![](/static/253f0d9b/assets/icons/icon-96x96.png)
![](https://programming.dev/pictrs/image/890e2662-72ba-4735-b443-91b49048766a.png)
sequenceDiagram
Computer->>+Nameserver: Where's wikipedia.org
Nameserver-->>-Computer: 185.15.59.224
Computer->>+Wikipedia: GET /
Wikipedia-->>-Computer: return /
Here is the simplified sequence diagram
As you can see the request to wikipedia itself does not go through a nameserver, only the DNS request does. It’s the entire reason Firefox has the option to proxy DNS queries over the proxy: to avoid DNS leaks
Right now, all that should be happening is DNS requests being proxied, not the rest of your traffic.
There’s a huge difference when I enter https://one.one.one.one/help/ normally with
"Use system proxy settings"
in my browser and when I enter it with a"Manual proxy configuration"
with theSOCKS Host set up
and"Proxy DNS when using SOCKS v5"
checked on.
To me that indicates the DNS proxy through TOR isn’t actually working with your dnscrypt setup 🤔 However it’s difficult to debug from here. It’s possible the DNS query is slow, but because the actual HTTP request is going through your standard internet with no proxy it’s fast, and when you do turn on the proxy for HTTP/S requests, you observe actually using TOR for everything and thus the latency.
Could you run these commands please
# Find which process is running the local DNS server
sudo ss -plant | grep ":53 " # alternatively sudo netstat -plant | grep ":53 "
# Check your DNS resolver config
# You can share it or not, but 127.0.0.1 MUST be in it, otherwise your DNS queries aren't being encrypted/proxied
cat /etc/resolv.conf
# Measure how long it takes to query a new domain name
time dig techhub.hpe.com
time dig bash.org
time dig element.io
If you feel comfortable with it, you share the logs of dnscrypt (I don’t know what kind of information is in there, so you might have to clean it).
journalctl -u dnscrypt-proxy2
or just systemctl status dnscrypt-proxy2
. Either here or PMed. Here are encrypted pastebin alternatives.
So trying to hack hackthebox is not permitted? Confusion is the name of the game
Anti Commercial-AI license