Hacking TitleDB.com - Update Blocking DNS Servers

ksanislo

Well-Known Member
OP
Member
Joined
Feb 23, 2016
Messages
386
Trophies
0
Location
Seattle, WA
XP
512
Country
United States
I'm performing some maintenance on the DNS servers. In the interest of safety I'll be blocking all DNS queries until finished from one server at a time, so they can't accidentally leak unfiltered responses. They are expected to be down only a few minutes each.

update: Maintenance has been concluded. The backend has been changed from bind9 to powerdns, since pdns provides a mechanism that will help prevent being used as a DDoS relay, and I'd rather prefer not dealing with that sort of thing.
 
Last edited by ksanislo,

ksanislo

Well-Known Member
OP
Member
Joined
Feb 23, 2016
Messages
386
Trophies
0
Location
Seattle, WA
XP
512
Country
United States
Thank you keep up with this, since the recent attacks against the other
These should remain up for the foreseeable future. I'd actually attempted to warn the operator of the DNS-U setup about his vulnerability of becoming a DDoS amplifier, but he apparently wasn't interested in fixing it.
 

ksanislo

Well-Known Member
OP
Member
Joined
Feb 23, 2016
Messages
386
Trophies
0
Location
Seattle, WA
XP
512
Country
United States
that's kind of a big assumption. i did try several iptables entries to defeat the attack but none worked.
You can't block the "source" addresses of a UDP based DNS amplification attack because that's a forged address of the DDoS target. You must utilize something such as PowerDNS's any-to-tcp option which returns a 'truncated' result to any UDP ANY query, requiring the client to switch to TCP which can't be forged in order to perform a query for ANY type records.
 

Ninja_Carver

Well-Known Member
Member
Joined
Dec 27, 2012
Messages
364
Trophies
0
Age
39
XP
652
Country
United States
You can't block the "source" addresses of a UDP based DNS amplification attack because that's a forged address of the DDoS target. You must utilize something such as PowerDNS's any-to-tcp option which returns a 'truncated' result to any UDP ANY query, requiring the client to switch to TCP which can't be forged in order to perform a query for ANY type records.

i'm familiar with how an amplification attack works and didn't say i was trying to block the source addresses.. christ you make a lot of generalizations. anyways, its not really worth the effort of rebuilding the server with powerdns. cheers.
 

ksanislo

Well-Known Member
OP
Member
Joined
Feb 23, 2016
Messages
386
Trophies
0
Location
Seattle, WA
XP
512
Country
United States
i'm familiar with how an amplification attack works and didn't say i was trying to block the source addresses.. christ you make a lot of generalizations. anyways, its not really worth the effort of rebuilding the server with powerdns. cheers.

I apologize if I came off as rude, and you're right that I made some possibly incorrect assumptions as to how your system was configured. Thank you for your support of the community with your service. If you do decide you wish to continue DNS-U with pdns later on, I'm sure people would be grateful for more options.
 

adittya

Member
Newcomer
Joined
Apr 9, 2017
Messages
7
Trophies
0
Age
33
XP
52
Country
Indonesia
Yeah, what problem are you having?

i cant connect to internet with the dns. but with auto dns i can connect without problem. without internet i cant open hbl
i already reset router, try another router, try with another connection, reset wii u couple times the result are the same
 
Last edited by adittya,

ksanislo

Well-Known Member
OP
Member
Joined
Feb 23, 2016
Messages
386
Trophies
0
Location
Seattle, WA
XP
512
Country
United States
Doing some maintenance on these DNS servers today. I'll be blocking them off from public access while working, to make sure I don't accidentally leak valid results out and let someone's console update unexpectedly. As long as you have BOTH of mine configured, you shouldn't see an impact. Anybody who still has one of the dead, alternate services (tubehax, dns-u) on their system will probably lose internet briefly.
 

ksanislo

Well-Known Member
OP
Member
Joined
Feb 23, 2016
Messages
386
Trophies
0
Location
Seattle, WA
XP
512
Country
United States
Doing some maintenance on these DNS servers today. I'll be blocking them off from public access while working, to make sure I don't accidentally leak valid results out and let someone's console update unexpectedly. As long as you have BOTH of mine configured, you shouldn't see an impact. Anybody who still has one of the dead, alternate services (tubehax, dns-u) on their system will probably lose internet briefly.

Maintenance has been concluded. Services are back up and running as expected on both systems.
 
  • Like
Reactions: Deleted User

Xerkies

Active Member
Newcomer
Joined
Dec 14, 2016
Messages
29
Trophies
0
Age
28
XP
108
Country
United States
Two of the TitleDB.com nameservers have been configured to block updates for the Wii U and allow open use from the internet.

Los Angeles, USA: 168.235.092.108
Alblasserdam, NL: 081.004.127.020


These should be stable and aren't going to be discontinued any time soon, so they should be solid choices to use on your system. Set the one nearest to you as your primary, and use the other as secondary.

The following domains are currently filtered:
nus.c.shop.nintendowifi.net
nus.cdn.c.shop.nintendowifi.net
nus.cdn.shop.wii.com
nus.cdn.wup.shop.nintendo.net
nus.wup.shop.nintendo.net
c.shop.nintendowifi.net
cbvc.cdn.nintendo.net
cbvc.nintendo.net

This list is subject to change without notice, and is a free service offered to the community. I make no guarantee to the quality or suitability of this service for anything whatsoever.
Now my internet doesn't work. It did work before but now it doesn't
 

Site & Scene News

Popular threads in this forum

General chit-chat
Help Users
  • K3Nv2 @ K3Nv2:
    Been noticing it more these days alot has to do with coperation attitude manipulation people work in it so long they think it's a good way to live
    +1
  • BigOnYa @ BigOnYa:
    And he/she used to do any/every mod to the Switch, just to learn and teach others as well. A true Switch genius.
    +2
  • Psionic Roshambo @ Psionic Roshambo:
    Ken secret tactic to expose them, "I was told you where a really bad person, now I'm not so sure." Watch who they tear into, that's the person who is doing that crap.
  • K3Nv2 @ K3Nv2:
    I just say this person said this about you and let it play out
  • Psionic Roshambo @ Psionic Roshambo:
    Fight lies with truth
  • K3Nv2 @ K3Nv2:
    Don't want me to snitch don't treat me any different
    +1
  • Xdqwerty @ Xdqwerty:
    @Psionic Roshambo, new version of rock paper scissors: truth lies
    hipocrisy
    +1
  • Psionic Roshambo @ Psionic Roshambo:
    My ex fiance was a master liar, manipulator and hypocrite. An actual diagnosed psychopath.
  • Psionic Roshambo @ Psionic Roshambo:
    They are not even human in my opinion.
  • K3Nv2 @ K3Nv2:
    Just because I said you were big that one time you believed me
    +1
  • Psionic Roshambo @ Psionic Roshambo:
    The shameful part is, I fell so in love with her mask. If I could find the real woman she pretended to be I would die for her without a moments hesitation.
  • Psionic Roshambo @ Psionic Roshambo:
    Truly loved what was never there
  • Psionic Roshambo @ Psionic Roshambo:
    I would have fought demons, gods, armies.
  • BigOnYa @ BigOnYa:
    "Be gentle, I've never done this before." What, biatch you got 3 kids already. Lol, I know loves sucks hard when bad, but really good when good.
    +2
  • Psionic Roshambo @ Psionic Roshambo:
    Lol BigOnYa I hear "I don't usually do sex on the first date" like every 2 to 3 weeks now...
    +1
  • Psionic Roshambo @ Psionic Roshambo:
    I never quite know how to respond lol
  • Psionic Roshambo @ Psionic Roshambo:
    Apparently saying nothing is the correct response lol
  • Psionic Roshambo @ Psionic Roshambo:
    I know they be lying but damn I need something
  • BigOnYa @ BigOnYa:
    You say " is your boyfriend gonna stay and watch, or should I call A cab for him"
    +1
  • BigOnYa @ BigOnYa:
    @Psionic Roshambo I have alot of family that lives in St pete, Clearwater, Tampa area, what part of FL you in?
    +1
  • Sicklyboy @ Sicklyboy:
    what is good, family
  • Psionic Roshambo @ Psionic Roshambo:
    Elfers Florida lol
    +1
  • BigOnYa @ BigOnYa:
    Where is that, city close to
  • Psionic Roshambo @ Psionic Roshambo:
    Lived in Hudson from 1999-2023
  • Psionic Roshambo @ Psionic Roshambo:
    Like hmm 45 minutes north of Tampa
    +1
    Psionic Roshambo @ Psionic Roshambo: Like hmm 45 minutes north of Tampa +1