2

nextdns.io addresses added to a blocklist -> internet goes down

Somehow, nextdns.io was added to a blocklist (Energized Ultimate) just now, and the result was basically nothing worked - could not access the web at all. Until I thought to change DNS servers and check my nextdns account logs, and there it was - nextdns.io addresses being blocked because they had somehow been added to a list I have added.

No idea how / why nextdns.io addresses ended up on that blocklist, but shouldn't nextdns mitigate against its own service being blocked by 3rd party lists? This is basically an attack vector isn't it?

24 replies

null
    • mstgrv
    • 2 yrs ago
    • Reported - view

    Should also add - I have no idea whether that list still blocks nextdns.io - the workaround was to add nextdns.io to my Allowlist. Which is what feels like nextdns itself should be doing silently anyway to prevent this exact situation?

    • mstgrv
    • 2 yrs ago
    • Reported - view

    This also seems weird to me - in my.nextdns.io, Energised Ultimate is listed as having 1385 entries. On its own website, it says it has 628,771. How / why is the list being used by nextdns so different?

    • Emanuel
    • 2 yrs ago
    • Reported - view

    try github.io or anything *.io are blocked, who knows why

    • snoopy168
    • 2 yrs ago
    • Reported - view

    Thanks for this discovery & workaround. I had problem accessing the internet since lunch (2 hrs ago) on my mobile. attempt to add the https DNS link on my Chrome app Android, it kept asking me for a valid URL address. 

    • Seojoon_You
    • 2 yrs ago
    • Reported - view
      • mstgrv
      • 2 yrs ago
      • Reported - view

      Seojoon You https://github.com/EnergizedProtection/block/issues/973#issuecomment-1327087565

      PS: There's likely something broken with @nextdns. Many filters have 0 entries or very few entries against them.
      May be we should reach out to NextDNS support.

      Perhaps ties into my post above about how the Energized Ultimate entry in nextdns quoting an incorrect number of entries (or a number of entries that doesn't match their own website's number)

      • Seojoon_You
      • 2 yrs ago
      • Reported - view

      mstgrv I noticed that other energized filters also have incorrect number of entries

    • mstgrv
    • 2 yrs ago
    • Reported - view

    github.io still being blocked, nextdns says "blocked by Energised Ultimate"

    Downloading the current Energized Ultimate list from their website, github.io (no subdomain) isn't listed as far as I can tell.

    So is nextdns using an out of date list, or did they pull a non-legit list with a bunch of non-legit entries?

    • mstgrv
    • 2 yrs ago
    • Reported - view

    Something screwy is still going on at the moment - my log is showing a particular domain was working fine 14 mins ago, but 8 mins ago it shows up as blocked by Energized Ultimate

    • Seojoon_You
    • 2 yrs ago
    • Reported - view

    the list got updated and there are new domains being blocked

    • mstgrv
    • 2 yrs ago
    • Reported - view

    Yes but still doesn't look correct: 

    github.com/EnergizedProtection/block • 

    1,402 entries • Updated 13 minutes ago

    Compared to 

    • snoopy168
    • 2 yrs ago
    • Reported - view

    My BBC news app draws a blank and several other app also affected.

    Removed the Energized Ultimate & Regional Extension from my settings, until it's restored.

    Using Lightswitch05 - Ads & Tracking & OISD list for the time being. 

    • real_acl
    • 2 yrs ago
    • Reported - view

    Glad this happened out of business hours for me, I just unsubscribed from Energized... But took me a while to realize the issue

    • mstgrv
    • 2 yrs ago
    • Reported - view

    Something seems to be screwy with multiple lists. Nextdns dashboard has AdGuard filters still showing 0 entries and says it was updated 6 hours ago, plus Energized Ultimate has been updated since this all began but seems to be adding new spurious entries, and the entries number quoted on the Nextdns dashboard still doesn't match their own website. 

    Disabling Energized Ultimate is one thing, but there's weirdness with other lists too.

      • snoopy168
      • 2 yrs ago
      • Reported - view

      mstgrv Could this be some kind of anti "ad block list" efforts, to screw things up. I am unsure how it is done but if the Energized list can crash from 600k+ to almost nothing, something isn't right.

      As a backup plan, is there anyway we can add a list by ourselves or something?

    • Seojoon_You
    • 2 yrs ago
    • Reported - view

    just found out discord doesn't work rn

    • Seojoon_You
    • 2 yrs ago
    • Reported - view
    • Seojoon_You
    • 2 yrs ago
    • Reported - view

    actually it seems like all .gg domains are blocked easy.gg doesn't work

    • mstgrv
    • 2 yrs ago
    • Reported - view

    Given github.io is still being blocked, it seems like the list (or the version of it being implemented by nextdns, with its weirdly low entries count) is being updated with entire suffixes like *.io, *.gg, *.me, that sort of thing

    • Meserias
    • 2 yrs ago
    • Reported - view

    many thanks for posting this solution, I was sure that my internet it's fine while I disable temporally my NedDNS on PC and 3 - Phone's. I'm paying for this service and I expect this very very logical think NOT to happen..... how in the world you could block yourself :))
    This is childish thing.... please correct and make sure this will not happen again !

    • mstgrv
    • 2 yrs ago
    • Reported - view

    Energized has a checking tool here: https://energized.pro/check/

    https://energized.pro/check/?domain=github.io -> "github.io domain is not blocked"

    And yet in my dashboard it's still being blocked and it says "Blocked by Energized Ultimate"

    The issue seems to be Nextdns itself - where is it getting this "Energized Ultimate" list from which is blocking entire suffixes and only has 1402 entries?

    • Pierre_Cartier
    • 2 yrs ago
    • Reported - view

    There are many issues with all lists from Energized. Unfortunately the admin in charge of the lists doesn't seem to care. All issues and reports on Github have no answers. 

     

    Solution: working with allow lists or just suppress Energized from your blocking lists. That's what I did because I was getting too mad. 

     

    • Seojoon_You
    • 2 yrs ago
    • Reported - view

Content aside

  • 2 Likes
  • 2 yrs agoLast active
  • 24Replies
  • 441Views
  • 9 Following