Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- # AmberIt (DNS / Port 53 traffic is being hijacked)
- # ICMP Tracerotue to the DNS server
- cinnamon@rolls:~$ sudo traceroute -I -q1 -w1 -n 5.132.191.104
- traceroute to 5.132.191.104 (5.132.191.104), 30 hops max, 60 byte packets
- 1 118.179.180.209 3.253 ms
- 2 *
- 3 202.4.100.253 3.631 ms
- 4 103.12.177.1 3.669 ms
- 5 103.12.176.1 4.163 ms
- 6 103.16.155.13 4.607 ms
- 7 103.16.152.30 4.591 ms
- 8 103.16.152.82 12.737 ms
- 9 27.111.228.81 52.854 ms
- 10 184.105.65.14 189.768 ms
- 11 184.105.80.13 193.056 ms
- 12 184.105.65.57 207.075 ms
- 13 184.104.204.134 204.645 ms
- 14 77.244.255.98 207.248 ms
- 15 77.244.255.149 314.480 ms
- 16 *
- 17 5.132.191.104 205.495 ms
- # DNS Traceroute to the DNS server
- cinnamon@rolls:~$ sudo dnstraceroute --expert -C -t A -s 5.132.191.104 -n facebook.com
- dnstraceroute.py DNS: 5.132.191.104:53, hostname: facebook.com, rdatatype: A
- 1 5.132.191.104 (5.132.191.104) 2.571 ms
- === Expert Hints ===
- [*] path too short (possible DNS hijacking, unless it is a local DNS resolver)
- # DotInternet (DNS / Port 53 traffic is NOT being hijacked)
- # ICMP Tracerotue to the DNS server
- pi@dolores ~ sudo traceroute -I -q1 -w1 -n 5.132.191.104
- traceroute to 5.132.191.104 (5.132.191.104), 30 hops max, 60 byte packets
- 1 59.153.100.16 1.473 ms
- 2 172.16.16.57 1.638 ms
- 3 43.224.113.69 1.646 ms
- 4 103.230.17.112 1.889 ms
- 5 180.87.39.117 41.460 ms
- 6 180.87.38.1 160.067 ms
- 7 80.231.217.29 161.322 ms
- 8 80.231.217.2 160.757 ms
- 9 80.231.200.78 162.859 ms
- 10 195.219.87.31 157.134 ms
- 11 195.219.25.22 179.262 ms
- 12 77.244.255.98 183.051 ms
- 13 77.244.255.149 181.999 ms
- 14 *
- 15 5.132.191.104 180.721 ms
- # DNS Traceroute to the DNS server
- pi@dolores ~ sudo dnstraceroute --expert -C -t A -s 5.132.191.104 -n facebook.com
- dnstraceroute DNS: 5.132.191.104:53, hostname: facebook.com, rdatatype: A
- 1 59.153.100.16 (59.153.100.16) 3.435 ms
- 2 172.16.16.57 (172.16.16.57) 5.480 ms
- 3 43.224.113.69 (43.224.113.69) 5.153 ms
- 4 103.230.17.112 (103.230.17.112) 5.417 ms
- 5 180.87.39.117 (180.87.39.117) 46.877 ms
- 6 180.87.38.1 (180.87.38.1) 164.670 ms
- 7 80.231.217.29 (80.231.217.29) 164.556 ms
- 8 80.231.217.2 (80.231.217.2) 166.780 ms
- 9 80.231.200.78 (80.231.200.78) 167.298 ms
- 10 *
- 11 195.219.25.22 (195.219.25.22) 183.188 ms
- 12 77.244.255.98 (77.244.255.98) 191.329 ms
- 13 77.244.255.149 (77.244.255.149) 185.990 ms
- 14 *
- 15 5.132.191.104 (5.132.191.104) 206.732 ms
- === Expert Hints ===
- [*] public DNS server is next to an invisible hop (probably a firewall)
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement