Cisco IOS can do funny things sometimes (Possibly my own fuckup) 07-19-2020, 05:37 AM
#1
So recently, firefox has been asking me "Did you mean to go to x.domain?" anytime I typed anything in my URL bar. It's only supposed to do that when it tries to resolve a domain after the search. I found this to be odd, as going to any of the suggested urls brought up a 404 page, but not the standard "not found" firefox normally does. This was driving me crazy, so I decided to dig deeper. I did find some information saying the ISPs may have their own redirect pages, but this was not like that, and I use googles DNS or cloudflare's DNS servers. My next course of action was to check for a DNS leak, it was clean. Trying to isolate the problem, I decided to run a traceroute, not expecting anything to come up. However, I noticed something odd. Bogus domains were resolving to a hosting service by Majestic hosting. Fearing the worst, I began a scan of my system. Further research showed the host was in texas. The scan turned up nothing, and out of desperation, I took a second look at my traceroute, and something else caught my eye: the bogus url I had put in to trace was actually resolving to a subdomain, xxxx.skullmeat.com. I thought "what the fuck? why is that happening?" Then it hit me: skullmeat.com was the throwaway domain I had set for my cisco router (its used for SSH, etc). Acting on a hunch, I changed the routers domain, and the problem went away. So not only did someone have the skullmeat.com domain, it was a host in texas! What are the odds?
TL;DR: Someone had the same domain my router used which caused every random url I typed in to resolve to a subdomain.
TL;DR: Someone had the same domain my router used which caused every random url I typed in to resolve to a subdomain.
(This post was last modified: 07-19-2020, 09:05 AM by Skullmeat.)












![[Image: qcYJ3l.png]](https://i.skull.moe/u/qcYJ3l.png)
![[+]](https://sinister.li/images/modern/collapse_collapsed.png)







