Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

屏蔽 type65 返回里面的 AAAA 记录 #616

Closed
ghost opened this issue Oct 1, 2020 · 6 comments
Closed

屏蔽 type65 返回里面的 AAAA 记录 #616

ghost opened this issue Oct 1, 2020 · 6 comments

Comments

@ghost
Copy link

ghost commented Oct 1, 2020

需求应用场景
参考 https://www.v2ex.com/t/712074#reply0
iOS14 会直接利用 type65 里面的 AAAA 记录请求最终服务

建议的方案
force-AAAA-SOA yes 时屏蔽 type65 里面的 AAAA

设备信息

  1. 设备信息(CPU,厂家)

  2. 固件信息

@fox85
Copy link

fox85 commented Oct 8, 2020

+1, 希望大佬能尽快添加屏蔽客户端发出的qtype 65的请求,目前我能想到的暂时性屏蔽方案是使用 iptables过滤特定qtype
ref: https://www.bortzmeyer.org/files/generate-netfilter-u32-dns-rule.py

@kousyougi
Copy link

+1, 希望大佬能尽快添加屏蔽客户端发出的qtype 65的请求,目前我能想到的暂时性屏蔽方案是使用 iptables过滤特定qtype
ref: https://www.bortzmeyer.org/files/generate-netfilter-u32-dns-rule.py

请问iptables 要怎么把 qtype 65挡掉?
我现在DNS被qtype 65 污染的问题感到很困扰,ipset几乎失效。

@fox85
Copy link

fox85 commented Nov 19, 2020

+1, 希望大佬能尽快添加屏蔽客户端发出的qtype 65的请求,目前我能想到的暂时性屏蔽方案是使用 iptables过滤特定qtype
ref: https://www.bortzmeyer.org/files/generate-netfilter-u32-dns-rule.py

请问iptables 要怎么把 qtype 65挡掉?
我现在DNS被qtype 65 污染的问题感到很困扰,ipset几乎失效。

iptables过滤效果有限制性,请使用另外一个dns软件
https://github.com/wolf-joe/ts-dns
可以过滤AAAA,qtype 65

@micturkey
Copy link

这几天也遇到了这个问题,主要是cloudflare加速的相关域名的type65解析问题,希望能够屏蔽

@pymumu
Copy link
Owner

pymumu commented Feb 17, 2022

最新代码试试:

force-qtype-SOA 65

@micturkey
Copy link

最新代码试试:

force-qtype-SOA 65

试了一下,效果很好👍

@pymumu pymumu closed this as completed Jun 9, 2022
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

4 participants