Hi
Installed the lastest firmware (380.58) and erased nvram through SSH.
nslookups from console does not resolve into expected domains (except for IPv6). For example google.com does not resolve into a 1e100.net domain (which it does outside my network).
Tried changing DNS to both 8.8.8.8 and to openDNS. Restarted dnsmasq. Even set cache to 0 (disabled it).
The wrong domains are still resolved.
Here is a nslookup dump
Name: www.google.com
Address 1: 2a00:1450:400f:805::2004 arn06s07-in-x04.1e100.net
Address 2: 83.140.66.45 83.140.66.45.biz.sta.port80.se
Address 3: 83.140.66.57 83.140.66.57.biz.sta.port80.se
Address 4: 83.140.66.42 83.140.66.42.biz.sta.port80.se
Address 5: 83.140.66.53 83.140.66.53.biz.sta.port80.se
Address 6: 83.140.66.34 83.140.66.34.biz.sta.port80.se
Address 7: 83.140.66.38 83.140.66.38.biz.sta.port80.se
Address 8: 83.140.66.29 83.140.66.29.biz.sta.port80.se
Address 9: 83.140.66.15 83.140.66.15.biz.sta.port80.se
Address 10: 83.140.66.59 83.140.66.59.biz.sta.port80.se
Address 11: 83.140.66.30 83.140.66.30.biz.sta.port80.se
Address 12: 83.140.66.27 83.140.66.27.biz.sta.port80.se
Address 13: 83.140.66.23 83.140.66.23.biz.sta.port80.se
Address 14: 83.140.66.44 83.140.66.44.biz.sta.port80.se
Address 15: 83.140.66.19 83.140.66.19.biz.sta.port80.se
Address 16: 83.140.66.49 83.140.66.49.biz.sta.port80.se
So it does not seem to be DNS-poisoning but rather a more elaborate exploit kit.
I should add that I'm more of a newb than a pro on these matters.
Please advise...
Thanks
Installed the lastest firmware (380.58) and erased nvram through SSH.
nslookups from console does not resolve into expected domains (except for IPv6). For example google.com does not resolve into a 1e100.net domain (which it does outside my network).
Tried changing DNS to both 8.8.8.8 and to openDNS. Restarted dnsmasq. Even set cache to 0 (disabled it).
The wrong domains are still resolved.
Here is a nslookup dump
Name: www.google.com
Address 1: 2a00:1450:400f:805::2004 arn06s07-in-x04.1e100.net
Address 2: 83.140.66.45 83.140.66.45.biz.sta.port80.se
Address 3: 83.140.66.57 83.140.66.57.biz.sta.port80.se
Address 4: 83.140.66.42 83.140.66.42.biz.sta.port80.se
Address 5: 83.140.66.53 83.140.66.53.biz.sta.port80.se
Address 6: 83.140.66.34 83.140.66.34.biz.sta.port80.se
Address 7: 83.140.66.38 83.140.66.38.biz.sta.port80.se
Address 8: 83.140.66.29 83.140.66.29.biz.sta.port80.se
Address 9: 83.140.66.15 83.140.66.15.biz.sta.port80.se
Address 10: 83.140.66.59 83.140.66.59.biz.sta.port80.se
Address 11: 83.140.66.30 83.140.66.30.biz.sta.port80.se
Address 12: 83.140.66.27 83.140.66.27.biz.sta.port80.se
Address 13: 83.140.66.23 83.140.66.23.biz.sta.port80.se
Address 14: 83.140.66.44 83.140.66.44.biz.sta.port80.se
Address 15: 83.140.66.19 83.140.66.19.biz.sta.port80.se
Address 16: 83.140.66.49 83.140.66.49.biz.sta.port80.se
So it does not seem to be DNS-poisoning but rather a more elaborate exploit kit.
I should add that I'm more of a newb than a pro on these matters.
Please advise...

Thanks
Last edited: