What's new

DNS-rebind attack detected: farm.plista.com. etc...??

  • SNBForums Code of Conduct

    SNBForums is a community for everyone, no matter what their level of experience.

    Please be tolerant and patient of others, especially newcomers. We are all here to share and learn!

    The rules are simple: Be patient, be nice, be helpful or be gone!

Howard_inGA

Senior Member
So the router is suddenly (since October 1) showing a lot of these system log entries from different sources.

Oct 10 01:48:10 dnsmasq[6357]: possible DNS-rebind attack detected: farm.plista.com
Oct 10 02:51:54 dnsmasq[6357]: possible DNS-rebind attack detected: gixel.gnetwork.me
Oct 6 14:08:21 dnsmasq[10313]: possible DNS-rebind attack detected: cdn.livefyre.com
Oct 6 20:10:27 dnsmasq[10313]: possible DNS-rebind attack detected: ib.beintoo.com

There are about 30 entries for each of these sources since the 1st. Do I need to do anything since the attacks were detected, and the router is rock solid and very fast?
Any help or advice would be appreciated...
 
Do you have DNS rebind protection enabled while using a third-party DNS server? For example, I use Cloudflare for Families (malware blocking) and I get those log entries when Cloudflare returns 0.0.0.0 whenever a malicious URL is accessed.
 
Do you have DNS rebind protection enabled while using a third-party DNS server? For example, I use Cloudflare for Families (malware blocking) and I get those log entries when Cloudflare returns 0.0.0.0 whenever a malicious URL is accessed.
I use DNS Server: 103.86.96.100, 103.86.99.100 (NordVPN’s DNS settings).
I do have rebind protection selected on, so it appears that this combo is stopping bad things?
 

Similar threads

Support SNBForums w/ Amazon

If you'd like to support SNBForums, just use this link and buy anything on Amazon. Thanks!

Sign Up For SNBForums Daily Digest

Get an update of what's new every day delivered to your mailbox. Sign up here!
Top