{"id":367,"date":"2020-11-15T14:15:13","date_gmt":"2020-11-15T13:15:13","guid":{"rendered":"http:\/\/www.labtinker.net\/?p=367"},"modified":"2020-11-15T14:15:13","modified_gmt":"2020-11-15T13:15:13","slug":"barefaced-cheek","status":"publish","type":"post","link":"https:\/\/labtinker.net\/?p=367","title":{"rendered":"Barefaced Cheek"},"content":{"rendered":"\n<p class=\"wp-block-paragraph\">I was messing around with various things when I had cause to check the address of this website and found I was getting a different ip address for <em>18.135.13.153\/ <\/em>and <em>labtinker.net<\/em>.&nbsp; This should not happen because <em>18.135.13.153\/<\/em> has a  DNS CNAME record which points to labtinker.net <\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"966\" height=\"48\" src=\"http:\/\/18.135.13.153\/wp-content\/uploads\/2020\/11\/image-15.png\" alt=\"\" class=\"wp-image-384\" srcset=\"https:\/\/labtinker.net\/wp-content\/uploads\/2020\/11\/image-15.png 966w, https:\/\/labtinker.net\/wp-content\/uploads\/2020\/11\/image-15-300x15.png 300w, https:\/\/labtinker.net\/wp-content\/uploads\/2020\/11\/image-15-768x38.png 768w\" sizes=\"auto, (max-width: 966px) 100vw, 966px\" \/><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\"><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">And this in turn points to the ip address of the website:<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"854\" height=\"54\" src=\"http:\/\/18.135.13.153\/wp-content\/uploads\/2020\/11\/image-6.png\" alt=\"\" class=\"wp-image-374\" srcset=\"https:\/\/labtinker.net\/wp-content\/uploads\/2020\/11\/image-6.png 854w, https:\/\/labtinker.net\/wp-content\/uploads\/2020\/11\/image-6-300x19.png 300w, https:\/\/labtinker.net\/wp-content\/uploads\/2020\/11\/image-6-768x49.png 768w\" sizes=\"auto, (max-width: 854px) 100vw, 854px\" \/><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\">So both these URLs should ultimately point to the same ip address, 3.8.120.91<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">This is what I saw in &#8216;nslookup&#8217; from my machine.<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"351\" height=\"150\" src=\"http:\/\/18.135.13.153\/wp-content\/uploads\/2020\/11\/image-3.png\" alt=\"\" class=\"wp-image-371\" srcset=\"https:\/\/labtinker.net\/wp-content\/uploads\/2020\/11\/image-3.png 351w, https:\/\/labtinker.net\/wp-content\/uploads\/2020\/11\/image-3-300x128.png 300w\" sizes=\"auto, (max-width: 351px) 100vw, 351px\" \/><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\">And then I spotted my error. I&#8217;d put in an extra &#8216;w&#8217; in the first part of the URL. But if I owned the domain how could someone add a DNS record for it? I did a &#8216;whois&#8217; on the ip address and found the following:<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"485\" height=\"133\" src=\"http:\/\/18.135.13.153\/wp-content\/uploads\/2020\/11\/image-7.png\" alt=\"\" class=\"wp-image-375\" srcset=\"https:\/\/labtinker.net\/wp-content\/uploads\/2020\/11\/image-7.png 485w, https:\/\/labtinker.net\/wp-content\/uploads\/2020\/11\/image-7-300x82.png 300w\" sizes=\"auto, (max-width: 485px) 100vw, 485px\" \/><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\"><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The ip address I was served from <em>wwww.labtinker.net<\/em>  was owned by Barefruit-Errorhandling and a quick google took me this post which explained what was going on&#8230;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><a href=\"https:\/\/manurevah.com\/blah\/en\/blog\/DNS-Hijacking-via-Barefruit-Talktalk-and-Others\">https:\/\/manurevah.com\/blah\/en\/blog\/DNS-Hijacking-via-Barefruit-Talktalk-and-Others<\/a><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Essentially it seems, my ISP, Virgin are using Barefruit&#8217;s services to intercept my DNS queries and instead of serving up an error pages from incorrect URLs, serve their own page up.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"> <\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"602\" height=\"127\" src=\"http:\/\/18.135.13.153\/wp-content\/uploads\/2020\/11\/image-8.png\" alt=\"\" class=\"wp-image-376\" srcset=\"https:\/\/labtinker.net\/wp-content\/uploads\/2020\/11\/image-8.png 602w, https:\/\/labtinker.net\/wp-content\/uploads\/2020\/11\/image-8-300x63.png 300w\" sizes=\"auto, (max-width: 602px) 100vw, 602px\" \/><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\">with suggested searches which didn&#8217;t seem that relevant\u2026(Why Rome?)<\/p>\n\n\n\n<figure class=\"wp-block-image size-large is-resized\"><img loading=\"lazy\" decoding=\"async\" src=\"http:\/\/18.135.13.153\/wp-content\/uploads\/2020\/11\/image-9.png\" alt=\"\" class=\"wp-image-377\" width=\"573\" height=\"140\" srcset=\"https:\/\/labtinker.net\/wp-content\/uploads\/2020\/11\/image-9.png 573w, https:\/\/labtinker.net\/wp-content\/uploads\/2020\/11\/image-9-300x73.png 300w\" sizes=\"auto, (max-width: 573px) 100vw, 573px\" \/><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\">They do allow you to turn this off:<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"602\" height=\"307\" src=\"http:\/\/18.135.13.153\/wp-content\/uploads\/2020\/11\/image-10.png\" alt=\"\" class=\"wp-image-378\" srcset=\"https:\/\/labtinker.net\/wp-content\/uploads\/2020\/11\/image-10.png 602w, https:\/\/labtinker.net\/wp-content\/uploads\/2020\/11\/image-10-300x153.png 300w\" sizes=\"auto, (max-width: 602px) 100vw, 602px\" \/><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\"><\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"602\" height=\"237\" src=\"http:\/\/18.135.13.153\/wp-content\/uploads\/2020\/11\/image-11.png\" alt=\"\" class=\"wp-image-379\" srcset=\"https:\/\/labtinker.net\/wp-content\/uploads\/2020\/11\/image-11.png 602w, https:\/\/labtinker.net\/wp-content\/uploads\/2020\/11\/image-11-300x118.png 300w\" sizes=\"auto, (max-width: 602px) 100vw, 602px\" \/><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\">I noticed some websites had anticipated this and registered likely typos, others hadn&#8217;t.<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"280\" height=\"179\" src=\"http:\/\/18.135.13.153\/wp-content\/uploads\/2020\/11\/image-12.png\" alt=\"\" class=\"wp-image-380\"\/><\/figure>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"275\" height=\"155\" src=\"http:\/\/18.135.13.153\/wp-content\/uploads\/2020\/11\/image-13.png\" alt=\"\" class=\"wp-image-381\"\/><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\"><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">I&#8217;ve a feeling this DNS interception is probably widespread and well known but I&#8217;d personally never noticed it before &#8211; possibly to due to accurate typing \ud83d\ude09 <\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><\/p>\n","protected":false},"excerpt":{"rendered":"<p>I was messing around with various things when I had cause to check the address of this website and found I was getting a different ip address for 18.135.13.153\/ and labtinker.net.&nbsp; This should not happen because 18.135.13.153\/ has a DNS CNAME record which points to labtinker.net And this in turn points to the ip address [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[5],"tags":[],"class_list":["post-367","post","type-post","status-publish","format-standard","hentry","category-dns"],"jetpack_featured_media_url":"","_links":{"self":[{"href":"https:\/\/labtinker.net\/index.php?rest_route=\/wp\/v2\/posts\/367","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/labtinker.net\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/labtinker.net\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/labtinker.net\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/labtinker.net\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=367"}],"version-history":[{"count":0,"href":"https:\/\/labtinker.net\/index.php?rest_route=\/wp\/v2\/posts\/367\/revisions"}],"wp:attachment":[{"href":"https:\/\/labtinker.net\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=367"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/labtinker.net\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=367"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/labtinker.net\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=367"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}