Show HN: A site to look up DNS records
dnsrecords.io
dnsrecords.io
Drop me a note at chris at ueland com with any other feedback. Thanks for trying it out!!
asynchronous string manipulation API now available for Docker
Lets say you have a string, and want to print that string to the console.
Now you can use our groundbreaking SaaS offering, to make that easier.
Just pipe the string to our Patent-Pending service, we'll apply our secret sauce, and return back the string for you, so you can call print/echo as you wish.
Example:
var="foo"
print "$(curl -X -d "${var}" http://echo.io)"B) Funny that echo.io is already registered
This site literally wraps a shell command [1]:
dig +nocmd example.com any +multiline +noall +answer
Wrapping shell commands into more usable services isn't necessarily bad. But this is a pretty crazy example.This 'app' is 500K (500 thousand!) lines of PHP. To run one shell command.
1: https://github.com/spatie/dnsrecords.io/blob/master/app/Http...
The source code of the command in question (dig) also doesn't count, because their application literally calls the `dig` shell command. So they need not just those 500K lines of PHP (I didn't bother to count the CSS or JS) but they are also dependent on a shell (probably /bin/sh, which could be anything deepening on their host OS) AND the dig command itself.
I'm not arguing about what command is used - I merely copied the command the site in question is using.
My comment is about the 1/2 million lines of PHP wrapped around that shell command, to present it as a site.
I don't know if the other info is useful to other people. But if so, perhaps you could have a few different "pages". One that gives all the DB stuff, and one that just prints the human readable stuff?
You could have made an nice ui with presents the information in a simple to understand way. Instead if showing stuff like seconds etc. you could have translated it into more understandable.
Instead of saying mx record, you could have used an email icon.
I just check my personal site with this tool and see that is possible know that I use Google G Suite.
Is no way to opt out this? I'm more vulnerable to an attacker, right? They can try to login to my account on gmail.com.
I thought that for not using an email address like @gmail.com, etc. I had the advantage of hiding my login page XD
Maybe I'm a bit paranoid. Sometimes I have the idea that the Internet is not well designed from the ground up for privacy in mind. Recently I check the product Hotjar [0] and was amazed how creepy it is, you can see screen recordings of the users interacting with your site, where are they from, and more. I made a video about this [1] (spanish). Why by default the Internet is like that?, all those features should be opt in imho, with user consent. What do you think?
Excuse me if my wording is not perfect, my english is not the best :)
Well, it's not technically a problem of the internet (the protocol of networked-communication between arbitrary machines), but specifically having a turing-complete language in the browser. The browser sandboxes the language to an extent (so you can't load a webpage and it goes and deletes all files on your computer), but it can't offer protection against any arbitrary program without being able to understand the goal of the program, and whether or not you as a user actually want that goal (or any of its sub-goals).
The problem comes down to: Freedom to act well is also the freedom to act poorly. The browser can't delete all your files, but it also can't organize your files for you. It can track your mouse position across the screen for the sake of recording it... but it can also track your mouse position for the sake of a game.
So it's really a question of how much do you actually want from the browser? Another alternative is to not give it a proper language at all, such that it can only do a predefined subset of behaviors (ie Web 2.0), and thus users are kept safe from any malicious behavior, but of course, at the cost of being kept from any "innovative" behaviors as well. Just fyi, you can enforce this rule if you'd like, by something like the noscript extension, to kill javascript everywhere (and optionally disable it for sites you trust). Half your webpages will break because developers assume javascript, and you can't play any games or fancy websites without opening yourself up to recording, but you'll be safe.
So the choice is yours: Self-impose limitations, or accept the risk.
Most people choose risk (by market-selection), though they may not have realized they ever made a choice, or understood it if they did.
Sorry for the late response, I hope this product had a notification feature and avoid have to be dependent on him accesing to check when someone responds to you.
Others can't send you a mail unless you publish those DNS records that say you use GSuite. Hiding your email host doesn't give you much in the way of security. If you're really concerned about security, see Google's Advanced Protection Program[0].
But I was thinking, a potential attacker receives an email from me (me@customdomain.com), with this tool, they can look up and see that I use G Suite and try to login on my account on gmail.com.
Thanks for letting me know about Google Advanced Protection Program.
Thanks for let me expand my knowledge through education.
[0] https://en.wikipedia.org/wiki/Security_through_obscurity
It would be nice if the page URL would update with each request and provide a copy-pastable link (e.g. https://dnsrecords.io/q/ycombinator.com).
But I liked your UI better.
Would you please provide example command(s) of blocking both ANY queries and NOERROR responses that you've had relative success with?
Thanks!
-A OUTPUT -p udp -m udp --sport 53 -m string --hex-string "|8500|" --algo kmp --from 30 --to 31 -j ACCEPT
-A OUTPUT -p udp -m udp --sport 53 -m string --hex-string "|8400|" --algo kmp --from 30 --to 31 -j ACCEPT
-A OUTPUT -p udp -m udp --sport 53 -j DROP
The above used in the filter table drops anything that does not match NOERROR recursive and NOERROR non-recursive responses. -A PREROUTING -i eth0 -p udp -m udp --dport 53 -m string --hex-string "|0000ff0001|" --algo bm --from 40 --to 65535 -j DROP
The above used in the raw table drops "ANY". It could probably be optimized to search through less of the packet. -A INPUT -i eth0 -p udp -m state --state NEW -m length --length 24:120 -m udp --dport 53 -j ACCEPT
Above is the inbound rule that blocks some overflow attempts.I'll take a crack at implementing something similar, much appreciated!
tcpdump -p -i interface -NNnn -s0 -c100 -SeX port 53
and look for the 8400 and 8500 hex codes and what the number in the far left column is. Then adjust iptables accordingly to look in that part of the packet.Another way to do this is to modify the source code of the DNS server, but I found that to be too time consuming.
Disclaimer: I should also add that the above method of using iptables to drop anything we do not know about does violate some RFC's and instead follows the thing our Mom's taught us, "If you don't have anything nice to say...". That said, you would have to decide if bending some RFC's is ok. In a Corporate environment it can lead to confusion and time lost troubleshooting.
<b onmouseover=alert('XSS')>click me!</b>
open mailbox go house open window get lamp
nothing worked. You might consider adding a game too. That way people could play a game while looking up stuff.
[0]: https://blog.cloudflare.com/what-happened-next-the-deprecati...
Some DNS servers will truncate the response or refuse (like CloudFlare).
But this is nice, it's pretty, and you've got a great domain name which you've put to great use.
Which seems like it could replicate yours with requests like: