This is an old revision of the document!
DNS Hijack
Let's make sure wyze is not leaking … after dropping all 443 853 to DoH and hijacking all udp53 and sending it back to the pihole:
tcpdump -ni eth1 udp port 53 and '( host 8.8.8.8 or host 8.8.4.4 or host 1.1.1.1 or host 1.0.0.1 or host 9.9.9.9 )' tcpdump -ni eth1 '(tcp port 443 or tcp port 853 or udp port 853)' and '(host 8.8.8.8 or host 8.8.4.4 or host 1.1.1.1 or host 1.0.0.1 or host 9.9.9.9 )' tcpdump -ni eth1 ip6 and udp port 53 and '( host 2001:4860:4860::8888 or host 2001:4860:4860::8844 or host 2606:4700:4700::1111 or host 2606:4700:4700::1001 or host 2620:fe::fe )' tcpdump -ni eth1 ip6 and '(tcp port 443 or tcp port 853 or udp port 853)' and '( host 2001:4860:4860::8888 or host 2001:4860:4860::8844 or host 2606:4700:4700::1111 or host 2606:4700:4700::1001 or host 2620:fe::fe )'
Or, run all at once:
tcpdump -ni eth1 '
(
udp port 53 or
tcp port 443 or
tcp port 853 or
udp port 853
) and (
host 8.8.8.8 or host 8.8.4.4 or
host 1.1.1.1 or host 1.0.0.1 or
host 9.9.9.9 or
host 2001:4860:4860::8888 or host 2001:4860:4860::8844 or
host 2606:4700:4700::1111 or host 2606:4700:4700::1001 or
host 2620:fe::fe
)
'
Or, to just check the cameras (use static ips on the restricted zone):
tcpdump -i br-lan.179 host 172.66.66.105 or host 172.66.66.106 or host 172.66.66.107 or host 172.66.66.108 -n
— oemb1905 2026/09/06 00:56