure is largely split into two types; open (public) and closed (private). Open DNS is provided by companies like OpenDNS, Google and Level 3. You can use it wherever you are on the Internet with no restrictions or authentication required."
- Mark Taylor, VP at Level3
http://blog.level3.com/level-3-network/a-flawed-study-of-cdn...
I can't find any cite where anyone else who I would consider a reliable source in the DNS world (Vixie, &c) repeat this claim. To the contrary, Level 3 is often grouped with Google, OpenDNS and others in discussions of open public resolvers [1][2][3], and those in the know never seem to speak up and say otherwise in these discussions.
That being said, I have absolutely no personal knowledge on any of this.
[1] http://www.maawg.org/system/files/Fergie_DNS_Open_Resolver_M...
[2] http://markmail.org/message/gh7f2wvfbn5mpvuq
[3] http://www.circleid.com/posts/87143_dns_not_a_guessing_game/...
So no, definitely not altruistic.
"We built Google Public DNS to make the web faster and to retain as little information about usage as we could, while still being able to detect and fix problems. Google Public DNS does not permanently store personally identifiable information."
What is the test for "intended for widespread public use"?
If a server is configured to accept queries from any IP address, can we conclude anything about "intent"?
If the server admin does nothing to stop widespread public use (which is trivial to do of course), can we conclude anything about intent?
Is there some other clue we need to look for?
Under your reasoning, it's "reasonable" to provide open resolvers and hijack NXDOMAIN responses, so long as there is no "intent" for widespread public use.
Interesting.
Having said that, 8.8.8.8, Google DNS, has been planted firmly in my memory as my go to "is this machine up?" IP.
EDIT: By the way, this is the actual company operating the "service" behind the scenes for Level 3 http://www.xerocole.com/searchguide/
But if they are being jerks rather than just being thoughtless, then maybe that isn't enough. In which case, my fallback answer is "bad PR". It would have been easier for them just to deny service to anybody they didn't want to serve. They went to a lot of trouble break something in a profitable way. To me, that says they might not be a trustworthy vendor, and thousands of nerds are now aware of that.
Inserting an ad where an error should be is detrimental because the implementation often break standards endpoint and intermediate apps depend on (http code, DNS query answer/s). An app that was expecting just JSON now dies in some horrible (maybe silent or end-user confusing stacktrace) way.
Then the cache is broken. Obviously not getting a response is going to confuse things, but there is a way to send back REFUSED without giving a positive or negative answer.
Take HN's authoritative DNS server and ask it for information on yahoo.com.
$ dig @sue.ns.cloudflare.com. yahoo.com.
...
;; ->>HEADER<<- opcode: QUERY, status: REFUSED, id: 28595
...
They are perfectly right to refuse service to non-customers, but I think it's bad network practice (legally right or not) to return incorrect information.77.109.138.45 (Ports: 53, 110; DNSSEC), 77.109.139.29 (Ports: 53, 110; DNSSEC) and 87.118.85.241 (Ports: 53, 110; DNSSEC).
https://www.privacyfoundation.ch/de/service/server.html
(The Swiss Privacy Foundation operates Tor exit nodes too.)
I've set my machine to use those three IP addresses as the DNS servers, is there something else I'm missing? Thanks!
'DNSSEC' means DNSSEC is supported by the server if your resolver can use it - it's a digital signature regime to prevent DNS forgery (disclaimer: look up criticisms of it as well as selling points).
Does anyone know if actual Level3 customers see this page, or is it only for off-network requests? Up until the end of last year, my employer had a Level3 internet connection and we legitimately used 4.2.2.1 as our DNS recursive resolver. I'd be pretty pissed if they returned spammy results to their customers, but to non-customers, well, I don't care: That's what you get. Use a DNS server that somebody says you're allowed to (8.8.8.8, maybe)
Not only does this give you known-good DNS resolution, but you can also enable DNSSEC validation and be fairly confident that it'll actually do its job in preventing your local machine from resolving poisoned zones.
1) Most DNS entries these days seem to have very short TTLs
2) Occasionally the recursive queries would fail
Doesn't seem too out of character, if they're returning this for actual customers, from the company that most likely allowed the US government to tap into Google and Yahoo's fiber lines.
http://www.nytimes.com/2013/11/26/technology/a-peephole-for-...
Since the 1970s the CIA has been installing taps on undersea cables using specialized submarines. This is well documented, and it is well known that the NSA prefers to use methods that involve the least amount of interaction from uncleared individuals even if it is at a much greater expense.
Is the accusation that Level 3 has a 'black room' agreement with the NSA totally out of the realm of possibility? We know AT&T has such an agreement after Mark Klein exposed Room 641A years ago.
A cool thing about OpenNIC is that they offer alternative TLDs that aren't part of ICANN's gTLDs. Also, the owners of the public servers strive to be as open as possible with their policies and features, such as no logging or using DNSCrypt. One of them even offers DNS level ad blocking, though I don't like it because I prefer the internet at its purest form and that policy doesn't seem to flow well with their anti-censorship mantra.
I'm not a Level 3 customer in a any way and I'm on a German VDSL connection provided by Deutsche Telekom. And here the Level 3 resolvers still return normal NXDOMAIN answers:
; <<>> DiG 9.8.3-P1 <<>> thisprobablydoesntexist.com @4.2.2.2
;; global options: +cmd
;; Got answer:
;; ->>HEADER<<- opcode: QUERY, status: NXDOMAIN, id: 44948
;; flags: qr rd ra; QUERY: 1, ANSWER: 0, AUTHORITY: 1, ADDITIONAL: 0 ; <<>> DiG 9.8.3-P1 <<>> nxdomain.horse @4.2.2.
;; global options: +cmd
;; Got answer:
;; ->>HEADER<<- opcode: QUERY, status: NXDOMAIN, id: 58067
;; flags: qr rd ra; QUERY: 1, ANSWER: 0, AUTHORITY: 1, ADDITIONAL: 0As a result quite a number of networks "hijack" 4.2.2.0/24 and route it locally to their own resolvers.
Here's what I see from my DigitalOcean droplet.
root@derpy:~# traceroute -I 4.2.2.1 traceroute to 4.2.2.1 (4.2.2.1), 30 hops max, 60 byte packets 1 198.199.122.1 (198.199.122.1) 12.055 ms 12.123 ms 12.314 ms 2 xe-10-3-3-100.edge3.Newark1.Level3.net (4.28.6.69) 0.948 ms 0.959 ms 0.959 ms 3 ae-31-51.ebr1.Newark1.Level3.net (4.69.156.30) 1.396 ms 1.477 ms 1.478 ms 4 ae-10-10.ebr2.NewYork1.Level3.net (4.69.132.97) 1.530 ms 1.630 ms 1.659 ms 5 ae-62-62.csw1.NewYork1.Level3.net (4.69.148.34) 1.465 ms ae-82-82.csw3.NewYork1.Level3.net (4.69.148.42) 1.464 ms ae-62-62.csw1.NewYork1.Level3.net (4.69.148.34) 1.390 ms 6 ae-1-60.edge2.NewYork1.Level3.net (4.69.155.16) 1.363 ms 1.389 ms 1.395 ms 7 a.resolvers.level3.net (4.2.2.1) 1.456 ms 1.466 ms 1.421 ms
You act as if most ISP support actually admits to problems on their own network and/or that troubleshooters have access to this information.
He must not realize that even if the DNS server was working correctly, the original request that should result in NXDOMAIN is also passed in clear text over the wire and naturally potentially logged by the DNS server. The lesson is not to rely on DNS security. Your ISP can see what servers (IPs) you communicate with anyway.
The Example Net Web Helper has been enabled to provide helpful searches from web address errors. You entered an unknown name that the Example Net service used to present site suggestions which you may find useful. Clicking any of these suggestions provides you with Yahoo! search results, which may include relevant sponsored links. Why should I use this?
The Example Net Web Helper makes finding what you are looking for easier and more convenient. The service uses the entered non-existing website name to determine useful search results. Often, you will see a desired website or page that meets your needs. Do you track my Internet usage?
No. The Example Net Web Helper simply redirects queries to non-existing domain names to a useful search results page instead of a cryptic error message page or browser-defined page.
The "Example Net" huh?
That said, we run our own recursive servers and don't rely on Level3's.
http://dns.comcast.net/index.php/help#faq2
Now no customers from Comcast suffer this.
... JavaScript and HTML injection when you reach a cap limit in a throttled market or when you get a cease and desist for pirating, however, is another matter.
Still, I am guilty of using them too.
Not really thrilled with the idea of using Google DNS.
You can use your own dns server. Just install a recursive dns server on your own network like https://www.powerdns.com/recursor.html or https://unbound.net/
Not a good first sign.
Perhaps L3 themselves have a lot of stuff both within and outside their subnet that depends on these servers behaving correctly.
Alternatively, run your own recursive resolver and cache, it's worth it.