What that (possible DNS-rebind attack)?

Tue Aug 13 23:18:49 2019 daemon.warn dnsmasq[2524]: possible DNS-rebind attack detected: mmbiz.qpic.cn.sched.ssd.tdnsv6.com
Tue Aug 13 23:18:49 2019 daemon.warn dnsmasq[2524]: possible DNS-rebind attack detected: mmbiz.qpic.cn.sched.ssd.tdnsv6.com
Tue Aug 13 23:18:49 2019 daemon.warn dnsmasq[2524]: possible DNS-rebind attack detected: mmbiz.qpic.cn.sched.ssd.tdnsv6.com
Tue Aug 13 23:18:49 2019 daemon.warn dnsmasq[2524]: possible DNS-rebind attack detected: mmbiz.qpic.cn.sched.ssd.tdnsv6.com
Tue Aug 13 23:18:49 2019 daemon.warn dnsmasq[2524]: possible DNS-rebind attack detected: mmbiz.qpic.cn.sched.ssd.tdnsv6.com
Tue Aug 13 23:18:49 2019 daemon.warn dnsmasq[2524]: possible DNS-rebind attack detected: mmbiz.qpic.cn.sched.ssd.tdnsv6.com
Tue Aug 13 23:18:50 2019 daemon.warn dnsmasq[2524]: possible DNS-rebind attack detected: mmbiz.qpic.cn.sched.ssd.tdnsv6.com
Tue Aug 13 23:18:50 2019 daemon.warn dnsmasq[2524]: possible DNS-rebind attack detected: mmbiz.qpic.cn.sched.ssd.tdnsv6.com
Tue Aug 13 23:18:50 2019 daemon.warn dnsmasq[2524]: possible DNS-rebind attack detected: mmbiz.qpic.cn.sched.ssd.tdnsv6.com
Tue Aug 13 23:18:50 2019 daemon.warn dnsmasq[2524]: possible DNS-rebind attack detected: mmbiz.qpic.cn.sched.ssd.tdnsv6.com
Tue Aug 13 23:18:50 2019 daemon.warn dnsmasq[2524]: possible DNS-rebind attack detected: mmbiz.qpic.cn.sched.ssd.tdnsv6.com
Tue Aug 13 23:18:50 2019 daemon.warn dnsmasq[2524]: possible DNS-rebind attack detected: mmbiz.qpic.cn.sched.ssd.tdnsv6.com
Tue Aug 13 23:18:50 2019 daemon.warn dnsmasq[2524]: possible DNS-rebind attack detected: mmbiz.qpic.cn.sched.ssd.tdnsv6.com
Tue Aug 13 23:18:50 2019 daemon.warn dnsmasq[2524]: possible DNS-rebind attack detected: mmbiz.qpic.cn.sched.ssd.tdnsv6.com

This warning appears if a public domain is resolved to a private address (non public ip like 192.168.xxx.xxx etc). The resolution for this domain will fail as long as you see this warning...

Have you set up some custom domains with private ip?

2 Likes

@xiaobo, you've posted about this exact issue before:

1 Like