Skip to content
Discussion options

You must be logged in to vote

Yes, this is textbook transparent DNS interception, and the sinkhole address gives it away.

10.10.34.35 is not a random private IP. 10.10.34.34/.35/.36 are the well-known addresses Iranian ISPs return for filtered domains — they're the block-page hosts. Getting that back from 8.8.8.8, 1.1.1.1 and 9.9.9.9 simultaneously doesn't mean three independent resolvers agree; it means none of your queries ever reached them.

What's actually happening

Plain DNS is UDP/53 in cleartext. A middlebox on the path doesn't need to be your resolver — it watches for UDP/53, and when it sees a query for a filtered name it injects a forged response. The forged packet arrives before the real one from Google/Clou…

Replies: 2 comments 2 replies

Comment options

You must be logged in to vote
1 reply
@AlienSarlak
Comment options

Answer selected by AlienSarlak
Comment options

You must be logged in to vote
1 reply
@AlienSarlak
Comment options

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Category
Q&A
Labels
None yet
3 participants