Some Fritz!Box modems might have been hijacked

TL;DR: Fritz!Box devices using custom DNS resolution services like Pihole or Adguard might have been compromised by DNS hijacking and using those Fritz!Box devices might be unsafe, especially for Windows users. Update: I updated the article to downscale the severity of the situation. After posting the article on HN, I came to the conclusion based on comments from other HN commenters that the Fritz!Box will not externally resolve *.fritz.box domain names. This it not the case if you use your own

@unixorn @homelab @homelabs

*sigh* And I do. It's actually *from* my ISP.

@unixorn @homelab @homelabs Small clarification on this: you're vulnerable if 1) you are *not* using the Fritz box as your local DNS resolver and 2) you *are* using the Fritz box as your DHCP server, or your DHCP server hands out fritz.box as a domain suffix. If either of those things isn't true, then you're not vulnerable.
@hedders @unixorn I have this setup and my devices aren't adding ".fritz.box" to the domains. As far as I understand DNS suffixes are just added if I do not fill in a complete domain.
This is something I could reproduce. If I type "http://test" in the browser, the domain request in Pi-hole is listed as "test.fritz.box". If the domain is complete "google.com" nothing is added.
I added a wildcard for "fritz.box" in my Pi-hole and everything is working normally.
Am I missing something?
@ottker It's about domain suffixes as well as default search domains. Are you using the Fritz box or your pi-hole as a DHCP server?
@hedders The Fritz box
@ottker Right. Do you have conditional forwarding on your pi-hole to send queries for foo.fritz.box to the Fritz box to resolve?
@hedders Nope, just a wildcard block list entry for fritz.box (but recently added after reading the blog entry)
@ottker Right. So what I would suggest to avoid the vulnerability without breaking local network name resolution is to create a conditional forwarding rule so that queries for anything.fritz.box get forwarded to your Fritz Box for resolution rather than your pi-hole trying to resolve them itself.
@hedders Ok, thank you. 🙂
@unixorn @homelab @homelabs I have a fritz but we do dns differrently. You dont have to use the dns on that box.

@unixorn @homelab @homelabs Better tl;dr: Your post says you have been hacked, the link byline says all modems have been hijacked, the blog headline says some modems have been hijacked, the blog post almost immediately clarifies that it was initially blown out of proportion, and the issue is even less serious than they still believe.

It’s not shorter, but at least it’s accurate.