hex0101 How can I test this? I have never noticied it. Custom DNS settings on my PC work.
I don’t have Comcast, so I cannot do any testing, but one reddit post I found suggests that the hijacker rewrites the target ip address, so if you do a nslookup with a fake dns server, fx: nslookup xfinity.com 5.5.5.5
If you get an answer back from that ip, you know something has happened.
My operator also hijacks port 53, but does it differently, so depending on the metod used, the above test may or may not work.
Edit: My hijacker is from F-Secure. It holds the request back, until it has been checked with the cloud (adds 200+ ms to uncached requests going through port 53). If it is safe, the original request will be allowed. If not, the hijacker throws it away and returns its own answer (an ip pointing to a server that displays a warning).
In a case like this, a fake dns server doesn’t reveal it.