广州电信宽带 DNS 污染: cloudflare.com 及子域名都解析成 127.0.0.1

276 天前
 cnbatch

前有深圳电信 DNS 污染 /t/962196 ,现在广州电信也有同样的情况了

无论是广州东区还是西区,得到的解析结果都是污染的

nslookup cloudflare.com 202.96.128.166
Server:  cache-b.guangzhou.gd.cn
Address:  202.96.128.166

Name:    cloudflare.com
Addresses:  ::1
          127.0.0.1
nslookup cloudflare.com 202.96.134.133
Server:  ns.szptt.net.cn
Address:  202.96.134.133

Name:    cloudflare.com
Addresses:  ::1
          127.0.0.1
nslookup api.cloudflare.com 202.96.128.166
Server:  cache-b.guangzhou.gd.cn
Address:  202.96.128.166

Name:    api.cloudflare.com
Addresses:  ::1
          127.0.0.1
nslookup api.cloudflare.com 202.96.134.133
Server:  ns.szptt.net.cn
Address:  202.96.134.133

Name:    api.cloudflare.com
Addresses:  ::1
          127.0.0.1

用广东电信 IPv6 的 DNS:

nslookup cloudflare.com 240e:1f:1::1
Server:  UnKnown
Address:  240e:1f:1::1

Name:    cloudflare.com
Addresses:  ::1
          127.0.0.1
nslookup api.cloudflare.com 240e:1f:1::1
Server:  UnKnown
Address:  240e:1f:1::1

Name:    api.cloudflare.com
Addresses:  ::1
          127.0.0.1

全部都污染了。

但如果用外省电信的 DNS ,就一切正常,例如用贵州电信的:

nslookup cloudflare.com 202.98.192.67
Server:  gz.ctcdma.com
Address:  202.98.192.67

Non-authoritative answer:
Name:    cloudflare.com
Addresses:  2606:4700::6810:85e5
          2606:4700::6810:84e5
          104.16.132.229
          104.16.133.229
nslookup api.cloudflare.com 202.98.192.67
Server:  gz.ctcdma.com
Address:  202.98.192.67

Non-authoritative answer:
Name:    api.cloudflare.com
Addresses:  2606:4700:300a::6813:c0af
          2606:4700:300a::6813:c01d
          2606:4700:300a::6813:c0b0
          2606:4700:300a::6813:c11d
          2606:4700:300a::6813:c0ae
          2606:4700:300a::6813:c0b1
          104.19.192.176
          104.19.192.175
          104.19.192.174
          104.19.192.29
          104.19.193.29
          104.19.192.177

换成江西电信的 DNS ,正常:

nslookup cloudflare.com 202.101.224.68
Server:  ns.jxncptt.net.cn
Address:  202.101.224.68

Non-authoritative answer:
Name:    cloudflare.com
Addresses:  2606:4700::6810:85e5
          2606:4700::6810:84e5
          104.16.133.229
          104.16.132.229
nslookup api.cloudflare.com 202.101.224.68
Server:  ns.jxncptt.net.cn
Address:  202.101.224.68

Non-authoritative answer:
Name:    api.cloudflare.com
Addresses:  2606:4700:300a::6813:c0af
          2606:4700:300a::6813:c0b0
          2606:4700:300a::6813:c11d
          2606:4700:300a::6813:c0ae
          2606:4700:300a::6813:c0b1
          2606:4700:300a::6813:c01d
          104.19.192.175
          104.19.192.177
          104.19.192.29
          104.19.192.176
          104.19.193.29
          104.19.192.174

换成安徽电信的 DNS ,正常:

nslookup cloudflare.com 202.102.199.68
Server:  cache2.ahwhtel.net.cn
Address:  202.102.199.68

Non-authoritative answer:
Name:    cloudflare.com
Addresses:  2606:4700::6810:85e5
          2606:4700::6810:84e5
          104.16.132.229
          104.16.133.229
nslookup api.cloudflare.com 202.102.199.68
Server:  cache2.ahwhtel.net.cn
Address:  202.102.199.68

Non-authoritative answer:
Name:    api.cloudflare.com
Addresses:  2606:4700:300a::6813:c01d
          2606:4700:300a::6813:c0b0
          2606:4700:300a::6813:c0af
          2606:4700:300a::6813:c0ae
          2606:4700:300a::6813:c11d
          2606:4700:300a::6813:c0b1
          104.19.192.175
          104.19.193.29
          104.19.192.177
          104.19.192.29
          104.19.192.174
          104.19.192.176
5941 次点击
所在节点    宽带症候群
59 条回复
yyzh
276 天前
还好没上反诈墙.不然连改 dns 也无法访问的
wwbfred
276 天前
运营商自己的 DNS 都带着各种稀奇古怪的污染和反诈墙,全国各地现在都这样了,不想使用换公共 DNS 就好。
pcslide
276 天前
现在不推荐使用 nslookup 。看下 dig 结果。
cnbatch
276 天前
@pcslide 没任何区别

; <<>> DiG 9.18.16 <<>> cloudflare.com @202.96.134.133
;; global options: +cmd
;; Got answer:
;; ->>HEADER<<- opcode: QUERY, status: NOERROR, id: 8546
;; flags: qr aa rd; QUERY: 1, ANSWER: 1, AUTHORITY: 0, ADDITIONAL: 0
;; WARNING: recursion requested but not available

;; QUESTION SECTION:
;cloudflare.com. IN A

;; ANSWER SECTION:
cloudflare.com. 300 IN A 127.0.0.1

;; Query time: 5 msec
;; SERVER: 202.96.134.133#53(202.96.134.133) (UDP)
;; WHEN: Mon Aug 07 02:00:36 HKT 2023
;; MSG SIZE rcvd: 48

————————————————————————————————————

; <<>> DiG 9.18.16 <<>> cloudflare.com AAAA @202.96.134.133
;; global options: +cmd
;; Got answer:
;; ->>HEADER<<- opcode: QUERY, status: NOERROR, id: 19392
;; flags: qr aa rd; QUERY: 1, ANSWER: 1, AUTHORITY: 0, ADDITIONAL: 0
;; WARNING: recursion requested but not available

;; QUESTION SECTION:
;cloudflare.com. IN AAAA

;; ANSWER SECTION:
cloudflare.com. 300 IN AAAA ::1

;; Query time: 5 msec
;; SERVER: 202.96.134.133#53(202.96.134.133) (UDP)
;; WHEN: Mon Aug 07 02:00:41 HKT 2023
;; MSG SIZE rcvd: 60

————————————————————————————————————

; <<>> DiG 9.18.16 <<>> api.cloudflare.com A @202.96.134.133
;; global options: +cmd
;; Got answer:
;; ->>HEADER<<- opcode: QUERY, status: NOERROR, id: 50590
;; flags: qr aa rd; QUERY: 1, ANSWER: 1, AUTHORITY: 0, ADDITIONAL: 0
;; WARNING: recursion requested but not available

;; QUESTION SECTION:
;api.cloudflare.com. IN A

;; ANSWER SECTION:
api.cloudflare.com. 300 IN A 127.0.0.1

;; Query time: 3 msec
;; SERVER: 202.96.134.133#53(202.96.134.133) (UDP)
;; WHEN: Mon Aug 07 02:01:50 HKT 2023
;; MSG SIZE rcvd: 52

————————————————————————————————————

; <<>> DiG 9.18.16 <<>> api.cloudflare.com AAAA @202.96.134.133
;; global options: +cmd
;; Got answer:
;; ->>HEADER<<- opcode: QUERY, status: NOERROR, id: 10470
;; flags: qr aa rd; QUERY: 1, ANSWER: 1, AUTHORITY: 0, ADDITIONAL: 0
;; WARNING: recursion requested but not available

;; QUESTION SECTION:
;api.cloudflare.com. IN AAAA

;; ANSWER SECTION:
api.cloudflare.com. 300 IN AAAA ::1

;; Query time: 5 msec
;; SERVER: 202.96.134.133#53(202.96.134.133) (UDP)
;; WHEN: Mon Aug 07 02:01:37 HKT 2023
;; MSG SIZE rcvd: 64

————————————————————————————————————

; <<>> DiG 9.18.16 <<>> api.cloudflare.com A @240e:1f:1::1
;; global options: +cmd
;; Got answer:
;; ->>HEADER<<- opcode: QUERY, status: NOERROR, id: 19489
;; flags: qr aa rd; QUERY: 1, ANSWER: 1, AUTHORITY: 0, ADDITIONAL: 0
;; WARNING: recursion requested but not available

;; QUESTION SECTION:
;api.cloudflare.com. IN A

;; ANSWER SECTION:
api.cloudflare.com. 300 IN A 127.0.0.1

;; Query time: 4 msec
;; SERVER: 240e:1f:1::1#53(240e:1f:1::1) (UDP)
;; WHEN: Mon Aug 07 02:02:41 HKT 2023
;; MSG SIZE rcvd: 52

————————————————————————————————————

; <<>> DiG 9.18.16 <<>> api.cloudflare.com AAAA @240e:1f:1::1
;; global options: +cmd
;; Got answer:
;; ->>HEADER<<- opcode: QUERY, status: NOERROR, id: 28900
;; flags: qr aa rd; QUERY: 1, ANSWER: 1, AUTHORITY: 0, ADDITIONAL: 0
;; WARNING: recursion requested but not available

;; QUESTION SECTION:
;api.cloudflare.com. IN AAAA

;; ANSWER SECTION:
api.cloudflare.com. 300 IN AAAA ::1

;; Query time: 4 msec
;; SERVER: 240e:1f:1::1#53(240e:1f:1::1) (UDP)
;; WHEN: Mon Aug 07 02:02:57 HKT 2023
;; MSG SIZE rcvd: 64
xixiv5
276 天前
@yyzh
@wwbfred
请问什么是反诈墙?和 GFW 有什么区别吗?
szzys
276 天前
不只是电信了,深圳移动也开始这样了
jackOff
276 天前
我日,想想 17 年直接手机装个翻墙软件就可以翻墙,现在感觉难度有点高了啊
Laeoo
276 天前
今天家里 nas 的 cloudflare ddns 没法注册,换了公共 dns 才注册成功。
另外才发现直连访问 cloudflare 会跳转 cloudflare-cn.com
xpn282
276 天前
现在这种网络环境,想想都气人!毫不犹豫的分流吧,国内域名 IP 走直连,其余全部走代理

包括 dns 也一样要分流,国内域名用国内 dns 解析,其余全部用国外 dns 解析(并且要代理解析才行)
naminokoe
276 天前
@xpn282 还不润,下一步就是域名白名单,看你分流到哪里去
lzl2000
276 天前
0668 电信一样。从昨天起,用默认 DNS 的 Cloudflare DDNS 一直报错,换成公共 DNS 就正常了
winterx
276 天前
坐标 0756 ,202.86.128.86 仍返回正确结果,128.166 确实被污染

```
; <<>> DiG 9.16.26 <<>> cloudflare.com @202.96.128.86
;; global options: +cmd
;; Got answer:
;; ->>HEADER<<- opcode: QUERY, status: NOERROR, id: 12145
;; flags: qr aa rd ra; QUERY: 1, ANSWER: 2, AUTHORITY: 0, ADDITIONAL: 1

;; OPT PSEUDOSECTION:
; EDNS: version: 0, flags:; udp: 1232
;; QUESTION SECTION:
;cloudflare.com. IN A

;; ANSWER SECTION:
cloudflare.com. 204 IN A 104.16.133.229
cloudflare.com. 204 IN A 104.16.132.229

;; Query time: 2 msec
;; SERVER: 202.96.128.86#53(202.96.128.86)
;; WHEN: Mon Aug 07 08:21:32 ;; MSG SIZE rcvd: 75
```

```
; <<>> DiG 9.16.26 <<>> cloudflare.com @202.96.128.166
;; global options: +cmd
;; Got answer:
;; ->>HEADER<<- opcode: QUERY, status: NOERROR, id: 32398
;; flags: qr aa rd; QUERY: 1, ANSWER: 1, AUTHORITY: 0, ADDITIONAL: 0
;; WARNING: recursion requested but not available

;; QUESTION SECTION:
;cloudflare.com. IN A

;; ANSWER SECTION:
cloudflare.com. 300 IN A 127.0.0.1

;; Query time: 5 msec
;; SERVER: 202.96.128.166#53(202.96.128.166)
;; WHEN: Mon Aug 07 08:21:07 ;; MSG SIZE rcvd: 48
```
TESTFLIGHT2021
276 天前
快要白名单了
noahzh
276 天前
哎,主要是这个电信诈骗一点办法也没有,逼的运营商搞白名单了
cnbatch
276 天前
@winterx 刚试了下 202.86.128.86 ,广州电信得到的是污染过的结果,我怀疑这个 DNS 要么按照区分地域返回结果,要么各市都有缓存服务器

nslookup cloudflare.com 202.96.128.86
Server: cache-a.guangzhou.gd.cn
Address: 202.96.128.86

Name: cloudflare.com
Addresses: ::1
127.0.0.1



nslookup api.cloudflare.com 202.96.128.86
Server: cache-a.guangzhou.gd.cn
Address: 202.96.128.86

Name: api.cloudflare.com
Addresses: ::1
127.0.0.1



; <<>> DiG 9.18.16 <<>> cloudflare.com @202.96.128.86
;; global options: +cmd
;; Got answer:
;; ->>HEADER<<- opcode: QUERY, status: NOERROR, id: 23963
;; flags: qr aa rd; QUERY: 1, ANSWER: 1, AUTHORITY: 0, ADDITIONAL: 0
;; WARNING: recursion requested but not available

;; QUESTION SECTION:
;cloudflare.com. IN A

;; ANSWER SECTION:
cloudflare.com. 300 IN A 127.0.0.1

;; Query time: 67 msec
;; SERVER: 202.96.128.86#53(202.96.128.86) (UDP)
;; WHEN: Mon Aug 07 13:33:13 HKT 2023
;; MSG SIZE rcvd: 48
cnbatch
276 天前
@lzl2000 看来只能暂时用公共 DNS 代替了,目前我在路由器手动设置了公共 DNS 的地址,替换掉运营商的 DNS ,暂时恢复正常
asdgsdg98
276 天前
202.101.172.47
202.101.172.35 正常
54xavier
276 天前
C:\>nslookup github.githubassets.com 202.96.128.86
服务器: cache-a.guangzhou.gd.cn
Address: 202.96.128.86

名称: github.githubassets.com
Addresses: ::1
127.0.0.1


C:\>nslookup github.githubassets.com 202.96.134.133
服务器: ns.szptt.net.cn
Address: 202.96.134.133

名称: github.githubassets.com
Addresses: ::1
127.0.0.1


C:\>nslookup github.githubassets.com 202.96.128.166
服务器: cache-b.guangzhou.gd.cn
Address: 202.96.128.166

名称: github.githubassets.com
Addresses: ::1
127.0.0.1


C:\>nslookup github.githubassets.com 202.96.134.33
服务器: cache-b.shenzhen.gd.cn
Address: 202.96.134.33

名称: github.githubassets.com
Addresses: ::1
127.0.0.1

佛山电信 github 的静态资源解析也是
cnbatch
276 天前
@54xavier 刚试了下,广州电信一样也污染了
cnbatch
276 天前
@szzys 刚发现广州移动也一样,cloudflare 和前面楼层提到的 github 的静态资源全都是 127.0.0.1 、::1
顺便试了下广州联通,还好仍然正常

这是一个专为移动设备优化的页面(即为了让你能够在 Google 搜索结果里秒开这个页面),如果你希望参与 V2EX 社区的讨论,你可以继续到 V2EX 上打开本讨论主题的完整版本。

https://www.v2ex.com/t/962883

V2EX 是创意工作者们的社区,是一个分享自己正在做的有趣事物、交流想法,可以遇见新朋友甚至新机会的地方。

V2EX is a community of developers, designers and creative people.

© 2021 V2EX