Go Back  FlyerTalk Forums > Travel&Dining > Travel Technology
Reload this Page >

Weird iPhone DNS requests

Community
Wiki Posts
Search

Weird iPhone DNS requests

Thread Tools
 
Search this Thread
 
Old Dec 7, 2021, 9:53 am
  #1  
FlyerTalk Evangelist
Original Poster
 
Join Date: Nov 2002
Location: ORD
Posts: 14,231
Weird iPhone DNS requests

Not really travel related but I know there are a bunch of IT security types floating around here...I happened to take a look at my PiHole DNS logs and Mr. Gfunk's iPhone is making a slew of weird DNS lookups. Every 50-70 seconds it looks up two new domains. Each time the domains are gibberish, like nwj34dkio3p13439.33nlowaos0-dhje33ks.com. The PiHole is returning NXDOMAIN for all of them.

Anyone know what's up?
gfunkdave is offline  
Old Dec 7, 2021, 10:08 am
  #2  
FlyerTalk Evangelist
 
Join Date: Jun 2002
Location: n.y.c.
Posts: 13,988
Perhaps related to this?

https://support.umbrella.com/hc/en-u...ing-in-reports
nerd is offline  
Old Dec 7, 2021, 10:12 am
  #3  
FlyerTalk Evangelist
Original Poster
 
Join Date: Nov 2002
Location: ORD
Posts: 14,231
Originally Posted by nerd
Interesting, thanks. Though he doesn't use Chrome on his iPhone so I don't think that's it. Also don't know why it would do these lookups every minute or so - the article just says Chrome does it on startup.
gfunkdave is offline  
Old Dec 7, 2021, 10:29 am
  #4  
FlyerTalk Evangelist
 
Join Date: Jun 2002
Location: n.y.c.
Posts: 13,988
Originally Posted by gfunkdave
Interesting, thanks. Though he doesn't use Chrome on his iPhone so I don't think that's it. Also don't know why it would do these lookups every minute or so - the article just says Chrome does it on startup.
Correct. Whatever app it is, it's still interested in seeing how invalid domains are handled.
nerd is offline  
Old Dec 7, 2021, 8:30 pm
  #5  
 
Join Date: Jan 2015
Posts: 2,918
Originally Posted by gfunkdave
Not really travel related but I know there are a bunch of IT security types floating around here...I happened to take a look at my PiHole DNS logs and Mr. Gfunk's iPhone is making a slew of weird DNS lookups. Every 50-70 seconds it looks up two new domains. Each time the domains are gibberish, like nwj34dkio3p13439.33nlowaos0-dhje33ks.com. The PiHole is returning NXDOMAIN for all of them.

Anyone know what's up?
A couple of things come to mind. But this reddit thread seems to fit the bill... TLDR: Something on Mr. Gfunk's iphone is trying to determine if the ISP the iphone is using, hijacks the DNS service.

If this doesn't settle it, then you could potentially have other issues which would likely not be pleasant.
StuckInYYZ is offline  


Contact Us - Manage Preferences - Archive - Advertising - Cookie Policy - Privacy Statement - Terms of Service -

This site is owned, operated, and maintained by MH Sub I, LLC dba Internet Brands. Copyright © 2024 MH Sub I, LLC dba Internet Brands. All rights reserved. Designated trademarks are the property of their respective owners.