serverok.pl is a Fediverse instance that uses the ActivityPub protocol. In other words, users at this host can communicate with people that use software like Mastodon, Pleroma, Friendica, etc. all around the world.

This server runs the snac software and there is no automatic sign-up process.

Site description
lonely small server
Admin email
postmaster@serverok.pl
Admin account
@mend0za@serverok.pl

Search results for tag #dns

Viv Oxtra »
@zebulonmysterioso@mas.to

Is there a reliable provider of Private DNS that isn't Google or Cloudflare?
Those are the two main recommendations when I go searching but using either seems, to me, problematic.

    Nominet »
    @Nominet@mastodon.social

    What could you achieve with dedicated time to focus on your project?

    For DNS Fund recipient Miek Gieben, it has meant tackling some of the most complex areas of DNS development and progressing work that might have otherwise crept into his evenings and weekends.

    Read the Q&A: nominet.uk/blog/building-faste

      Infoblox Threat Intel »
      @InfobloxThreatIntel@infosec.exchange

      Three actors. Zero sites compromised. Thousands of victims inherited.

      In the third installment of our dropcatch series, we introduce three new opportunistic scavengers: actors who don't hack websites, but dropcatch the domains previous attackers left embedded in tens of thousands of compromised sites to redirect the inherited traffic to their own operations. We call these actors Stuffy Squirrel, Shady Squirrel, and Swiping Squirrel.

      Most notably, in collaboration with @rmceoin, we discovered Shady Squirrel began using their catalogue of dropcatch domains to send traffic to SocGholish shortly after Operation Endgame's disruption of the actor in June.

      ⛔️ Sample IOCs:
      Stuffy Squirrel: gsstats[.]ru, weatherplllatform[.]com
      Shady Squirrel: advanceslibrary[.]com, blacksaltys[.]com
      Swiping Squirrel: blackshelter[.]org, jqueryapihelpers[.]com

      Full indicators on GitHub. infoblox.com/blog/threat-intel

        OTX Bot » 🤖
        @techbot@social.raytec.co

        Project CAV3RN uses Google Apps Script for stealthy C2 in Israel

        A modular espionage framework targeting entities in Israel has evolved to incorporate sophisticated command-and-control capabilities. The framework employs DNS A-record responses to dynamically select between direct HTTPS connections and a Google Apps Script relay for each transaction, enabling operators to rotate communication channels and deployment identifiers. The communication module uses DNS infrastructure to validate and update Google Apps Script deployment IDs, while XOR encoding obfuscates command-and-control traffic. An inter-component broker coordinates framework DLL components, enabling runtime upgrades without system restarts. The infrastructure leveraged a previously expired Israeli domain, now repurposed with custom authoritative DNS servers, alongside legitimate Google services to blend malicious traffic with normal network activity.

        Pulse ID: 6a7d8cc2109e73821519b31d
        Pulse Link: otx.alienvault.com/pulse/6a7d8
        Pulse Author: AlienVault
        Created: 2026-08-13 09:22:10

        Be advised, this data is unverified and should be considered preliminary. Always do further verification.

          OTX Bot » 🤖
          @techbot@social.raytec.co

          CaptiveCrunch: Midnight Blizzard Weaponizes Hotel Wi-Fi Captive Portals to Steal Microsoft 365 Credentials

          A sophisticated credential theft campaign manipulates DNS and HTTP traffic on captive portal networks at hotels, conference centers, and hospitality venues to redirect victims to attacker-controlled infrastructure. The operation harvests Microsoft 365 credentials through phishing pages, device code phishing abusing Microsoft Entra ID authentication flow, and malware delivery via ClickFix social engineering techniques. Evidence indicates compromised shared captive portal services rather than individual venue breaches, with affected gateways identified in several U.S. cities, India, and Saudi Arabia. The campaign deploys two primary malware tools: CornFlake, a Go-based RAT providing persistent access and extensive surveillance capabilities, and ChocoShell, an in-memory PowerShell stealer that harvests browser credentials, Microsoft 365 tokens, and Azure AD tokens. The operation targets travelers across multiple sectors and has expanded to include Android devices through malicious APK files.

          Pulse ID: 6a7bdb051d6a41c7ea440061
          Pulse Link: otx.alienvault.com/pulse/6a7bd
          Pulse Author: AlienVault
          Created: 2026-08-12 02:31:33

          Be advised, this data is unverified and should be considered preliminary. Always do further verification.

            Infoblox Threat Intel »
            @InfobloxThreatIntel@infosec.exchange

            Season's Scammings 🔅 🎄

            We've been tracking a cluster of personal loan phishing sites that work hard to look like independent lenders — different brands, different domains, even deliberately varied infrastructure.

            Look closely enough, though, and the seams show. Similar underlying templates. The same technology stack. And passive DNS tying their thousands of domains back to the same operator.

            The sites present as loan applications. Name, address, employment details, financial history. And then, at the final step: your Social Security Number. No real company name. No regulatory disclosure. Just a form — and your most sensitive personal data sent off to who-knows-where for who-knows-what.

            A significant portion of the domains are seasonal — Christmas cash, Thanksgiving funds, Black Friday loans. Financially stretched consumers, at exactly the moment they're most likely to reach for a quick fix.
            ⛔ mychristmaswallet[.]com
            ⛔ cashzillaloans[.]com
            ⛔ personalreliefwallet[.]com
            ⛔ thanksgivingcash-5k[.]com
            ⛔ christmascashhelp-direct[.]com

              Infoblox Threat Intel »
              @InfobloxThreatIntel@infosec.exchange

              validx[.]shop looked fine at first glance. "Normal" name servers, a real mail setup, nothing that immediately stood out at the apex level. One subdomain didn't quite fit, though. It was getting DNS queries that were absurdly long and frequent for a new domain that nobody was really visiting. Rather than that being web traffic, we detected it as likely tunneling.

              Turns out it wasn't a one-off. The same setup shows up on hundreds of other domains.

              The domain names follow a similar pattern: short, brandable and portmanteau-y (i.e., cordkit, zenithly, queuebox), spread across a long list of cheap gTLDs with the same registrar.

              The tunnel itself is answering with TXT records like:

              ⚠️ "H2;n=5;k=3;ol=2004;sz=800;cz=gz"

              As best as we can tell, that's a shard count, a reconstruction threshold, a length, a chunk size, and a compression flag. We checked the signature against a number of known DNS tunnelling tools and none of them write a header like this.

              We watched two more domains get registered mid-investigation, hours apart, which was fun to see and immediately block :ablobcatpopcorn:

              We've got the infrastructure and the method. We haven't got a payload, and we haven't matched this header format to anything documented publicly.

              Has anyone else run into this, recognize the TXT format above, or have a sample of a possible malware source? We'd like to hear from you.

              ⛔ validx[.]shop
              ⛔ cordkit[.]online
              ⛔ zenithly[.]best

              ☠️ 95[.]179[.]159[.]229

                OTX Bot » 🤖
                @techbot@social.raytec.co

                Russian AI Slopsquatting Publishes 700+ Malicious NPM Packages

                A threat actor published over 700 malicious packages to the NPM registry within 48 hours using AI-generated typo-squatting package names. These packages deploy a cross-platform RAT and infostealer without requiring install scripts, executing immediately upon import via require(). The downloader supports Windows, Linux, and macOS, rotating through three Cloudflare Workers hosts for payload delivery with a DNS TXT record fallback under wel1.ru. The macOS payload establishes persistence via LaunchAgents and downloads additional beacons. The Linux version delivers what appears to be a Sliver implant. The campaign shows connections to the earlier Moika malware operation, with shared tradecraft including focus on Russian financial institutions, fake telemetry camouflage, and similar kill switch mechanisms. The malware includes anti-analysis capabilities detecting debuggers, virtualization, and packet capture tools.

                Pulse ID: 6a76515e8fbfccabf4dbb65b
                Pulse Link: otx.alienvault.com/pulse/6a765
                Pulse Author: AlienVault
                Created: 2026-08-07 21:42:54

                Be advised, this data is unverified and should be considered preliminary. Always do further verification.

                  Nikhil 🐧 »
                  @realestninja@social.linux.pizza

                  I was just looking at 🤔

                  What is people's experience with it?
                  I was thinking about setting it up for a phone that will be in children's hands to keep them protected from bad shit on the web.

                  The free tier allows 300,000 queries per month... which should be MORE than enough for a kid with limited screentime 🤔

                  privacy-wise, they seem to be base in France, log retention can be disabled, the account can be set up anonymously 🤔

                  Anyone using NextDNS? thoughts? other solutions? (other solutions should please NOT contain the mother of the kid selfhosting pihole with wireguard lmao)

                  nextdns.io/

                    Dr. Dek 👨‍🚀🐧🚀 ) »
                    @portaloffreedom@social.linux.pizza

                    What is the best non spying people use these days?
                    Assume my ISP, OpenDNS (208.67.222.222) , google (8.8.8.8) and cloudflare (1.1.1.1) are not respecting my privacy at all

                      1 ★ 1 ↺
                      d4s boosted

                      mend0za »
                      @mend0za@serverok.pl

                      Тернистый Путь Греха в сетапе личного PrivateDNS для Android со встроенной баннеро-резалкой.

                      Весь мой вчерашний и позавчерашний день, в борьбе с Unbound , DNS-over-TLS , #letsencrypt, AppArmor и, естественно , Linux.

                      #unbound опять не запускается

                      Alt...#unbound опять не запускается

                      #AppArmor мешает #unbound читать сертификаты #letsencrypt

                      Alt...#AppArmor мешает #unbound читать сертификаты #letsencrypt