Question DNS rebinding attacks

Please provide comments and solutions that are helpful to the author of this topic.
Always wondered what that filter did, thanks for educating me (y)

Your much more likely to get pwned by your crappy router with outdated and exploitable firmware than some weird edge case DNS attack. My 2 cents :unsure:
They can't hack your router if it's not accessible from the outside web. ISPs in Croatia by default close all ports (including 80) so no one can access router's internal page. Then you can safely use router with outdated firmware. 😄
 
Hosting your dns locally has a price to be paid by performance.
I was not talking about hosting DNS locally. Yoga DNS just replaces the clients such as NextDNS and Controlid. Just put your DNS config in it and it enables the custom DNS systemwide using a protocol of your choosing.

The client is robust and it shows many details and errors which will help you diagnose anything.
 
I was not talking about hosting DNS locally. Yoga DNS just replaces the clients such as NextDNS and Controlid. Just put your DNS config in it and it enables the custom DNS systemwide using a protocol of your choosing.

The client is robust and it shows many details and errors which will help you diagnose anything.
I am currently trying RethinkDNS (Hagezi TIF + OISD big).
 
I'm using ControlD Setup Utility. Launched it once, set up the resolver, pressed connect and that's it. Can't be more simple than that.
The same goes to NextDNS client, but what if you keep change DNS providers? Yoga DNS can setup different profiles for different DNS providers and you can switch profiles in a click.
 
  • Hundred Points
Reactions: Parkinsond
Does their client support using a custom DNS?
It is basically customized; the only downside, it does not support legacy dns for old routers.

Screenshot_3-12-2025_132935_rethinkdns.com.jpeg
 
The same goes to NextDNS client, but what if you keep change DNS providers? Yoga DNS can setup different profiles for different DNS providers and you can switch profiles in a click.
I'm not the kind of person that often changes things; I like to set them once for all and change only when something stops working. I tested ControlD for a month and it was reliable enough for me, so I just stick to it now.
It is basically customized; the only downside, it does not support legacy dns for old routers.

View attachment 293440
Careful: Rethink DNS even though customizable, rarely updates their blocklists. This massively decreases effectiveness of said blocklists. From what I understand, they are usually updated once every week while some might be updated once a month.

I asked them about this and the reason was they don't have resources (and finances) to update them often. On question why don't they decrease number of blocklists in order to update the most popular more often, I didn't get the reply.

Personally, I'd stay away.
 
I'll follow your advice, and shift to ControlD Hagezi TIF; no real need for ad and trackers lists as I use uBOL.
You absolutely should use ad blocking DNS along with uBOL in browser as DNS and ad blocking extensions complement each other. DNS can't block everything; can't hide ad placeholders, can't block ads that are served by first party and this is where your uBOL comes in. It uses cosmetic filtering to hide those annoying blank ad boxes and can even block ads served by the first party.

Using ad blocking DNS also reduces resource usage as uBOL doesn't have to work hard to block ads, considering majority of ad/tracking domains are blocked by DNS before they reach extension.
 
Actually browser extension can do the job much better than dns; I only use dns ad blocking for my phone; I use only Chrome on phone, which does not support extensions.
That is true, but remember: the ultimate goal is to block ads BEFORE they even have a chance to load and this is what DNS does. Ad blocking extensions block the request near the finish line, DNS blocks it at start.

When DNS blocks something, that means less work for your ad blocking extension. And less work for your ad blocking extension, means less CPU usage which translates to extended battery life and better performance for device.
If you were to use only uBlock Origin on your mobile device, you'd notice battery draining more than if you used ad blocking DNS and uBlock Origin together.

This is why you should block everything you can though DNS and what DNS can't solve, pass to ad blocking extension.
 
That is true, but remember: the ultimate goal is to block ads BEFORE they even have a chance to load and this is what DNS does. Ad blocking extensions block the request near the finish line, DNS blocks it at start.

When DNS blocks something, that means less work for your ad blocking extension. And less work for your ad blocking extension, means less CPU usage which translates to extended battery life and better performance for device.
If you were to use only uBlock Origin on your mobile device, you'd notice battery draining more than if you used ad blocking DNS and uBlock Origin together.

This is why you should block everything you can though DNS and what DNS can't solve, pass to ad blocking extension.
I like ControlD so much; the problem, they do not provide an option to use both Hagezi TIF list with one of the ad and tracker blocking ones such as Hagezi Pro++ or OISD big; I have to choose between, or to use ControlD native list which is supposed to encompass both.
 
  • Like
Reactions: Sorrento
I like ControlD so much; the problem, they do not provide an option to use both Hagezi TIF list with one of the ad and tracker blocking ones such as Hagezi Pro++ or OISD big; I have to choose between, or to use ControlD native list which is supposed to encompass both.
You have two options:

1. use ControlD HaGeZi Pro Plus or Ultimate—Pro Plus contains TIF light; Ultimate contains TIF medium
2. use ControlD configurator at the middle of the page and select Ads & Tracking + Malware (uses multiple TIF blocklists).

I myself use ControlD HaGeZi Pro Plus because it uses TIF light which doesn't have any FP. Ultimate uses TIF medium which can have some FPs. Haven't tried Ads & Tracking + Malware though.
 

You may also like...