Homebrew RELEASE 90DNS: DNS server for blocking all Nintendo Servers

AveSatanas

Well-Known Member
OP
Member
Joined
Aug 7, 2018
Messages
153
Trophies
0
XP
950
Country
Chad
So I set 163.172.141.219" and secondary DNS to "45.248.48.62. I can establish the connection to my WiFi with these settings but performing the connection test in the internet options results in a "unable to connect". Is that intended?

Edit: is there a way to prevent my Switch to connect to the internet entirely, but allow WiFi connection to my router and therefor my connected PC. I just want to use it for installing my NSPs.
Connection test failing is a sign that 90dns is working as it hits up dauth IIRC.

---

I read up on it and it seems like good ban protection even against hard coded IPs, unlike just protecting against name resolution. I'll use both that and 90DNS!
Honestly, I'm happy that blawar brought prodinfo mods to the table again, but I've some worries as I've been told that prodinfo is cached in system savefiles, and I'm personally worried about the telemetry your console uploads which may still have your account, ticket etc data which can be used to ban your console or account.

Right now it might prevent my own concerns as it does break your client cert, but N could always just allow any client cert to connect (on telemetry endpoints) and send telemetry and ban people. This is a much bigger risk than a fw update happening and adding hardcoded IPs because it actually can be done by N on serverside at any time.

IMO the proper way to use incognito would be to run it, then do a factory reset, but this isn't what you're told on its README or thread, so I'm worried for people thinking that they can run it once and be safe forever.

Also doing a factory reset isn't really favorable to all, as you lose all of your games, and as your prodinfo is gone, you can't re-download them from eshop, meaning that you'll need to stick to cart games, backups or "backups". With cart games you're missing out on a lot of eshop only titles, and with backups/"backups", you are required to use ES patches, and this will not only exclude you from support on various big communities, but also force you to wait before updating as the patches take time to be updated.

But all in all, I think that incognito could be improved and de-snarked, and perhaps then I will appreciate and recommend it more.
 
Last edited by AveSatanas,

blawar

Developer
Developer
Joined
Nov 21, 2016
Messages
1,708
Trophies
1
Age
40
XP
4,311
Country
United States
Connection test failing is a sign that 90dns is working as it hits up dauth IIRC.

---


Honestly, I'm happy that blawar brought prodinfo mods to the table again, but I've some worries as I've been told that prodinfo is cached in system savefiles, and I'm personally worried about the telemetry your console uploads which may still have your account, ticket etc data which can be tlused to ban your console or account.

Right now it might prevent my own concerns as it does break your client cert, but N could always just allow any client cert to connect and send telemetry and ban people. This is a much bigger risk than a fw update happening and adding hardcoded IPs because it actually can be done by N on serverside at any time.

IMO the proper way to use incognito would be to run it, then do a factory reset, but this isn't what you're told on its README or thread, so I'm worried for people thinking that they can run it once and be safe forever.

Also doing a factory reset isn't really favorable to all, as you lose all of your games, and as your prodinfo is gone, you can't re-download them from eshop, meaning that you'll need to stick to cart games, backups or "backups". With cart games you're missing out on a lot of eshop only titles, and with backups/"backups", you are required to use ES patches, and this will not only exclude you from support on various big communities, but also force you to wait before updating as the patches take time to be updated.

But all in all, I think that incognito could be improved and de-snarked, and perhaps then I will appreciate and recommend it more.

incognito kills the ssl cert, so no data is ever sent to nintendo’s servers. the connection isn’t even attempted.

there is some ssl data cached in the system save file, but it does not appear to be important, and again all of the ssl connections fail.

there is more work to be done, to make it better, however it works well on 7.x as is.
 

dexter90

Active Member
Newcomer
Joined
Nov 20, 2016
Messages
30
Trophies
0
Age
34
XP
156
Country
Italy
Hello everyone, I wanted to ask a very simple question. 90dns should not block nintendo servers? I use 90dns on all the wireless networks stored, today it tells me that an update is ready for the console. Why? Did something happen or 90dns only blocks some nintendo servers? How come today tells me that there is an update? I do not really care about the ban at the end ... I try to avoid it, but having the switch mod I know if it happens, peace and good. :) I know that refers to version 7.0 or above, but I wanted to understand how he managed to pass
 

jester_

Well-Known Member
Member
Joined
Sep 20, 2018
Messages
172
Trophies
0
XP
740
Country
United States
....

According to people here, it's your ISPs fault? I'm not sure. I'm using 90dns + incognito and no update prompts so far
 

dexter90

Active Member
Newcomer
Joined
Nov 20, 2016
Messages
30
Trophies
0
Age
34
XP
156
Country
Italy
i use many wireless network with many isp. but in the last month i only use my home newtwork... but if 90dns block the request to nintendo server, how did you upgrade? how could my isp fail if there are no requests to their dns but at 90dns? it's not a criticism, but I'm curious to understand why.

--------------------- MERGED ---------------------------

sorry for the double post...
I do not remember if the switch has the ability to connect automatically to open wireless networks ... unfortunately I happen to find a little and maybe it is precisely there the problem. In my home i have a router Fastweb and all traffic all redirect to my physical firewall sophos. I can create a vlan for one wirelle network for switch, but when i go outside? for this reason i use 90dns. ok... I think my switch has a different problem ... with active airplane mode, the wifi works the same perfectly ... has it already happened?
in the settings airplane mode, the wifi, nfc and bt are off...

91RQAg3.jpg
 
Last edited by dexter90,

AveSatanas

Well-Known Member
OP
Member
Joined
Aug 7, 2018
Messages
153
Trophies
0
XP
950
Country
Chad
Hello everyone, I wanted to ask a very simple question. 90dns should not block nintendo servers? I use 90dns on all the wireless networks stored, today it tells me that an update is ready for the console. Why? Did something happen or 90dns only blocks some nintendo servers? How come today tells me that there is an update? I do not really care about the ban at the end ... I try to avoid it, but having the switch mod I know if it happens, peace and good. :) I know that refers to version 7.0 or above, but I wanted to understand how he managed to pass
Honestly, I've no idea why this happens, but it doesn't necessarily mean that you're not correctly connected (fyi, I've talked with people who got firmware update but were correctly connected, and they weren't banned when they restored to a clean nand), try running tester.

I've tried on many different OFW versions, many regions, reinstalled HOS etc etc, and it doesn't happen for me, or for many others. I can't repro it, I can't fix it.

I think only thing I haven't tried (or asked people about) is testing with anything but stock and Atmosphere, so... Are you using a CFW? If so, which one?

Also: If anyone's who's having this issue that is also willing to help me out by setting up a proxy server (charles/fiddler), installing SSL patches and listening to network queries, lmk.
 
Last edited by AveSatanas,

dexter90

Active Member
Newcomer
Joined
Nov 20, 2016
Messages
30
Trophies
0
Age
34
XP
156
Country
Italy
Thk for the reply. Personally as I said it does not create problems .. I'm not fixed with ban or similar things. In theory I should not be banned or banned, but I do not understand how it goes to pass the same. Probably the switch connects to open wifi networks. Confirm? I'm asking you this because maybe I'm creating a problem that does not exist. The only problem is that it works with wifi mode, but this does not hit anything with 90dns .. I use Kosmos CFW. If you need a beta tester, when i can i help you to test. Sorry for me bad english
 
Last edited by dexter90,
D

Deleted User

Guest
Is it confirmed blocking all the N's servers on 7.0.0 and 7.0 1?

in op it's not mentioned.

I run it on 7.0.1 but I ran the Python script first to confirm on my PC to make sure it blocks Ninty servers.
 

NoNAND

Give me back my legions!
Member
Joined
Aug 22, 2015
Messages
2,274
Trophies
1
Location
Somewhere
XP
5,064
Country
Albania
i think the dns is not functioning as it should. my switch is nagging me to install the 7.0 update even that i still have 90dns set up. how did it download the update i wonder.
 

Picalo

Well-Known Member
Newcomer
Joined
Feb 18, 2019
Messages
89
Trophies
0
Age
44
XP
298
Country
United States
Is there away to block the update like the ps4 by putting a fake update file in the update folder in order to block nint from telling the system to download the file?
 

developer_su

Developer
Developer
Joined
Feb 18, 2019
Messages
163
Trophies
0
XP
1,884
Country
Russia
Thanks a lot! OpenWRT settings are very useful and saved a lot of time! Also NGINX configuration helped!
Just deployed docker container and viola! (Thinking about moving this to inetd@oWRT to simplify.. but not deep enough in it and not sure yet). Also, I guess, paranoiacs may restrict any packets that out-coming to WAN.. I did it for ICMP:D/UDP/TCP and a bit worry that Nintendo uses some protocol I missed..
Anyway, you're doing awesome things ( ^-^)_\m/
 

OrGoN3

Well-Known Member
Member
Joined
Apr 23, 2007
Messages
3,241
Trophies
1
XP
3,253
Country
United States
Is there easier way to use this? Like how stealth mode works on sxos?
  • Go to System Settings
  • Go to Internet tab
  • Open Internet Settings
  • If you already have a wifi network: Tap on your wifi network, pick Change Settings
  • If you don't have a wifi network added, open Manual Setup and set up your network name, SSID and Security
  • Set DNS Settings to Manual, and set primary DNS to "163.172.141.219" and secondary DNS to "45.248.48.62"
  • Save and then connect to wifi

That sounds pretty easy to me...
 
  • Like
Reactions: aos10

Site & Scene News

Popular threads in this forum

General chit-chat
Help Users
    Xdqwerty @ Xdqwerty: good night