Skip to content
DnsLister Forum

Where domain hunters compare notes

Confirming (or confusing) transparent redirect (hijack) in Brazil

Just testing a Quad9 upstream setup from Brazil, using the Quad9 FAQ's test suggestions. I can't seem to pass the Detecting DNS Transparent Redirection (Hijacks) section/suggestions. If I do:

dig -c ch -t txt id.server 

I get a not implemented (NOTIMP) response. If I do:

dig -t txt id.server 

I get a proper NXDOMAIN response but an empty TXT record (there are other records, though).

First, I'm confused about this entry in the FAQ. Why would I get a result like resXXX.xxx.rrdns.pch.net when the partnering service provider in Brazil is EdgeUno?

Second, the Now what? section says that, if your ISP is transparently redirecting, then you should use encrypted DNS. I am pretty sure I am using encrypted DNS: I watched TCP and UDP conns on my router and there only appeared TCP 853 when I was doing lookups; what more, when I do:

dig -t txt proto.on.quad9.net 

I do indeed see "dot" for the TXT record.

This particular test (transparent hijacking) interests me, especially noting how the Brazilian government likes to intervene with tech/comms (e.g. Whatsapp, Discord video). I wouldn't be surprised if EdgeUno needs to quietly log all DNS requests in Brazil.

Shall I conclude that there is indeed a hijack happening here?

Source: r/Quad9 · by /u/Typical-Traffic-7605

Leave a Reply

Your email address will not be published. Required fields are marked *