Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
blechschmidt
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
8 ms
·
1.
▲
Show HN: A vibe-coded low-level PKCS#11 Terraform provider
(github.com)
2 points
by
blechschmidt
8mo ago
|
0 comments
2.
▲
by
blechschmidt
4y ago
AFAIK, there are even companies that own hundreds of registrars to just do that [1]. Just scroll through [2]. [1]: https://domainnamewire.com/2015/10/09/wow-dropcatch-adds-300... [2]: https://www.i
3.
▲
ICanProve: digitally signed screenshots and session logs for legal evidence
(icanprove.de)
4 points
by
blechschmidt
9y ago
|
0 comments
4.
▲
by
blechschmidt
9y ago
Blocking a /64 is not even enough in many cases. I know a couple of server providers handing out a /48 per server. If routing is done the right way, you can pretty easily randomize your source address by making use of features lik
5.
▲
by
blechschmidt
9y ago
In my opinion, it is dangerous to draw conclusions about responsibility from phone usage only. Even if the conclusions may be correct in 95% of all cases, what about the other five percent? To me, the imagination of a company that does not
6.
▲
by
blechschmidt
9y ago
I find the title confusing. At first I thought the post was about DNS hijacking or something similar. However, the phishing attack does not make use of identical domains but homographs.
7.
▲
by
blechschmidt
9y ago
You could use libnetfilter_queue and some DNS library like ldns to parse the packets and drop them if the DNS question contains "xn--".
8.
▲
by
blechschmidt
10y ago
A possibility to break these might consist in using Google's image reverse search and check whether the word which you are supposed to identify images for appears on the result pages. However, the Google search is protected by reCaptch
9.
▲
by
blechschmidt
10y ago
This might already filter out legitimate users. dig MX io. Also, you don't know what new TLDs ICANN might come up with at some point. I am pretty sure there are service providers that do and did limit the TLD length and then TLD
10.
▲
by
blechschmidt
10y ago
This is probably a better approach if your domain provider supports wildcard DNS records. My old provider did not and I am very glad I switched.
11.
▲
by
blechschmidt
10y ago
I do not use Gmail but a self-hosted Postfix instance. I have configured an alias for tagged use only and configured Postfix to reject all emails to this alias without a tag. This means that currently any tag will be delivered but luckily,
12.
▲
by
blechschmidt
10y ago
Yes, the + is incredibly useful for tagging emails. When I register new web accounts, I always specify a new unique tag so that I can track down the source in case I receive spam. Furthermore, they help my mail server when filtering out jun
13.
▲
PINCE – A GDB front-end/reverse engineering tool focused on games
(github.com)
93 points
by
blechschmidt
10y ago
|
3 comments
14.
▲
by
blechschmidt
10y ago
Ah, that would mean that I would have the libraries handle the resolving. I was currently only thinking about keeping the single socket which is used in order to only use the parsing functions from the libraries.
15.
▲
by
blechschmidt
10y ago
A look at https://archive.is/https://petition.parliament.uk/petitions/... supports the claim. Although, of course, one cannot really tell how many fraudulent signatures have remained undetected.
16.
▲
by
blechschmidt
10y ago
I have not yet managed to setup a single local recursor, such as PowerDNS recursor, to deliver the same performance as the list consisting of multiple open resolvers, although bandwidth does not seem to be the limiting factor. Testing with
17.
▲
by
blechschmidt
10y ago
Not yet. I have had a quick look at ldns ( https://www.nlnetlabs.nl/projects/ldns/ ) which supports parsing DNS packets from wire . I will probably replace the DNS implementation with either libldns or c-ares.
18.
▲
by
blechschmidt
10y ago
You are correct. Has been fixed.
19.
▲
by
blechschmidt
10y ago
This is the line of code that pre-checks whether an incoming packet should be parsed at all. If it is not a response packet or if the number of questions is not one, it should not be parsed, simply because the packet parsing function expect
20.
▲
by
blechschmidt
10y ago
I have not heard about tindydns before but it seems to be a DNS server, not a client. The tool has mainly been tested on a Hetzner EX41 server. (Ubuntu, Intel® Core™ i7-6700, 32 GB RAM)
21.
▲
by
blechschmidt
10y ago
For DNS cache snooping the usage would of course be different. You would supply the tool with one resolver which does not reject non-recursive queries. Theoretically, one could even perform traffic analyses of DNS resolvers by snooping. Hav
22.
▲
by
blechschmidt
10y ago
Why should that matter in this case? The worst case would have been the output of a wrong value and it was some commented out debug output which I have used in a very specific case.
23.
▲
by
blechschmidt
10y ago
Well, in order to make it correct, I have implemented a --norecurse option.
24.
▲
by
blechschmidt
10y ago
This is already discussed below and you are right. It was an issue with the perspective of the term recursion from my side. Unfortunately, I cannot change the HN title anymore. (Maybe some moderator can?) The GitHub project description has
25.
▲
by
blechschmidt
10y ago
Thank you for pointing this out. This file actually contained some unused code that was not supposed to make it into the repository so I just removed it. The "%x" format specifiers were located in debug comments that have been com
26.
▲
by
blechschmidt
10y ago
Malloc results are checked by the safe_malloc function in security.h. Could you point out a line that is prone to integer overflows?
27.
▲
by
blechschmidt
10y ago
What I mean by non-recursive in this case is that the program does not perform recursion by itself as it relies on a list of DNS resolvers. When querying these resolvers, the recursion bit is actually set. However, I agree that the title mi
28.
▲
Show HN: MassDNS – A high-performance DNS stub resolver in C
(github.com)
35 points
by
blechschmidt
10y ago
|
53 comments