Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

FYI - Chrome bypasses your DNS Resolvers #350

Closed
TraderStf opened this issue Dec 22, 2019 · 5 comments
Closed

FYI - Chrome bypasses your DNS Resolvers #350

TraderStf opened this issue Dec 22, 2019 · 5 comments

Comments

@TraderStf
Copy link
Contributor

TraderStf commented Dec 22, 2019

Hello,

Block (www.)facebook.com in routeur, /etc/hosts, littlesnitch...
All DNS Resolvers are set to e.g. : 1.1.1.1 ip4/6
8.8.8.8 or others google DNS IP4/6 are NOT existing anywhere
No VPN...

Click on a facebook.com link.

After few seconds, FaceCrooK can't be reached
LittleSnitch displays Chrome wants to connect to 8.8.8.8, Deny, 8.8.8.4

Chrome bypasses user/router/mac settings 👎

To disable this:

Chrome prefs
Google-Sync
Disable ~'display site suggestions if it can not be reached'

Thanks

MC & HNY ⛄️

@drduh
Copy link
Owner

drduh commented Dec 23, 2019

Good eye, may make sense to sinkhole traffic to those addresses with PF as well.

@TraderStf
Copy link
Contributor Author

Will test few others. wonder if it's chrome or chromium.

Should make a sinkhole for internet apps: chrome, ff, safari, mail...

I think to all the checking included in them: update, safe site, pw stolen... and more obvious one like 'remote-fonts' and all those little 'nice trackers' provided for our security 👀

@TraderStf
Copy link
Contributor Author

FYI, for the sinkhole
https://developers.google.com/speed/public-dns/docs/dns64

@TraderStf
Copy link
Contributor Author

FYI, don't want to create a new case. We should have some kind of blabla case/posts.

This might perhaps interest you
https://www.sentinelone.com/blog/macos-red-team-calling-apple-apis-without-building-binaries/

I will post asap the connections made by most browsers.

@drduh
Copy link
Owner

drduh commented Feb 6, 2020

Updated with 7aa6381

@drduh drduh closed this as completed Feb 6, 2020
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants