5 ms·
As as aside, I recently goofed up our company website DNS (updated a record on long TTL with an incorrect), but quickly fixed it and found a partial workaround
by nreece 6y ago
As as aside, I recently goofed up our company website DNS (updated a record on long TTL with an incorrect), but quickly fixed it and found a partial workaround to propagation: flush the DNS cache of Google[1] and Cloudflare[2]. It helped with DNS cache refresh within minutes from most global locations, if not all.
[1] https://dns.google/cache https://dns.google/cache
[2] https://1.1.1.1/purge-cache/ https://1.1.1.1/purge-cache/
- saagarjha 6y agoI find it interesting that you can do this for any website at all…
- pathseeker 6y agoIt only costs them a single lookup
- axaxs 6y agoIt's not an attack surface. You're posting relatively tons of data to ask them to do one small lookup.
- bombcar 6y agoIt could be one aspect of a cache poisoning attack. One of the things DNSSEC was to protect against.
- abhishekjha 6y agoI just did it for fb.com. What impact does this have on such huge websites?
- judge2020 6y agoThe cache probably gets re-filled again pretty quickly, if you were to spam this endpoint it'd be more of a problem but I would assume/hope there's rate limiting on it.
- chucky_z 6y agoI would imagine it does some kind of atomic swap, where it's just force updating an existing cache and not actually flushing it.
- mike_d 6y agoNone. For the recursive resolver it is effectively the same as a TTL expiration. The next request initiates a recursion which adds a small number of milliseconds to the response time and is recached.
- titanomachy 6y agoNice find! Filing that away for future reference.
- mike_d 6y agoOpenDNS was the first to expose cache clearing to end users: http://cachecheck.opendns.com/ http://cachecheck.opendns.com/
- pdmccormick 6y agoI was curious as to how a certificate could be issued to an IP address and not a domain (I didn't know that such a thing was possible), and learned this: X509v3 Subject Alternative Name: DNS:cloudflare-dns.com, DNS:*.cloudflare-dns.com, DNS:one.one.one.one, IP Address:1.1.1.1, IP Address:1.0.0.1, IP Address:162.159.36.1, IP Address:162.159.46.1, IP Address:2606:4700:4700:0:0:0:0:1111, IP Address:2606:4700:4700:0:0:0:0:1001, IP Address:2606:4700:4700:0:0:0:0:64, IP Address:2606:4700:4700:0:0:0:0:6400 You can inspect the certificate yourself with: openssl s_client -showcerts -connect 1.1.1.1:443 < /dev/null | openssl x509 -text -noout Too bad Let's Encrypt will not issue certificates for IP's at this time.