BSNL FTTH ONU DNS automatically changed

  • Thread starter Thread starter vishalrao
  • Start date Start date
  • Replies Replies 4
  • Views Views 3,658

vishalrao

The Global Village Idiot
Messages
6,453
Location
Pune
ISP
Tata Play 1 gbps, Jio AirFiber 100 mbps. Prior Microscan 500 mbps, PDPL 300 mbps and BSNL 300 mbps.
Couldn't find the earlier posts/threads where this was discussed.

Today again I noticed my BSNL FTTH modem primary DNS server address was automatically changed to 89.207.131.8 which whois shows some server.inteltek.com in netherlands snel.com owner.

This is the second time is has happened, not sure if this is some DNS malicious attack or a normal BSNL update.

Anyone have any ideas what that DNS IP belongs to?

Searching for the IP in quotes on google returns several people from different countries complaining about this specific IP address!

See https://www.abuseipdb.com/check/89.207.131.8
 
I just found the thread here DNS Hacked in Router | Internet (General Discussions)

@Sushubh can you merge this thread into that original one?
 
Yeah even though I am using the modem in routed/NAT mode I have a netgear r7000 router connected to it which I've set DNS to google dns so no issue of any of my devices getting this possibly malicious DNS server IP :)
 

Back