What's new

possible DNS-rebind attack: secure.base.shared.live.com.akadns.net

  • SNBForums Code of Conduct

    SNBForums is a community for everyone, no matter what their level of experience.

    Please be tolerant and patient of others, especially newcomers. We are all here to share and learn!

    The rules are simple: Be patient, be nice, be helpful or be gone!

randomName

Very Senior Member
Hi there, I keep getting this spammed in my logs. Anyone have any idea what that's about?

Thanks
 
That record returns 127.0.0.1, which will trigger dnsmasq's rebind protection, so it's working as expected.
 
Do you use any Firewall?

I was using the router firewall + Skynet, but my firmware was going corrupt as my WAN kept disconnecting from y ISP. It disconnected 5 times today so I had to reinstall the firmware, not just reset. I think there might be something going on with either my USB 3.0 port on my 86U or my USB drive is junk so I haven't reinstalled Skynet just yet as I'm seeing how it behaves the next 24hrs to trouble shoot things. Whether or not it was causing the issue I'm not sure, though.
 
I was using the router firewall + Skynet, but my firmware was going corrupt as my WAN kept disconnecting from y ISP. It disconnected 5 times today so I had to reinstall the firmware, not just reset. I think there might be something going on with either my USB 3.0 port on my 86U or my USB drive is junk so I haven't reinstalled Skynet just yet as I'm seeing how it behaves the next 24hrs to trouble shoot things. Whether or not it was causing the issue I'm not sure, though.

Kill those firewalls and test it. I think this is the firewall issue.
 
Kill those firewalls and test it. I think this is the firewall issue.

As far as I know the reinstall of the firmware has fixed the WAN disconnect issue. It seems to be stable so far, today.

@ColinTaylor
As far as the issue about the rebind, I don't have office 365 installed. It's a fresh Windows 10 install, though.
 
@ColinTaylor
As far as the issue about the rebind, I don't have office 365 installed. It's a fresh Windows 10 install, though.
As it's just a Microsoft general purpose "live.com" CDN it's used by other products as well, e.g. Skype, Azure, etc.

If you want to suppress the messages just add the URL to your local blacklist.
 
Or whitelist it with dnsmasq. Example dnsmasq.conf.add:

Code:
rebind-domain-ok=/mcafee.com/amazonmusiclocal.com/

replace my domains with akadns.net if you trust it.
 

Similar threads

Latest threads

Sign Up For SNBForums Daily Digest

Get an update of what's new every day delivered to your mailbox. Sign up here!
Top