广州电信宽带 DNS 污染: cloudflare.com 及子域名都解析成 127.0.0.1

2023-08-06 23:58:41 +08:00
 cnbatch

前有深圳电信 DNS 污染 /t/962196 ,现在广州电信也有同样的情况了

无论是广州东区还是西区,得到的解析结果都是污染的

nslookup cloudflare.com 202.96.128.166
Server:  cache-b.guangzhou.gd.cn
Address:  202.96.128.166

Name:    cloudflare.com
Addresses:  ::1
          127.0.0.1
nslookup cloudflare.com 202.96.134.133
Server:  ns.szptt.net.cn
Address:  202.96.134.133

Name:    cloudflare.com
Addresses:  ::1
          127.0.0.1
nslookup api.cloudflare.com 202.96.128.166
Server:  cache-b.guangzhou.gd.cn
Address:  202.96.128.166

Name:    api.cloudflare.com
Addresses:  ::1
          127.0.0.1
nslookup api.cloudflare.com 202.96.134.133
Server:  ns.szptt.net.cn
Address:  202.96.134.133

Name:    api.cloudflare.com
Addresses:  ::1
          127.0.0.1

用广东电信 IPv6 的 DNS:

nslookup cloudflare.com 240e:1f:1::1
Server:  UnKnown
Address:  240e:1f:1::1

Name:    cloudflare.com
Addresses:  ::1
          127.0.0.1
nslookup api.cloudflare.com 240e:1f:1::1
Server:  UnKnown
Address:  240e:1f:1::1

Name:    api.cloudflare.com
Addresses:  ::1
          127.0.0.1

全部都污染了。

但如果用外省电信的 DNS ,就一切正常,例如用贵州电信的:

nslookup cloudflare.com 202.98.192.67
Server:  gz.ctcdma.com
Address:  202.98.192.67

Non-authoritative answer:
Name:    cloudflare.com
Addresses:  2606:4700::6810:85e5
          2606:4700::6810:84e5
          104.16.132.229
          104.16.133.229
nslookup api.cloudflare.com 202.98.192.67
Server:  gz.ctcdma.com
Address:  202.98.192.67

Non-authoritative answer:
Name:    api.cloudflare.com
Addresses:  2606:4700:300a::6813:c0af
          2606:4700:300a::6813:c01d
          2606:4700:300a::6813:c0b0
          2606:4700:300a::6813:c11d
          2606:4700:300a::6813:c0ae
          2606:4700:300a::6813:c0b1
          104.19.192.176
          104.19.192.175
          104.19.192.174
          104.19.192.29
          104.19.193.29
          104.19.192.177

换成江西电信的 DNS ,正常:

nslookup cloudflare.com 202.101.224.68
Server:  ns.jxncptt.net.cn
Address:  202.101.224.68

Non-authoritative answer:
Name:    cloudflare.com
Addresses:  2606:4700::6810:85e5
          2606:4700::6810:84e5
          104.16.133.229
          104.16.132.229
nslookup api.cloudflare.com 202.101.224.68
Server:  ns.jxncptt.net.cn
Address:  202.101.224.68

Non-authoritative answer:
Name:    api.cloudflare.com
Addresses:  2606:4700:300a::6813:c0af
          2606:4700:300a::6813:c0b0
          2606:4700:300a::6813:c11d
          2606:4700:300a::6813:c0ae
          2606:4700:300a::6813:c0b1
          2606:4700:300a::6813:c01d
          104.19.192.175
          104.19.192.177
          104.19.192.29
          104.19.192.176
          104.19.193.29
          104.19.192.174

换成安徽电信的 DNS ,正常:

nslookup cloudflare.com 202.102.199.68
Server:  cache2.ahwhtel.net.cn
Address:  202.102.199.68

Non-authoritative answer:
Name:    cloudflare.com
Addresses:  2606:4700::6810:85e5
          2606:4700::6810:84e5
          104.16.132.229
          104.16.133.229
nslookup api.cloudflare.com 202.102.199.68
Server:  cache2.ahwhtel.net.cn
Address:  202.102.199.68

Non-authoritative answer:
Name:    api.cloudflare.com
Addresses:  2606:4700:300a::6813:c01d
          2606:4700:300a::6813:c0b0
          2606:4700:300a::6813:c0af
          2606:4700:300a::6813:c0ae
          2606:4700:300a::6813:c11d
          2606:4700:300a::6813:c0b1
          104.19.192.175
          104.19.193.29
          104.19.192.177
          104.19.192.29
          104.19.192.174
          104.19.192.176
8528 次点击
所在节点    宽带症候群
59 条回复
yyzh
2023-08-07 00:24:11 +08:00
还好没上反诈墙.不然连改 dns 也无法访问的
wwbfred
2023-08-07 00:39:38 +08:00
运营商自己的 DNS 都带着各种稀奇古怪的污染和反诈墙,全国各地现在都这样了,不想使用换公共 DNS 就好。
pcslide
2023-08-07 01:26:07 +08:00
现在不推荐使用 nslookup 。看下 dig 结果。
cnbatch
2023-08-07 02:03:26 +08:00
@pcslide 没任何区别

; <<>> DiG 9.18.16 <<>> cloudflare.com @202.96.134.133
;; global options: +cmd
;; Got answer:
;; ->>HEADER<<- opcode: QUERY, status: NOERROR, id: 8546
;; flags: qr aa rd; QUERY: 1, ANSWER: 1, AUTHORITY: 0, ADDITIONAL: 0
;; WARNING: recursion requested but not available

;; QUESTION SECTION:
;cloudflare.com. IN A

;; ANSWER SECTION:
cloudflare.com. 300 IN A 127.0.0.1

;; Query time: 5 msec
;; SERVER: 202.96.134.133#53(202.96.134.133) (UDP)
;; WHEN: Mon Aug 07 02:00:36 HKT 2023
;; MSG SIZE rcvd: 48

————————————————————————————————————

; <<>> DiG 9.18.16 <<>> cloudflare.com AAAA @202.96.134.133
;; global options: +cmd
;; Got answer:
;; ->>HEADER<<- opcode: QUERY, status: NOERROR, id: 19392
;; flags: qr aa rd; QUERY: 1, ANSWER: 1, AUTHORITY: 0, ADDITIONAL: 0
;; WARNING: recursion requested but not available

;; QUESTION SECTION:
;cloudflare.com. IN AAAA

;; ANSWER SECTION:
cloudflare.com. 300 IN AAAA ::1

;; Query time: 5 msec
;; SERVER: 202.96.134.133#53(202.96.134.133) (UDP)
;; WHEN: Mon Aug 07 02:00:41 HKT 2023
;; MSG SIZE rcvd: 60

————————————————————————————————————

; <<>> DiG 9.18.16 <<>> api.cloudflare.com A @202.96.134.133
;; global options: +cmd
;; Got answer:
;; ->>HEADER<<- opcode: QUERY, status: NOERROR, id: 50590
;; flags: qr aa rd; QUERY: 1, ANSWER: 1, AUTHORITY: 0, ADDITIONAL: 0
;; WARNING: recursion requested but not available

;; QUESTION SECTION:
;api.cloudflare.com. IN A

;; ANSWER SECTION:
api.cloudflare.com. 300 IN A 127.0.0.1

;; Query time: 3 msec
;; SERVER: 202.96.134.133#53(202.96.134.133) (UDP)
;; WHEN: Mon Aug 07 02:01:50 HKT 2023
;; MSG SIZE rcvd: 52

————————————————————————————————————

; <<>> DiG 9.18.16 <<>> api.cloudflare.com AAAA @202.96.134.133
;; global options: +cmd
;; Got answer:
;; ->>HEADER<<- opcode: QUERY, status: NOERROR, id: 10470
;; flags: qr aa rd; QUERY: 1, ANSWER: 1, AUTHORITY: 0, ADDITIONAL: 0
;; WARNING: recursion requested but not available

;; QUESTION SECTION:
;api.cloudflare.com. IN AAAA

;; ANSWER SECTION:
api.cloudflare.com. 300 IN AAAA ::1

;; Query time: 5 msec
;; SERVER: 202.96.134.133#53(202.96.134.133) (UDP)
;; WHEN: Mon Aug 07 02:01:37 HKT 2023
;; MSG SIZE rcvd: 64

————————————————————————————————————

; <<>> DiG 9.18.16 <<>> api.cloudflare.com A @240e:1f:1::1
;; global options: +cmd
;; Got answer:
;; ->>HEADER<<- opcode: QUERY, status: NOERROR, id: 19489
;; flags: qr aa rd; QUERY: 1, ANSWER: 1, AUTHORITY: 0, ADDITIONAL: 0
;; WARNING: recursion requested but not available

;; QUESTION SECTION:
;api.cloudflare.com. IN A

;; ANSWER SECTION:
api.cloudflare.com. 300 IN A 127.0.0.1

;; Query time: 4 msec
;; SERVER: 240e:1f:1::1#53(240e:1f:1::1) (UDP)
;; WHEN: Mon Aug 07 02:02:41 HKT 2023
;; MSG SIZE rcvd: 52

————————————————————————————————————

; <<>> DiG 9.18.16 <<>> api.cloudflare.com AAAA @240e:1f:1::1
;; global options: +cmd
;; Got answer:
;; ->>HEADER<<- opcode: QUERY, status: NOERROR, id: 28900
;; flags: qr aa rd; QUERY: 1, ANSWER: 1, AUTHORITY: 0, ADDITIONAL: 0
;; WARNING: recursion requested but not available

;; QUESTION SECTION:
;api.cloudflare.com. IN AAAA

;; ANSWER SECTION:
api.cloudflare.com. 300 IN AAAA ::1

;; Query time: 4 msec
;; SERVER: 240e:1f:1::1#53(240e:1f:1::1) (UDP)
;; WHEN: Mon Aug 07 02:02:57 HKT 2023
;; MSG SIZE rcvd: 64
xixiv5
2023-08-07 02:13:36 +08:00
@yyzh
@wwbfred
请问什么是反诈墙?和 GFW 有什么区别吗?
szzys
2023-08-07 02:20:22 +08:00
不只是电信了,深圳移动也开始这样了
jackOff
2023-08-07 02:37:09 +08:00
我日,想想 17 年直接手机装个翻墙软件就可以翻墙,现在感觉难度有点高了啊
Laeoo
2023-08-07 04:01:05 +08:00
今天家里 nas 的 cloudflare ddns 没法注册,换了公共 dns 才注册成功。
另外才发现直连访问 cloudflare 会跳转 cloudflare-cn.com
xpn282
2023-08-07 07:17:15 +08:00
现在这种网络环境,想想都气人!毫不犹豫的分流吧,国内域名 IP 走直连,其余全部走代理

包括 dns 也一样要分流,国内域名用国内 dns 解析,其余全部用国外 dns 解析(并且要代理解析才行)
naminokoe
2023-08-07 07:22:16 +08:00
@xpn282 还不润,下一步就是域名白名单,看你分流到哪里去
lzl2000
2023-08-07 07:36:17 +08:00
0668 电信一样。从昨天起,用默认 DNS 的 Cloudflare DDNS 一直报错,换成公共 DNS 就正常了
winterx
2023-08-07 08:22:44 +08:00
坐标 0756 ,202.86.128.86 仍返回正确结果,128.166 确实被污染

```
; <<>> DiG 9.16.26 <<>> cloudflare.com @202.96.128.86
;; global options: +cmd
;; Got answer:
;; ->>HEADER<<- opcode: QUERY, status: NOERROR, id: 12145
;; flags: qr aa rd ra; QUERY: 1, ANSWER: 2, AUTHORITY: 0, ADDITIONAL: 1

;; OPT PSEUDOSECTION:
; EDNS: version: 0, flags:; udp: 1232
;; QUESTION SECTION:
;cloudflare.com. IN A

;; ANSWER SECTION:
cloudflare.com. 204 IN A 104.16.133.229
cloudflare.com. 204 IN A 104.16.132.229

;; Query time: 2 msec
;; SERVER: 202.96.128.86#53(202.96.128.86)
;; WHEN: Mon Aug 07 08:21:32 ;; MSG SIZE rcvd: 75
```

```
; <<>> DiG 9.16.26 <<>> cloudflare.com @202.96.128.166
;; global options: +cmd
;; Got answer:
;; ->>HEADER<<- opcode: QUERY, status: NOERROR, id: 32398
;; flags: qr aa rd; QUERY: 1, ANSWER: 1, AUTHORITY: 0, ADDITIONAL: 0
;; WARNING: recursion requested but not available

;; QUESTION SECTION:
;cloudflare.com. IN A

;; ANSWER SECTION:
cloudflare.com. 300 IN A 127.0.0.1

;; Query time: 5 msec
;; SERVER: 202.96.128.166#53(202.96.128.166)
;; WHEN: Mon Aug 07 08:21:07 ;; MSG SIZE rcvd: 48
```
TESTFLIGHT2021
2023-08-07 08:37:07 +08:00
快要白名单了
noahzh
2023-08-07 09:15:14 +08:00
哎,主要是这个电信诈骗一点办法也没有,逼的运营商搞白名单了
cnbatch
2023-08-07 13:33:49 +08:00
@winterx 刚试了下 202.86.128.86 ,广州电信得到的是污染过的结果,我怀疑这个 DNS 要么按照区分地域返回结果,要么各市都有缓存服务器

nslookup cloudflare.com 202.96.128.86
Server: cache-a.guangzhou.gd.cn
Address: 202.96.128.86

Name: cloudflare.com
Addresses: ::1
127.0.0.1



nslookup api.cloudflare.com 202.96.128.86
Server: cache-a.guangzhou.gd.cn
Address: 202.96.128.86

Name: api.cloudflare.com
Addresses: ::1
127.0.0.1



; <<>> DiG 9.18.16 <<>> cloudflare.com @202.96.128.86
;; global options: +cmd
;; Got answer:
;; ->>HEADER<<- opcode: QUERY, status: NOERROR, id: 23963
;; flags: qr aa rd; QUERY: 1, ANSWER: 1, AUTHORITY: 0, ADDITIONAL: 0
;; WARNING: recursion requested but not available

;; QUESTION SECTION:
;cloudflare.com. IN A

;; ANSWER SECTION:
cloudflare.com. 300 IN A 127.0.0.1

;; Query time: 67 msec
;; SERVER: 202.96.128.86#53(202.96.128.86) (UDP)
;; WHEN: Mon Aug 07 13:33:13 HKT 2023
;; MSG SIZE rcvd: 48
cnbatch
2023-08-07 13:36:31 +08:00
@lzl2000 看来只能暂时用公共 DNS 代替了,目前我在路由器手动设置了公共 DNS 的地址,替换掉运营商的 DNS ,暂时恢复正常
asdgsdg98
2023-08-07 13:41:24 +08:00
202.101.172.47
202.101.172.35 正常
54xavier
2023-08-07 13:51:36 +08:00
C:\>nslookup github.githubassets.com 202.96.128.86
服务器: cache-a.guangzhou.gd.cn
Address: 202.96.128.86

名称: github.githubassets.com
Addresses: ::1
127.0.0.1


C:\>nslookup github.githubassets.com 202.96.134.133
服务器: ns.szptt.net.cn
Address: 202.96.134.133

名称: github.githubassets.com
Addresses: ::1
127.0.0.1


C:\>nslookup github.githubassets.com 202.96.128.166
服务器: cache-b.guangzhou.gd.cn
Address: 202.96.128.166

名称: github.githubassets.com
Addresses: ::1
127.0.0.1


C:\>nslookup github.githubassets.com 202.96.134.33
服务器: cache-b.shenzhen.gd.cn
Address: 202.96.134.33

名称: github.githubassets.com
Addresses: ::1
127.0.0.1

佛山电信 github 的静态资源解析也是
cnbatch
2023-08-07 15:03:40 +08:00
@54xavier 刚试了下,广州电信一样也污染了
cnbatch
2023-08-07 15:13:06 +08:00
@szzys 刚发现广州移动也一样,cloudflare 和前面楼层提到的 github 的静态资源全都是 127.0.0.1 、::1
顺便试了下广州联通,还好仍然正常

这是一个专为移动设备优化的页面(即为了让你能够在 Google 搜索结果里秒开这个页面),如果你希望参与 V2EX 社区的讨论,你可以继续到 V2EX 上打开本讨论主题的完整版本。

https://www.v2ex.com/t/962883

V2EX 是创意工作者们的社区,是一个分享自己正在做的有趣事物、交流想法,可以遇见新朋友甚至新机会的地方。

V2EX is a community of developers, designers and creative people.

© 2021 V2EX