Phantom DNS Requests

WireFree

Well-Known Member
Joined
Oct 23, 2005
Messages
448
I have a client who has the following setup, TPlink MR3220 router with a Huawei E303 modem and a Telkom mobile SIM card.

We manually configured the router to forward DNS requests to our DNS server on the Internet, and not use the DNS settings from the mobile operator.

WiFi is disabled on the router and there are no devices connected to the Ethernet ports of the router.

On our DNS server we see DNS requests from the router for the following (not a complete list, there are a few others):
- root dns servers
- www.baidu.com
- www.microsoft.com
- www.nasa.gov
- connect.facebook.net
- ak.ssl.imgfarm.com
- www.google.com
- www.att.com

What's up?
Has anyone come across this before?

This router+modem have been using up to 200MB per day.

Thanks for your replies.
W.
 

WireFree

Well-Known Member
Joined
Oct 23, 2005
Messages
448
So how you connect to the router?

The computer that is used to configure the router via Ethernet is also disconnected from the router. I can see the DNS requests from the router via another computer that is connected to the Internet via fibre.

If the USB modem is unplugged, the DNS requests stop. When the modem is plugged back in, the DNS requests start again after a few minutes from a different IP address, that is assigned to the new 3G connection. Plugging the computer back into the router later and checking the IP address assigned by the network confirms that it is the same IP address.

W.
 

sajunky

Honorary Master
Joined
Nov 1, 2010
Messages
13,124
Interesting. What kind is E303 connection? COM port, NDIS or HiLink? Is there any settings on the modem for accessing management from the WAN?

Also the same for router. What services are configured to be accessible from the WAN?

Either modem or router is hacked. Poor Chinese use it to access free world. Change passwords :)

EDIT: It might be not sufficient. Hardware reset or even flashing firmware could help. Do your client use stock firmware or some downloaded from the WEB Chineese version?
 
Last edited:
Top