You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

求助:DNS疑似遭劫持问题排查及解决建议(Ubuntu 17.10)

Hey there, let's tackle this annoying redirect issue together—nothing's more frustrating than a fresh Ubuntu install acting up with unwanted domain hijacks. Here's a step-by-step troubleshooting plan to get to the bottom of it:

1. First, confirm your DNS settings are actually taking effect

Just changing the WiFi DNS doesn't always mean the system is using it. Let's verify:

  • Run systemd-resolve --status and look for the "DNS Servers" section under your active network interface. It should show 8.8.8.8 and 8.8.4.4 if your Google DNS settings stuck.
  • Alternatively, run nslookup testdomain.com and check the "Server" line at the top. If it's not Google's DNS, your system is ignoring the WiFi config.
2. Check for local DNS tampering

Malware or misconfigs often mess with local files first:

  • Inspect your hosts file for suspicious entries: cat /etc/hosts
    Look for any lines pointing to advexplore.com or random IPs that shouldn't be there. If you find something, edit the file with sudo nano /etc/hosts and delete the bad lines.
  • Flush your system's DNS cache to clear any stale hijacked records:
    sudo systemd-resolve --flush-caches
    Then restart the DNS service to be safe: sudo systemctl restart systemd-resolved
3. Rule out browser-specific hijacks

Sometimes the issue is isolated to your browser, not the entire system:

  • Check your browser's default search engine—make sure it's not set to advexplore.com or a weird unknown provider.
  • Disable all browser extensions temporarily, then test accessing a non-existent domain again. A malicious extension could be forcing the redirect.
  • If that doesn't work, reset your browser to its default settings (most browsers have a "Restore defaults" or "Refresh" option in their settings menu).
4. Scan for malware on your system

Even fresh installs can pick up bad stuff if you downloaded software from untrusted sources:

  • Install ClamAV, a free open-source antivirus tool:
    sudo apt-get update && sudo apt-get install clamav
  • Update its virus definitions: sudo freshclam
  • Run a full system scan (this might take a while): sudo clamscan -r /
  • Also, check for suspicious startup programs:
    For GNOME desktop, run gnome-session-properties and look for any unrecognized apps set to launch on startup.
    For system services, run sudo systemctl list-unit-files --type=service and note any services you don't recognize.
5. Test for ISP-level transparent DNS hijacking

Some ISPs force redirects even when you use custom DNS. Let's verify:

  • Run dig randomfakeexamplexyz.com (use any totally made-up domain).
    A normal response with Google DNS should show NXDOMAIN (meaning the domain doesn't exist). If you get an IP address pointing to advexplore.com, your ISP is doing transparent hijacking.
  • If that's the case, try using DNS over TLS (DoT) or a VPN to bypass the ISP's redirects.
6. Fix your resolv.conf configuration (if needed)

Ubuntu 17.10 uses systemd-resolved, which sometimes overrides DNS settings via a linked resolv.conf file:

  • Check what /etc/resolv.conf points to: ls -l /etc/resolv.conf
  • If it's a symlink to /run/systemd/resolve/stub-resolv.conf, we can replace it with a manual config:
    1. Unlink the existing file: sudo unlink /etc/resolv.conf
    2. Create a new file: sudo nano /etc/resolv.conf
    3. Paste these lines:
      nameserver 8.8.8.8
      nameserver 8.8.4.4
      
    4. Save and exit (Ctrl+O, then Ctrl+X in nano)
    5. Restart NetworkManager to apply changes: sudo systemctl restart NetworkManager

If none of these steps fix the redirect, double-check if you installed any third-party network tools or software right before the issue started—sometimes those can inject DNS hijacks.

内容的提问来源于stack exchange,提问作者Brandon Bertelsen

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.19 09:29:52