Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Seems that hacker is inserting a foreign DNS into my computer, how to remove it?

    Scheduled Pinned Locked Moved Firewalling
    30 Posts 7 Posters 2.2k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • JKnottJ
      JKnott @Firewalldude89
      last edited by

      @Netgate1100guy said in Seems that hacker is inserting a foreign DNS into my computer, how to remove it?:

      There is often a secondary IPv6 address, which seems to be from hacker. Can Link Local IPv6 work
      or what else?

      ????

      Where are you seeing the link local address? Every IPv6 capable device has one. However, given they're not routeable, they'd be pretty much useless for an attacker.

      PfSense running on Qotom mini PC
      i5 CPU, 4 GB memory, 32 GB SSD & 4 Intel Gb Ethernet ports.
      UniFi AC-Lite access point

      I haven't lost my mind. It's around here...somewhere...

      1 Reply Last reply Reply Quote 0
      • F
        Firewalldude89 @johnpoz
        last edited by

        @johnpoz It shows me a login page but it stalls.

        M johnpozJ R 3 Replies Last reply Reply Quote 0
        • M
          michmoor LAYER 8 Rebel Alliance @Firewalldude89
          last edited by

          @Netgate1100guy turn off the firewall and keep it off for 9 days. That should solve it. Come back and let us know if that works.
          Also, as a last resort try turning off the cable modem just in case. You should be clear from the hacker after that. Worked for me

          Firewall: NetGate,Palo Alto-VM,Juniper SRX
          Routing: Juniper, Arista, Cisco
          Switching: Juniper, Arista, Cisco
          Wireless: Unifi, Aruba IAP
          JNCIP,CCNP Enterprise

          R 1 Reply Last reply Reply Quote 1
          • johnpozJ
            johnpoz LAYER 8 Global Moderator @Firewalldude89
            last edited by

            @Netgate1100guy said in Seems that hacker is inserting a foreign DNS into my computer, how to remove it?:

            It shows me a login page but it stalls.

            Stalls? If pfsense has no working dns then yes the login page can be very slow.. From what you posted before - pfsense has only an actual IP on 1 interface - so hard to image that it would have working dns.. So yeah the login is prob going to be very slow.

            An intelligent man is sometimes forced to be drunk to spend time with his fools
            If you get confused: Listen to the Music Play
            Please don't Chat/PM me for help, unless mod related
            SG-4860 24.11 | Lab VMs 2.8, 24.11

            1 Reply Last reply Reply Quote 0
            • R
              rcoleman-netgate Netgate @Firewalldude89
              last edited by rcoleman-netgate

              @Netgate1100guy said in Seems that hacker is inserting a foreign DNS into my computer, how to remove it?:

              @johnpoz It shows me a login page but it stalls.

              Connect via the console.

              Tell your 1100 to reboot.

              Attempt a GUI login again.

              Does the console report any errors?

              However as @johnpoz notes if your WAN isn't connected or your DNS upstream isn't working pages can take some time to load. Also loading the initial dashboard from the LAN also can take time to load but other pages afterwards are quick to load.

              Try loading a subpage after logging in from your URL history. This is how I bypass the 30-second wait.

              Ryan
              Repeat, after me: MESH IS THE DEVIL! MESH IS THE DEVIL!
              Requesting firmware for your Netgate device? https://go.netgate.com
              Switching: Mikrotik, Netgear, Extreme
              Wireless: Aruba, Ubiquiti

              1 Reply Last reply Reply Quote 0
              • R
                rcoleman-netgate Netgate @michmoor
                last edited by

                @michmoor said in Seems that hacker is inserting a foreign DNS into my computer, how to remove it?:

                You should be clear from the hacker after that. Worked for me

                Not helpful...

                Ryan
                Repeat, after me: MESH IS THE DEVIL! MESH IS THE DEVIL!
                Requesting firmware for your Netgate device? https://go.netgate.com
                Switching: Mikrotik, Netgear, Extreme
                Wireless: Aruba, Ubiquiti

                M 1 Reply Last reply Reply Quote 0
                • M
                  michmoor LAYER 8 Rebel Alliance @rcoleman-netgate
                  last edited by michmoor

                  @rcoleman-netgate There is seeking help and then there is trolling. We crossed that boundary several posts ago. If there is no attempt by the OP to seek assistance then how is my attempt at helping any different than others? Plus they stopped responding.

                  Firewall: NetGate,Palo Alto-VM,Juniper SRX
                  Routing: Juniper, Arista, Cisco
                  Switching: Juniper, Arista, Cisco
                  Wireless: Unifi, Aruba IAP
                  JNCIP,CCNP Enterprise

                  R 1 Reply Last reply Reply Quote 0
                  • R
                    rcoleman-netgate Netgate @michmoor
                    last edited by

                    @michmoor said in Seems that hacker is inserting a foreign DNS into my computer, how to remove it?:

                    We crossed that boundary several posts ago.

                    Then you can walk away and turn off notifications on the post.
                    50d3f40a-c5e3-4fdf-aede-d4312485f313-image.png

                    Ryan
                    Repeat, after me: MESH IS THE DEVIL! MESH IS THE DEVIL!
                    Requesting firmware for your Netgate device? https://go.netgate.com
                    Switching: Mikrotik, Netgear, Extreme
                    Wireless: Aruba, Ubiquiti

                    M 1 Reply Last reply Reply Quote 0
                    • M
                      michmoor LAYER 8 Rebel Alliance @rcoleman-netgate
                      last edited by

                      @rcoleman-netgate thats a great option.

                      Firewall: NetGate,Palo Alto-VM,Juniper SRX
                      Routing: Juniper, Arista, Cisco
                      Switching: Juniper, Arista, Cisco
                      Wireless: Unifi, Aruba IAP
                      JNCIP,CCNP Enterprise

                      1 Reply Last reply Reply Quote 0
                      • F
                        Firewalldude89
                        last edited by

                        Hi all, I can now log into admin site on web and it is better now.
                        Link Local for IPv6 seems to be great and can make a hacker intrusion much less likely.

                        A few simple questions:

                        On Suricata and Snort, should I enable interface for both LAN and WAN or just one of them,
                        which of them? Because I have often blocked myself actually and maybe thats because of interface enabled
                        for both LAND and WAN..

                        I have accepted that SSL Inspection or Interception is not that necessary or ideal for blocking a hacker,
                        seems that fine tuned Snort and Suricata settings are far more important.
                        SSL Inspection is used for only clients connected to the LAN network, but not for anyone from the outside,
                        incoming from the web? Is SSL Inspection useless for stopping hackers?

                        What other packages are important for blocking hackers? How can I for example block DoS and DDoS attacks?

                        R GertjanG 2 Replies Last reply Reply Quote 0
                        • R
                          rcoleman-netgate Netgate @Firewalldude89
                          last edited by

                          @Firewalldude89 said in Seems that hacker is inserting a foreign DNS into my computer, how to remove it?:

                          On Suricata and Snort, should I enable interface for both LAN and WAN or just one of them,
                          which of them? Because I have often blocked myself actually and maybe thats because of interface enabled
                          for both LAND and WAN..

                          Best to post this type of question in the IDS/IPS section.

                          Ryan
                          Repeat, after me: MESH IS THE DEVIL! MESH IS THE DEVIL!
                          Requesting firmware for your Netgate device? https://go.netgate.com
                          Switching: Mikrotik, Netgear, Extreme
                          Wireless: Aruba, Ubiquiti

                          1 Reply Last reply Reply Quote 0
                          • GertjanG
                            Gertjan @Firewalldude89
                            last edited by Gertjan

                            @Firewalldude89 said in Seems that hacker is inserting a foreign DNS into my computer, how to remove it?:

                            How can I for example block DoS and DDoS attacks?

                            On your side ? Nothing to do, the default hidden WAN firewall rules is the one rule that will do it all : it blocks all and everything.
                            The only traffic that passes = comes in - is traffic initiated from behind the firewall, like for example a LAN based device.

                            But, as we can compare this to the good old phone network : can you stop some one (or even the entire planet) to call you ?
                            No, of course not.
                            If many, like thousands, try to connect to your WAN, they will all find themselves before a closed door. They will manage to do just one thing : your down stream 'pipe' is full with these access requests. So, no more data comes in - the pipe is full, and no more data gets out, as the pipe is full.
                            And that's what a DOS or DDOS is all about : stopping your Internet access.
                            And yes, it's known that the firewall just 'give up' (goes 'down').

                            The only thing you can do against DOS/DDOS is : be good friends with your ISP, so they can block traffic for you, way upstream.
                            Next best solution : the little boys solution : who has the biggest pipe ? Like : if your WAN upstream / downstream is 100 Gbits / sec then a 'miserable' (still consequent) 10 Gbit sec DOS/DDOS won't even ne noticed by you.

                            No "help me" PM's please. Use the forum, the community will thank you.
                            Edit : and where are the logs ??

                            M 1 Reply Last reply Reply Quote 0
                            • M
                              michmoor LAYER 8 Rebel Alliance @Gertjan
                              last edited by

                              @Gertjan said in Seems that hacker is inserting a foreign DNS into my computer, how to remove it?:

                              Like : if your WAN upstream / downstream is 100 Gbits / sec then a 'miserable' (still consequent) 10 Gbit sec DOS/DDOS won't even ne noticed by you.

                              The only caveat i would add is that the resource utilization of the firewall will be impacted. As far as I am aware there are no built in protections to protect the firewall(pfSense) itself from resource exhaustion if a ddos attack occurs.
                              Typically there are "Zone Protection" features in other products that limit the amount SYNs or UDPs that are allowed.
                              Otherwise inter-vlan traffic on the firewall will be impacted because of a ddos on the WAN.

                              Firewall: NetGate,Palo Alto-VM,Juniper SRX
                              Routing: Juniper, Arista, Cisco
                              Switching: Juniper, Arista, Cisco
                              Wireless: Unifi, Aruba IAP
                              JNCIP,CCNP Enterprise

                              1 Reply Last reply Reply Quote 0
                              • First post
                                Last post
                              Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.