10 ms·
Mess with DNS
- blakesterz 5y agoJulia Evans continues to do so many cool projects! The blog, the zines, now this, such great work! It always amazes me when one person can create so many useful things.
- pknerd 5y agoBecause she loves it! She also cover her strategy here(https://jvns.ca/blog/2021/09/20/teaching-by-filling-in-knowledge-gaps/ https://jvns.ca/blog/2021/09/20/teaching-by-filling-in-knowl...)
- luketheobscure 5y agoI had a few tasks last month that https://nginx-playground.wizardzines.com/ https://nginx-playground.wizardzines.com/ really helped with.
- deleted 5y ago[deleted]
- rektide 5y agoThere's another AWS outage, & presently the top comment is talking about us as barbarians that have stumbled into fancy hot baths & are amazed but have no idea how to keep them running. And a wonderful follow-up reply[1] talking about living in an apartment in a storm versus living in a cave during a storm. It presents another severe image of how much drift there has been in the world, how much more built up, but how we ourselves are not necessarily more advanced, smarter, wiser. It's work like this (Mess with DNS). This is the stuff. Revealing, experimenting, inviting people in. Tech that illuminates & shows off, that is there to explain & help create understanding. This is the stuff, this is what keeps humanity powerful & competent & connected. Tech does a lot for us, but when it helps us become better wiser more creative people, when it reveals itself & the world: that holds a very dear place in my heart, is the light & heat in a vast cold and dark universe. I love this project. It's a capital example of revelatory technology, of enlightening technology. [1] https://news.ycombinator.com/item?id=29568078 https://news.ycombinator.com/item?id=29568078
- ASalazarMX 5y agoHumans individually are pretty useless. Abandon a random human in a jungle and they will likely perish soon no matter how smart and well educated they are. The strength of humanity is teamwork, working together to build things other groups can build things upon. Abandon 100 random humans in the same jungle and they will build a town.
- robrorcroptrer 5y agoHow many would actually be able to build anything if it was purely random? How many tries of 100 people batches until they've built something? Not arguing, just questions that came into my mind.
- ASalazarMX 5y agoRandom people would have the most varied set of skills. A single person can have skills that are useless for surviving in the jungle, but if any of the 100 people has a good enough idea of what to do, the rest can help. Even non-random groups like your coworkers or immediate neighbors can have unexpected skills that will make you feel dumb.
- s_dev 5y ago>Abandon 100 random humans in the same jungle and they will build a town. https://en.wikipedia.org/wiki/Lord_of_the_Flies https://en.wikipedia.org/wiki/Lord_of_the_Flies I'm not sure -- but I do think it would be interesting how that would turn out. Australia would founded in this sort of fashion. I think there's a bit more nuance though.
- gruez 5y agoexcept that's fiction, and this is non-fiction: https://en.wikipedia.org/wiki/Tongan_castaways https://en.wikipedia.org/wiki/Tongan_castaways
- Lammy 5y ago> The strength of humanity is teamwork, working together to build things other groups can build things upon. This is why I don't trust anybody who tries to tell me that human population growth is an actual problem and not just our rulers' fear of irrelevance.
- who-shot-jr 5y agoThis looks great!
- 300bps 5y agoWhat’s happening…when I set a long/short TTL? Real answer: many ISP’s DNS servers are set to ignore whatever you set and use a value they feel works best for themselves.
- rwbhn 5y agoRelevant: https://jvns.ca/blog/2021/12/06/dns-doesn-t-propagate/ https://jvns.ca/blog/2021/12/06/dns-doesn-t-propagate/
- jfrunyon 5y ago> I needed to write an authoritative DNS server Why not just... use an authoritative DNS server? > I think I’m doing a pretty bad of following the DNS RFCs Yeah, probably, which makes this experiment much less worthwhile than just... doing the same thing on an actual DNS host. BTW, experimentation is no replacement for training/education/experience. Just because an experiment results one way on the computer you're testing with, doesn't mean it will resolve the same way in another browser - or on another OS - or even just on a different ISP(/resolver). > finding out who owns IP addresses with an ASN database - When a DNS requests comes in, it comes from an IP address. I wanted to tell users who owns that IP address (Google? Cloudflare? their ISP?). The obvious way is to do a reverse DNS lookup. But what if that doesn’t work? Or just use one of the many databases that exists for exactly this purpose (and are free, like MaxMind's GeoLite ASN). Except, oh wait, you did do that (although with some random, auto-scraped database). Not sure what the point of rDNS is. > I do a database write every time a DNS request comes in Why? There's no reason to store that info on disk. As you say, "I could easily clear out old requests every hour and it probably wouldn’t make a difference" > let’s talk about security Sure, except you skipped over the "huh, I'm sharing cookies across all these people because I'm not on the PSL". But at least "the website's domain" isn't sharing cookies with 'em too? Oh, and you also skipped over things like whether or not your roll-your-own DNS server is vulnerable to being used as an amplification vector (probably). > I have one main opinion about programming, which is that deeply understanding the underlying systems It's a shame she doesn't deeply understand the underlying systems she's using.
- harikb 5y agoOn the security aspect, I wonder how is this site affected services that do domain ownership verification [1] where they assume that only a person who owns the domain can edit dns records. I think letsencrpt ACME protocol [2] does it for SSL certs too. This site does create a subdomain for every user, so may be these issues don't apply. [1] https://support.google.com/a/answer/183895?hl=en https://support.google.com/a/answer/183895?hl=en [2] https://letsencrypt.org/docs/client-options/ https://letsencrypt.org/docs/client-options/
- mlyle 5y agoGenerally a dot is used as a barrier for these, because otherwise you need to have an infinite (and changing) list where users are allowed to register subdomains. .ac.uk vs. .com, etc. Not to mention that there are some of these domains where the policy is changing and there's both delegates and toplevel domains. If you don't trust across separator boundaries you're mostly safe. That is, mytxt.foo.com shouldn't be blindly trusted for my.subdomain.foo.com nor mytxt.subdomain.foo.com shouldn't be trusted for foo.com. IMO the biggest concern is with organizations that blacklist domains for various reasons, because they are not eager to just build very fine-grained blacklists.
- isclever 5y agoAt least for certificate issuance they can turn it off via a CAA record: https://en.wikipedia.org/wiki/DNS_Certification_Authority_Authorization https://en.wikipedia.org/wiki/DNS_Certification_Authority_Au...
- tialaramex 5y agoOne inconvenience is that although RFC8657 explains how to tell a CA that it must use particular methods, the most obvious public CA (Let's Encrypt) has not shipped RFC8657 support. So you can write a CAA record which says "Only Let's Encrypt may issue" or indeed say "Only Sectigo may issue" but you cannot write a record which says e.g. "Only Let's Encrypt may issue, and they must use the tls-alpn-01 method". Or rather, you can write that record but it won't work. Now, there are a bunch of things you could do about that, and I believe this cool toy does one of the obvious ones: Don't have any certificates for the problematic domain. The web site isn't in the domain you can mess with. But it would be nice if Let's Encrypt got to this, periodically I check so far each time somebody has pestered them for RFC 8657 recently, so I don't pile on since that's unhelpful.
- dharmab 5y agoThis is a neat tool! FYI, make sure the domain is registered with Safe Browsing in advance. If one subdomain is cataloged as malicious by google the entire domain can be flagged. It can be a pain to deal with.
- kccqzy 5y agoYou need multiple subdomains to be flagged in order to cause the eTLD+1 domain to be flagged. But then since this is open for anyone to change, I imagine it's really easy to cross that threshold. This is a real risk. When people start adding CNAME's or A's that point to known phishing sites, it's very easy for Google to notice and block.
- AlexanderTheGr8 5y agohypothetically, what happens if a domain is catalogued by malicious? Also who catalogues it? If you haven't bought the domain from Google, the only thing that Google can do is not show the domain on google search results. Did I miss anything?
- tnorthcutt 5y ago> If you haven't bought the domain from Google, the only thing that Google can do is not show the domain on google search results. Did I miss anything? I would imagine they might also show warnings in Chrome.
- iotku 5y agoPretty much all major browsers check against Google's safe browsing list so it's pretty much a death sentence to be on it.
- deleted 5y ago[deleted]
- tialaramex 5y agoIndeed. Google basically gives this service away to browsers. It costs money if you want to build a commercial service using it, but if you give away browsers, no problem. You can switch it off, but you probably shouldn't, even if you're sure you would spot a phishing scam, actually maybe even especially if you're sure you would spot the scam. The service is capable of being quite nuanced since it works on (hashes of) HTTP path segments, so e.g. it can say OK this site https://some.example/ https://some.example/ seems fine except the /cgi-bin/crapscript.php/fake-bank/ pages are clearly a fake bank, and so if your browser tries to visit those pages it gets flagged. But equally it can say OK, everything in bogus.example is bogus, fakebank.bogus.example, harrods.bogus.example, www.news.bogus.examples, it's all bogus, warn for all of it. You can't get the actual list, because if you could of course that mostly helps bad guys. Your browser does a bunch of hash lookups, and it has a fancy tree structure, so it can rule out e.g. OK everything starting FE43 is fine, everything in FD9 is fine etc. If that tree can't rule out a hash it calls Google, who have much finer grained hash data that wouldn't fit in your browser. Also periodically the browser fetches delta updates to the tree from Google.
- beardyw 5y agoLooks like hug of death. Nice when it was going.
- jvns 5y agoRestarted the server and it should be back up for now :). Here's the culprit: > 2021/12/15 18:39:10 http: Accept error: accept tcp [::]:8080: accept4: too many open files; retrying in 1s
- anonymousiam 5y agoAnd then there's this too: https://blog.benjojo.co.uk/post/dns-filesystem-true-cloud-storage-dnsfs https://blog.benjojo.co.uk/post/dns-filesystem-true-cloud-st...
- indigodaddy 5y agoWild stuff
- WakiMiko 5y agoVery cool project! It's interesting to see how different DNS providers cap the maximum TTL. Google uses 21600s Quad9 uses 43200s Cloudflare does not cap at all! And my personal unbound uses 86400s (which is the default)
- m3047 5y agoVery cool. dig 'a test.hazel10.messwithdns.com' txt +short "test" If the owner of the site contacts me I'm happy to discuss...
- darau1 5y agoThe tech is fantastic, and your writing skills also stood out to me. This is excellent work all around.
- lelandfe 5y agoJulia's writing always feels breathable and fun. It's impressive to get technical stuff to be this friendly.
- nimbius 5y ago
- xyzzy_plugh 5y agoThe tone of your comment is pretty inappropriate. The whole point of this is to help people learn about DNS, including the author, who happens to be one of the most humble and helpful persons on the internet. No volume of books can be adequately substituted for doing something, which this project enables handily. I'm sure you'll be down voted to oblivion but maybe consider a more constructive approach, like opening a PR and helping the authors out.
- krisrm 5y agoI don't really agree with the tone of your comment, and why would you cite a section of the article where the author was talking about a front-end testing framework?
- warent 5y agoSomeone is missing knowledge, admits it, and this somehow inflames you? They created a free tool. Nowhere do they claim that this is a comprehensive replacement of a full O'Reilly book.
- deleted 5y ago[deleted]
- throwaway894345 5y agoSome of my fondest memories were learning programming and then infrastructure engineering in bits and pieces while so many “veterans” at the time pissed and moaned about how the One True Way to learn was reading O’Reilly books. A decade into my career, I’m pretty sure I out-earn nearly all of them despite them having a solid decade on me. Of course, income is a fallible indicator, and to the extent that it’s accurate, I don’t think the difference is “reading books vs Googling” but rather (if I had to guess) some handicap that correlates with bitching about how other people learn on the Internet.
- m1ckey 5y agolife is too short for that. it is incredible valuable to have a basic understanding of many things. Julia just built a tool which will help me learn the basics of DNS in 20min.
- maartenh 5y agoNice! A month ago, I scripted https://github.com/moretea/browsers-with-fake-dns https://github.com/moretea/browsers-with-fake-dns as an alternative to editing /etc/hosts. It's a docker container with a BIND DNS server, and chrome/Firefox reachable via webvnc
- NelsonMinar 5y agoThis tool is so neat! One thing I've learned from it is my ISP (sonic.net) seems to be doing queries to _.example.com. For instance: $ dig @50.0.1.1 nelson.lily6.messwithdns.com a Results in two queries being answered by the messwithdns server. One for nelson.lily6.messwithdns.com as expected, but also one for _.lily6.messwithdns.com. Any guesses what that naked underscore query is for? Not every nameserver does it (Cloudflare, Google, Quad9, and Adguard all don't). But Sonic isn't the only one that does. I've asked on Twitter and the best guess right now is it has something to do with RFC2782 or RFC 8552. But those are about using _ to make unique tokens that aren't likely domain names, things like _tcp or _udp. What would a naked _ mean?
- NelsonMinar 5y agoSome useful data on this mystery; Cloudflare DNS doesn't see very many queries for these _ domains globally. So maybe it's something weird my ISP is doing. https://twitter.com/elithrar/status/1471260615947788290 https://twitter.com/elithrar/status/1471260615947788290
- imachine1980_ 5y ago1 fun thing learn about my ISP provider a few days ago is their block example.com
- fanf2 5y agoIt is one of the variants of qname minimization. I wrote the draft algorithm that appears in appendix A of the first experimental RFC describing qname minimization https://datatracker.ietf.org/doc/html/rfc7816#appendix-A https://datatracker.ietf.org/doc/html/rfc7816#appendix-A I wrote it because I wanted more specific advice about how qname minimization should work, and I deliberately aimed it at an ideal world, ignoring obvious interoperability problems. I hoped that this would provoke discussion and get people working towards a more realistic algorithm. But that did not happen until years later. So the early implementations of qname minimization had to invent their own ways of working around the inevitable interop problems, and some of those solutions were quite creative. I think the bare _ version is trying to avoid querying delegation points directly, so that it still gets a referral as it would have done using the full qname. And the _ also avoids problems with negative responses, which are often implemented very badly - it is common to make a mess of the distinction between NXDOMAIN and NODATA.
- Kototama 5y agoVery smart idea and great execution. Allowing to experiment quickly on infras/devops knowledge is the key and tools like Ansible are useless for that.
- anderspitman 5y agoThis is awesome. But I wish a service existed that made domain names easy enough to use that the average person could manage them. IMO you shouldn't have to learn DNS and TLS in order to securely use a domain name. If I want to sign up to have Fastmail host my email, why do I have to manually copy and paste a bunch of DNS records? Fastmail already knows exactly what records need to be set. I should be able to OAuth redirect over to my domain registrar and approve giving Fastmail control over a subdomain of my choosing, and Fastmail should be able to use a simple open protocol to update the records.
- Lyrex 5y agoIn my personal experience I find that zone files work quite well as universal format for that. To pick up your Fastmail example: Fastmail could generate a matching zone file for your domain and let you download it. You could then upload it to any domain service provider that supports importing zone files. It's obviously not as hassle-free than something like your oauth example, but it's using the infrastructure that is already there.
- 63 5y agoIncidentally, just an hour ago I was setting up a mail server on a Digital Ocean droplet, and had to manually copy and paste 20+ DNS entries because Digital Ocean doesn't support zone file upload (only download). So, the zone file seems like a good enough solution if only everyone would use it.
- wpietri 5y agoThat's a good idea, but it would require all the registrars agreeing on a few different protocols and people doing the hard work of implementing them reliably at many, many, many different participants. Since lots of those participants are competitors (e.g., many registrars provide hosting, email service, etc), I think it would be very hard to get enough momentum that places like, say, GoDaddy would feel obligated to participate.
- anderspitman 5y ago
- stephbu 5y agoThis is a really great resource. I wrote a DNS Server in C# once upon a time, it was hard, I wouldn't suggest it to anyone unless the benefit weights up as $millions. I could have killed for a tool like this, instead I spent a tonne of time in PCap and NetMon :( Its out there on my GitHub if folk are interested. Ironically 53 comments just before I added this comment...
- krylon 5y ago> 53 comments Maybe, just maybe, it is an omen? ;-)
- allanrbo 5y agoLove how this just drops you straight into a workspace where you can start experimenting - no sign up required! And the live view of requests is really neat too.
- koshergweilo 5y agoLooks awesome, but I wonder if it could be used by spambots and the like
- henryaj 5y agoThis is absurdly good - great work Julia.
- jeroenhd 5y agoNeat project! Setting up your own DNS server for a throwaway domain is definitely a pain, especially if you've never done so and use anything other than PowerDNS really, so this is useful for messing around with. I do hope the author has set some limits on the DNS configuration you can freely enter. One annoying trick DDoS spammers will use is that they will set up DNS records that are as large as possible to use for their botnet's amplification attack, so allowing them arbitrarily large requests on your domain may be problematic and may cause nasty complaints against your domain. I'd recommend anyone running a free subdomain service (or something super cool like this!) to consider this in their configuration. We can't have nice things because of these bad people :(
- neop1x 5y agoCoreDNS which is commonly used in Kubernetes as a caching DNS server also supports RFC zone files and is very easy to configure. Written in Go, with just a few system library dependencies. I use it for LAN domains + cache + DoT client and it works nicely. I would probably not use it for big production deployments but it actually even supports master-slave transfers. :) Maybe worth having a look at this too.
- silisili 5y agoI just want to applaud this for the effort. I've seen jvns take a similar path to me in engineering over the years, almost uncannily. The difference mostly is that I stored it all in my head, and they take the time to write it up for everyone. Same with DNS. DNS is such a freakin black box, mostly because outside of RFCs, it's some good ol boys club of 'consultants' that don't want to share information. You should see the mailing lists, it's a giant pissing contest. Back on point, I always wanted to distill this information down to make it for everyone, but always hit some small hurdle like... making a website about it. That Julia takes the time to do this and share this is invaluable. It's like a better version of me exists out there, and I'm happy for it.
- thammyvienula 5y agoUla House Spa: Giữa thật giả của ngành làm đẹp, luôn đề cao giá trị cốt lõi là khách hàng Không thể phủ nhận rằng thời đại của nền công nghiệp làm đẹp đã tới. Trước đây, khi nhắc tới “Spa”, người ta sẽ nghĩ ngay đến hoạt động xa xỉ dành cho những người ở tầng lớp thu nhập cao nhưng cho đến nay, những trung tâm thẩm mỹ hay Spa đã trở nên quá phổ biến và quen thuộc với nhiều người. Nguồn:https://eva.vn/lam-dep-moi-ngay/ula-house-spa-giua-that-gia-cua-nganh-lam-dep-luon-de-cao-gia-tri-cot-loi-la-khach-hang-c291a405530.html https://eva.vn/lam-dep-moi-ngay/ula-house-spa-giua-that-gia-...
- Sami_Lehtinen 5y agoCNAME target should be allowed to contain a dash '-'
- mot3 5y agoGood idea, but you have to work on its bugs.