Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Doesn't work, questions + any recommendations on how to debug? #29

Open
aderchox opened this issue Aug 16, 2024 · 1 comment
Open

Doesn't work, questions + any recommendations on how to debug? #29

aderchox opened this issue Aug 16, 2024 · 1 comment

Comments

@aderchox
Copy link

aderchox commented Aug 16, 2024

I've installed the proxy on a server abroad the geo-blocked region, and took all the steps successfully (including issuing the certificate) without any errors. The server also says it's Active. I'm also receiving requests on the /dns-query path on Nginx, however, browser DoH proxy clients don't recognize it as valid, and Edge as an instance, shows this:
image
I wonder if this is an issue with using a .ir domain name?
The domain records are on Cloudflare, but maybe due to DNS requests taking a recursive path, a .ir domain will still encounters issues on its way? Maybe ccTLDs can block DoH? How do I debug this?
Thanks in advance.

@aderchox
Copy link
Author

Also another question.
I've read somewhere that hackers could abuse such servers! I'd be grateful if you explain whether this is true, and if it is, explain how they can abuse it?
The only thing a DNS server does is, give the IP address corresponding to a domain name, so assuming I've hardened the security of my server properly (there's no faith in any amount of security hardening, but just let's assume that it's secured and cannot be spoofed), I can't imagine how hackers could abuse an impenetrable DoH server to harm any targets?
Of course it is possible to block IPs other than mine, but considering the dynamic nature of home public IP addresses issued by ISPs, I suspect this option is barely useful.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant