8 ms·
Reverse DNS IPv4 Map
- system2 3y agoWhy is there a giant blackout after 224.?
- lncoyyis 3y agomulticast, then experimental blocks
- system2 3y agoThanks for creating an account just to answer my question, I guess.
- usr1106 3y agoYes, I noticed that recently when writing a unit test with with randomly created IP addresses. A significant part where deemed as non-routable by the code under test, so I had to limit the first octet < 224. But is that huge allocation really extensively used in real life? How? Or could a significant part just be reallocated for new unicast usage?
- zamadatix 3y agoThe 224.0.0.0/4 multicast space could probably have been made smaller, at least down to a /8 if follow on standards had been written with that kind of size in mind from the beginning, but at this point that'd be like saying "We're going to change 10.0.0.0/8 into 10.0.0.0/16 to free up space everyone, let me know when you've all stopped using it. Thanks!". The space is already in sparse use in corporate networks around the world, you're not going to get everyone to just up and change internal networks to fit less sparsely. If it were that easy IPv6 adoption would be 100% instead of 45%. 240.0.0.0/4 could conceivably be assigned. It's not really in use as it was actually reserved for "future use" from the beginning. That said, if you want to use that space publicly in any reliably usable form you've still got to convince near the entire internet to update their stuff to support/allow it. On this front I'm actually kind of against opening it up even just for internal use as it'd just create another headache to check for and not be particularly reliable. For "extra internal space" 0.0.0.0/8 was in a similar situation and already opened up. If that's not enough for you then you desperately need to move on from IPv4 already.
- usr1106 3y agoWell that's true. Probably there are users that use it in violation of the spec, relying on that it would not harm. Was it 1.1.1.1 that had quite some problems in the beginning of their operation or some similar one? I vaguely remember reading a blog post at the time.
- pests 3y agoYes it was 1.1.1.1. I remember the initial blog post. Before even turning DNS on they just monitored traffic patterns and types to make sure they could handle it.
- sgjohnson 3y agoThat’s actually exactly the reason why Cloudflare got it. They were the only ones at that point who could handle all the garbage that was sent to it, and willing to deal with it at their own expense.
- zamadatix 3y agoFor 240.0.0.0/4 it's not as much existing users violating spec as existing in-spec software and hardware not allowing it. E.g. even if you patched your Linux box and DHCP server to support 224.0.0.0 your hardware router might not forward the packet between zones, your Windows clients might not accept the assignment. In the public case your ISP might not accept it in their router hardware or filters and even if they did it doesn't mean the other 100,000 entities on the internet you're trying to talk to/through do. The same is all true with 224.0.0.0/4 as well plus the fact there is existing in spec use for multicast. 1.1.1.1 was never reserved but it was unassigned until 2010. By that point it had been used improperly so much it received massive amounts of garbage data when advertised (and still does to this day). It's just that "massive" turns to "quite tiny" in context of a giant CDN like Cloudflare so they were able to salvage it.
- KomoD 3y ago> could probably have been made smaller A lot of reserved ranges could've been made smaller, 127.0.0.0/8 is JUST loopback, that's over 16 million ips just for loopback! 0.0.0.0/8 is also just absurd 224.0.0.0/4 and 240.0.0.0/4 are also crazy... over 500 million ips. I probably wouldn't care about it if we didn't have ipv4 exhaustion (which is in my opinion is at least partially the US govt's fault, because they're hoarding 200+ million ips)
- mike_d 3y agoThe solution to IPv4 exhaustion. It is basically unused multicast and "reserved for future use." Only thing standing in our way is the IPv6 proponents who know address space exhaustion is the only thing that will drive adoption of an otherwise shitty idea.
- account-5 3y agoCan you elaborate on why ipv6 is so shitty?
- system2 3y agoI'd assume legacy support isn't there for IPv6. At least for our environments, it wasn't feasible.
- kaliszad 3y agoCould you please elaborate, what were some of the major blockers for you? In some cases, you can "just" add a reverse proxy in front of the legacy services or use some kind of NAT64/ DNS64 setup on the server side. Internal systems can expect IPv4 only for addresses for some kind of accounting, configuration etc. But internal systems that you cannot evolve to support current requirements are a burden anyway. There might be other debt that keeps getting postponed because of these things. I have had a client tell me that some services cannot get a different IPv4 because they don't know about all the things that only know it by its IP instead of its DNS name. I am pretty sure that as a man made software system their system could definitely switch to a different address with some preparation but I am not going to push for it too hard. (It would allow improving the segmentation of their network in turn making it easier to firewall things in a simpler manner. Also, with L3 switches now commonplace it is no longer a question of performance.)
- Avamander 3y agoAbsolutely not the solution, a temporary relief at best. Better to bury this idea.
- usr1106 3y agoThe MIT is bigger than most countries and looks interesting: https://uwe.iki.fi/public/mit.png https://uwe.iki.fi/public/mit.png
- nubinetwork 3y agoAlso goes to show how much is taken up by AWS... but I see a distinct lack of cloudflare.
- usr1106 3y agoSure. But AWS has several "smaller" massive blocks in several places, no such rather regular patterns like MIT in single network. Whith a few exceptions for those adding their own reverse entry and some smaller cloudfront blocks.
- nanmu42 3y agoIt would be cool if there's a blog post on it.
- teddyh 3y agoOriginal: <https://xkcd.com/195/ https://xkcd.com/195/>
- zX41ZdbW 3y agoThank you for posting! There is also a presentation about it: https://presentations.clickhouse.com/meetup85/app/ https://presentations.clickhouse.com/meetup85/app/
- zX41ZdbW 3y agoI want to make it updateable, so we can see how the DNS records change over time. Also, I want to map various scans, similar to https://blog.benjojo.co.uk/post/scan-ping-the-internet-hilbert-curve https://blog.benjojo.co.uk/post/scan-ping-the-internet-hilbe...
- mrngm 3y agoI accidentally stumbled on your project just yesterday evening after reading your comment here https://news.ycombinator.com/item?id=39792381 https://news.ycombinator.com/item?id=39792381 (Hivekit, hexagons and Hilbert spaces). I posted it on a network operator IRC channel, and now it's on HN again, nice to see how that works. Something to add, perhaps, is some sort of map marker and compass per zoom level? What part of the IPv4 space am I seeing, and what are the neighbours? Perhaps you've seen https://map.bgp.tools/ https://map.bgp.tools/ as well?
- jconnop 3y agoCool display! Small feature idea: "find my ip" which zooms to/selects the apparent ip of the current visitor.
- usr1106 3y agoHa, boring :) I just tried to find a couple of addresses I use/know on the map and it was a nice challenge. For octets closer to the center of their highest order square it was quite easy by just trial and error. But for octets at the edge of their square like e.g. 149 I admit having used pen and paper...
- omoikane 3y agoOn this slide: https://presentations.clickhouse.com/meetup85/app/#32 https://presentations.clickhouse.com/meetup85/app/#32 It says the the intent was to make it similar to https://xkcd.com/195/ https://xkcd.com/195/ , i.e. with a space filling curve that preserves grouping, but actual implementation doesn't seem to do that. For example, the upper left squares are: 0 1 2 3 As opposed to 0 1 3 2 Also, 127.0.0.1 is near the right center edge of the map, while 128.0.0.1 is next row down near the left center edge.
- assimpleaspossi 3y agoI can see my house from there!
- lxgr 3y agoNice! A public IPv4 is basically the equivalent of having a swimming pool in Internet real estate these days :)
- spiral09 3y agoNeeeerds
- system2 3y agoYou are on the wrong website if you think this is nerdy.
- xyst 3y agoNow do IPv6
- sgjohnson 3y agoYeah, just go ahead, scan PTR records for some mere 2^120 addresses. Even if we scan just the first address of each /64, it’s still about 2^56. Unlikely anyone is ever going to do it. This is another thing I like about IPv6. Makes mass address scanning completely useless.
- mike_d 3y agoI'm currently mass scanning IPv6, so are others. v6 results have been on Shodan for I think 7 or 8 years at least?
- Avamander 3y agoHow large of a prefix are you scanning and are you preseeding your scans?
- sgjohnson 3y agoAre you aware of what SLAAC does? For the most part your scan results are going to be useless in <24h
- maxmouchet 3y agoHosts with randomized addresses are likely to have auto-generated PTR records, or none at all, so for the purpose of rDNS resolution those are not a big issue. And that’s a detail, but SLAAC as in RFC4842 is deterministic. The randomization is introduced by the privacy extensions in RFC4941.
- mike_d 3y agohttps://www.rfc-editor.org/rfc/rfc7707#section-4 https://www.rfc-editor.org/rfc/rfc7707#section-4 But in general devices using SLAAC are not typically the things you are looking for when scanning.
- deleted 3y ago[deleted]
- aragilar 3y agoWhat (if anything) do the colours of the non-black squares represent (or is there no scheme)?
- walth 3y agoAppears some blocks near (but not in) RFC1918 space are missing?
- londons_explore 3y agoIs SoftBank buying up ips as an investment?
- lencastre 3y agoI was kinda hoping that the biggest patch would be Aws
- MaximilianEmel 3y agoI clicked on a random one, and it happened to be the website of a business a mile away.. What are the chances?
- MaximilianEmel 3y agoOne could draw art onto this, by using different domains to color it. Would be expensive though.