Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
yatralalala
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
5 ms
·
1.
▲
by
yatralalala
10mo ago
Internet is no longer decenstralised. Some interesting DNS data https://news.ycombinator.com/item?id=46159249
2.
▲
Global DNS State, Part 2 – DNS Centralisation
(reconwave.com)
12 points
by
yatralalala
10mo ago
|
6 comments
3.
▲
by
yatralalala
10mo ago
Given what's happening with Cloudflare downtimes, we looked at internet centralisation. GoDaddy and Cloudflare alone host ~106 millions of domains – about one-third of all the domains. The top 10 providers sit on over half of all the d
4.
▲
by
yatralalala
2y ago
I'm all for in for it. Sadly, companies host wild stuff and forget about it. What we build is primarily focused on companies that have at least hybrid stack - some on prem, some in cloud. If you completely behind load balancer and have
5.
▲
by
yatralalala
2y ago
I'm building Recon Wave ( https://reconwave.com ) - we monitor companies online perimeter and let them know when something's wrong. Recon Wave basically finds and scans all their services - DNS, IPs, Apps, Ports - and no
6.
▲
by
yatralalala
2y ago
Sorry for a bit of self promo, but just to explain we run https://reconwave.com/ , basically EASM product but more focused on network/DNS/setup level. Finding all things about domains is one of the things that we d
7.
▲
by
yatralalala
2y ago
See my comment above https://news.ycombinator.com/item?id=43289743 there are many techniques!
8.
▲
by
yatralalala
2y ago
Zone transfers are super interesting topic. Thanks for mentioning that. It's basically the way how to get all DNS records a DNS server has. Interestingly in some countries this is illegal and in some this is considered best practice. G
9.
▲
by
yatralalala
2y ago
If you're using infra in a way [cloudflare -> your VM] I'd recommend setting firewall on the VM in a way that it can be accessed only from Cloudflare. This way, you will force everyone to go through Cloudflare and utilize all t
10.
▲
by
yatralalala
2y ago
Lifehack - it's especially awesome in cases where server operator is using self-signed certs / private cert authorities. Because you will not find these in public cert logs.
11.
▲
by
yatralalala
2y ago
As always, depends on your threat model. Generally having private IPs in public DNS is not great, because potential attacker gets "a general idea" how your private net looks like. But I'd say there's no issue if everythi
12.
▲
by
yatralalala
2y ago
I sadly did not see the comment above, but I'd like to just add, that this bruteforce and sniffing methods are target only against our paying customers. We built global reverse-DNS dataset solely from cert transparency logs. Our active
13.
▲
by
yatralalala
2y ago
So many thoughts on that, but from my perspective - obscurity is ok, but you can not depend on it at all. Great example is port knocking - it hides your open port from random nmap, but would you leave it as the only mechanism preventing peo
14.
▲
by
yatralalala
2y ago
Hi, our company does this basically "as-a-service". The options how to find it are basically limitless. Best source is probably Certificate Transparency project as others suggested. But it does not end there, some other things tha
15.
▲
by
yatralalala
2y ago
similar thing - https://search.reconwave.com/ - but it's passive and includes reverse dns search (all domains for given IP)
16.
▲
Private RSA keys in DNS TXT data
(twitter.com)
2 points
by
yatralalala
2y ago
|
2 comments
17.
▲
by
yatralalala
2y ago
TLDR: they're used as a revocation mechanism for DKIM. non "paywalled" link: https://threadreaderapp.com/thread/1852021884902138123.html
18.
▲
The Alarming Prevalence of Zone Transfers
(reconwave.com)
1 points
by
yatralalala
2y ago
|
0 comments
19.
▲
by
yatralalala
2y ago
TIL: there's .su gtld
20.
▲
by
yatralalala
2y ago
Very nice, I read one of your blog posts [0] and was pretty surprised, great read! Good luck on your journey. [0] https://reconwave.com/blog/post/storing-private-keys-in-txt-...
21.
▲
Storing RSA Private Keys in DNS TXT Records?
(reconwave.com)
8 points
by
yatralalala
2y ago
|
1 comments
22.
▲
Enumerating DNS zones using NSEC
(reconwave.com)
4 points
by
yatralalala
2y ago
|
1 comments
23.
▲
by
yatralalala
2y ago
Yup, it kinda makes sense, but I agree with other commenters there that plausible deniability is not as strong here.
24.
▲
by
yatralalala
2y ago
Oh wow, just recently started a discussion about this on reddit [0]. Still seems pretty bad idea in all possible scenarios. I don't believe that this "plausible deniability" would be a thing there. [0] https://www.
25.
▲
Empowering Control with Edge Computing
(cdn77.com)
1 points
by
yatralalala
3y ago
|
0 comments
26.
▲
PIHack: Stratosphere Laboratory ChatGPT Hacking Challenge
(pihack.stratosphereips.org)
1 points
by
yatralalala
3y ago
|
0 comments
27.
▲
Anonymous claim to hack Russian TV Channels
(twitter.com)
17 points
by
yatralalala
5y ago
|
1 comments
28.
▲
by
yatralalala
6y ago
Have you heard about Wire? Groups up to 500, when they switch to MLS protocol then thousands, e2e, Swiss based and it has kind of ok UI.
29.
▲
by
yatralalala
6y ago
Wire has backups and is e2e even for groups and all.
30.
▲
Show HN: Katlib – A Companion to Kotlin Standard Library
(github.com)
1 points
by
yatralalala
6y ago
|
1 comments
More ›