Post #4383461
2026-08-04 18:43 UTC
@fullywoolly@mastodon.social @badsamurai@infosec.exchange
Direct2IP means it doesn't need DNS at all, because it already knows the IP-Address it needs/wants to talk to.
So, unless your PiHole _also_ blocks certain known malicious IP-Addresses or -networks (or entire AS for that matter) the DNS blocklists, or enforcing the PiHole's DNS server makes exactly zero difference for that type of malware.
Replies (1)
-
@fullywoolly@mastodon.social 2026-08-04 19:41
@syn_rst@norden.social @badsamurai@infosec.exchange I guess I always assumed that the router would look up the IP and see a substitution for an unreachable address. Is AS Autonomous System? I'll have to look up how to do this in OpenWRT. If you know of a good resource for further reading would you mind sharing it? Also if there are reputable lists of IP/AS to drop, that'd be cool too. I'll go looking regardless but with AI slop I'm worried it might be hard to find. Thanks for the knowledge and helping keep me safer.