This is an old revision of the document!
DNS Hijack
1. Static DHCP leases
LuCI → Network → DHCP and DNS → Static Leases. Establish statics for each camera or OIT device, which helps for tcpdump tracking later.
2. Port 53 intercept (four NAT redirects)
LuCI → Network → Firewall → Port Forwards / Incoming.
General Settings (Camera1 shown; clone and change source IP + internal IP for the others)
Name: Camera1 Restrict to address family: IPv4 only Protocol: TCP + UDP Source zone: res External port: 53 Destination zone: res Internal IP address: 172.66.66.150 (ns5.haacksnetworking.org) Internal port: 53
Advanced Settings Source MAC address:
80:48:2C:44:C7:7D 80:48:2C:41:71:78 80:48:2C:41:69:FF 80:48:2C:46:0E:C4
I decided to give the first two cams/OIT devices back to ns5 and the other two cams/OIT devices back to ns6.
3. DoH / DoT drop
LuCI → Network → Firewall → Traffic Rules.
Name: `Camera DoH` Family: IPv4 and IPv6 From: zone `res` In aDvanced, specify the MACs:
`80:48:2C:41:69:FF`
`80:48:2C:41:71:78` `80:48:2C:44:C7:7D` `80:48:2C:46:0E:C4`
To: zone `wan` Specify that these IPs are blocked (add as needed)
``` 1.1.1.1 1.0.0.1 8.8.8.8 8.8.4.4 9.9.9.9 149.112.112.112 94.140.14.14 94.140.15.15 208.67.222.222 208.67.220.220 185.228.168.9 185.228.169.9 76.76.2.0 76.76.10.0 45.90.28.0 45.90.30.0 ```
Ports: `443`, `853` Action: Drop
Then, once these are setup, confirm using tcpdump on your openWRT router. The basic tcpdump commands to check wan interface (eth1) for leaks:
tcpdump -ni eth1 udp port 53 and '( host 8.8.8.8 or host 8.8.4.4 or host 1.1.1.1 or host 1.0.0.1 or host 9.9.9.9 )' tcpdump -ni eth1 '(tcp port 443 or tcp port 853 or udp port 853)' and '(host 8.8.8.8 or host 8.8.4.4 or host 1.1.1.1 or host 1.0.0.1 or host 9.9.9.9 )' tcpdump -ni eth1 ip6 and udp port 53 and '( host 2001:4860:4860::8888 or host 2001:4860:4860::8844 or host 2606:4700:4700::1111 or host 2606:4700:4700::1001 or host 2620:fe::fe )' tcpdump -ni eth1 ip6 and '(tcp port 443 or tcp port 853 or udp port 853)' and '( host 2001:4860:4860::8888 or host 2001:4860:4860::8844 or host 2606:4700:4700::1111 or host 2606:4700:4700::1001 or host 2620:fe::fe )'
Or, run all at once:
tcpdump -ni eth1 '
(
udp port 53 or
tcp port 443 or
tcp port 853 or
udp port 853
) and (
host 8.8.8.8 or host 8.8.4.4 or
host 1.1.1.1 or host 1.0.0.1 or
host 9.9.9.9 or
host 2001:4860:4860::8888 or host 2001:4860:4860::8844 or
host 2606:4700:4700::1111 or host 2606:4700:4700::1001 or
host 2620:fe::fe
)
'
Or, to just check the cameras (use static ips on the restricted zone) traffic in entirety:
tcpdump -i br-lan.179 host 172.66.66.105 or host 172.66.66.106 or host 172.66.66.107 or host 172.66.66.108 -n
Or, just check outbound 53 / 853, direct udp:
tcpdump -i br-lan.179 host 172.66.66.105 or host 172.66.66.106 or host 172.66.66.107 or host 172.66.66.108 -n | egrep '(\.53 |\.853 )'
Or, check 443 and 853 while stripping the okay stun/turn they need for the app:
tcpdump -i br-lan.179 host 172.66.66.105 or host 172.66.66.106 or host 172.66.66.107 or host 172.66.66.108 -n | egrep -v '(\.443|\.3478|\.8883|ARP)'
— oemb1905 2026/09/06 00:56