Google DNS at 010.010.010.010
8.8.8.8
8.8.8.8
https://lucb1e.com/randomprojects/php/funnip.php?ip=8.8.8.8
The variant found by OP is apparently the very last option that my tool generates. These days, Firefox is a bit boring (okay, okay, I'll admit it's a good choice for security) and translates these at the first opportunity. Even hyperlinks are translated on hover in the 'status bar' (if we can still call it that). For mobile users, this is what it shows when you paste one of those addresses in Firefox: https://snipboard.io/kbLTso.jpg
<?php
if (isset($_GET['source'])) {
highlight_file(__FILE__);
exit;
}
This is such a useful and nice snippet I add to many of my PHP files. Open Source at its finest, literally "in place" :-)So basically it allows the reader to read the source directly without hunting it down on github of something.
This is just bizarre, I can’t see a sane codebase where this would be preferable to going on GitHub and pressing “.”
As opposed to which web development ecosystem exactly? The only web development ecosystem with overall decent quality software that I could come up with is Java, and their understanding of quality is... enterprise-y.
Give me a mature PHP framework over a NPM dependency tree, python web framework, or ruby on rails any day. At least when looking for 'quality'. Relatively.
PHP is a very modern and mature language at this point. If the first thing you think of is Wordpress, then you’re behind.
I don't understand your criticism and I suggest you might not either.
Edit: this reminds me, I was like this too at the beginning of my dev career, I also was completely in favor of this supposed “simplicity” of php, only much later, thanks to hickey’s nice talk I realized that I was confusing simplicity with ease.
Are you suggesting that it is bad that PHP applications often have a request path that relates to the folder structure?
In other words, are you suggesting that simplicity means an application should not have a request path that relates to the folder structure?
To give an example, are you saying it's a bad thing that example.com/profile/ loads /profile/index.php, rather than passing /profile through a single controller function to identify what code should be responsible for handling it?
The first approach actually seems pretty straightforward paradigm and it's what most new programmers would expect. Adopting a MVC/routes method is more complex and arguably overkill for a simple application.
If that is what you are contending, it should be said that PHP does not require this approach. Although it is often a preferred approach, because it doesn't depend on additional web server configuration.
Also, let's not lose sight that this arises in a context of criticism of the model adopted for programming a simple form. This is just a simple one page form. More complex or abstract paradigms or design patterns is overkill.
The next on the line is that PHP doesn’t even need anything like version control because you can just copy files over SFTP.
PS: if your project is simple enough to fit in a single file I would argue that most of the time you may use absolutely anything (including a Google Sheet) and you would be equally happy with the results.
127.256 is valid, and would be equivalent to 127.0.1.0. The last integer can be up to 16777215 (2²⁴-1).
Similarly, if you instead include three groups of integers, the first two represents one octet each, and the last represents two. 127.2.256 is equivalent to 127.2.1.0.
Name borrowed from https://github.com/ian-hamlin/ipdec
Note the trietool "list" command prints data as %d not %u. To fix, edit list_enum_func() in trietool.c
sed -n 's/ //;wip4dec.l' << eof
/*
not a domain name or ip address validator
input file format:
(left-justified, no leading spaces)
example.com 93.184.216.34
example.net 93.184.216.34 comment
*/
int fileno(FILE *);
int setenv(const char*,const char*,int);
int unsetenv(const char*);
#define echo do{if(fwrite(yytext,(size_t)yyleng,1,yyout)){}}while(0)
#define jmp (yy_start) = 1 + 2 *
int x=0,y=0,o=0;
xa [0-9]{1,3}\x2e
xb [0-9]{1,3}
xc [0-9]{4,5}
xd ^[A-Za-z0-9\.-]*
xe ^[^A-Za-z0-9]
%s xa
%option noyywrap nounput noinput
%%
{xd} if(yytext[0]=='-'||yytext[0]=='.')jmp 0;else{o=0;y=0;x=0;setenv("x",yytext,1);jmp xa;}
{xe} jmp 0;
<xa>{xc} jmp 0;
<xa>{xa}|{xb} {
switch(o){
case 0: y=atoi(yytext);if(y<1)break;x=y*16777216;y=0;o++;break;
case 1: y=atoi(yytext);if(y>255)break;x=x+y*65536;y=0;o++;break;
case 2: y=atoi(yytext);if(y>255)break;x=x+y*256;y=0;o++;break;
case 3: y=atoi(yytext);if(y>255)break;x=x+y;printf("%s\t%u\n",getenv("x"),x);unsetenv("x");break;
default: break;
}
}
.|\n
%%
int main(){ yylex();exit(0) ;}
eof
flex -8iCrf ip4dec.l
cc -std=c89 -Wall -pedantic -I. -pipe lex.yy.c -static -o ip4dec
usage: ip4dec < input-fileexample:
echo example.com 93.184.216.34 icann|ip4dec
output: example.com 1572395042Name borrowed from https://github.com/ian-hamlin/ipdec
Note the trietool "list" command prints data as decimal not unsigned integer.
sed -n 's/ //;wip4dec.l' << eof
/*
not a domain name or ip address validator
input file format:
(left-justified, no leading spaces)
example.com 93.184.216.34
example.net 93.184.216.34 comment
*/
int fileno(FILE *);
int setenv(const char*,const char*,int);
int unsetenv(const char*);
#define echo do{if(fwrite(yytext,(size_t)yyleng,1,yyout)){}}while(0)
#define jmp (yy_start) = 1 + 2 *
int x=0,y=0,o=0;
xa [0-9]{1,3}\x2e
xb [0-9]{1,3}
xc [0-9]{4,5}
xd ^[A-Za-z0-9\.-]+
xe ^[^A-Za-z0-9]
%s xa
%option noyywrap nounput noinput
%%
{xd} if(yytext[0]=='-'||yytext[0]=='.')jmp 0;else{o=0;y=0;x=0;setenv("x",yytext,1);jmp xa;}
{xe} jmp 0;
<xa>{xc} jmp 0;
<xa>{xa}|{xb} {
switch(o){
case 0: y=atoi(yytext);if(y<1)break;x=y*16777216;y=0;o++;break;
case 1: y=atoi(yytext);if(y>255)break;x=x+y*65536;y=0;o++;break;
case 2: y=atoi(yytext);if(y>255)break;x=x+y*256;y=0;o++;break;
case 3: y=atoi(yytext);if(y>255)break;x=x+y;printf("%s\t%u\n",getenv("x"),x);unsetenv("x");break;
default: break;
}
}
.|\n
%%
int main(){ yylex();exit(0) ;}
eof
flex -8iCrf ip4dec.l
cc -std=c89 -Wall -pedantic -I. -pipe lex.yy.c -static -o ip4dec
usage: ip4dec < input-fileOnly thing I can think of personally is UNIX file permissions.
0644|0755: a=rX,u+w
0600: u=rw
Etc.
You wanna look up what a constant is and you find
#define S_IRUGO (S_IRUSR|S_IRGRP|S_IROTH)
or you could see 0444 and immediately know what it means.I agree in cases where you're modifying existing permissions it's much better to do a `chmod u+w` than to replace the whole thing with octal. When you're defining permissions at the time of creation though, everyone can parse 0644 at a glance.
a=rX,u+w isn't so bad but I don't know if I'd prefer it personally, in code where you can't use chmod syntax I'm definitely preferring octal.
If you split file permissions into two halves - defining the initial permissions / modifying something that already exists - I can see how it makes sense to do both with the same syntax since modifying existing permissions is worse with octal.
Credit: IPv4 addresses are silly, inet_aton(3) doubly so. https://www.netmeister.org/blog/inet_aton.html
I think you probably know that already, but there are at least a couple of ways to interpret what you wrote.
There's also always dns.adguard.com to block Ads (which is what I use on my phone).
What are we looking at here that’s new?
Try this:
curl -v -H "Host: 010.010.010.010" https://8.8.8.8
Trying to do the same with other websites doesn't seem to work. curl -kiH Host:1348764566 https://1348764566
(-k flag needed because I didn't get a valid cert for this variant of the IP. One could also specify the fingerprint but let's keep the demo simple.)It'll give you a 404 because of the unknown vhost, but it would also do that if you access it using the 'normal' dotted decimal notation: http://80.100.131.150
I used to detect this number actually and it would give you a small easter egg, but nobody triggered it and nowadays Firefox doesn't send it as a host header anymore when you specify the IP as such so I didn't check how to port that over to my new web server stack.
You can check it by hovering over the link
curl -v -H "Host: 010.010.010.010" https://8.8.8.8
curl -v -H "Host: 222.222.222.222" https://8.8.8.8
curl -v -H "Host: example.com" https://8.8.8.8The usual reasons are given - protecting children and preventing other illegal activity, which is all well and good and commendable in theory. However there have been instances where the filter has been used to silence opposing political opinions, as well as prevent access to materials on subjective moral grounds (ie "hardcore" pornography, online gambling, discussion of suicides, etc) where the government has decided Aussies shouldn't do that sort of thing, which seems a bit puritanical and mildly thought police-y.
It's not like we're in an "actual dictatorship", by and large the representative democracy trundles along as best these things do, and the life and freedoms we enjoy in Australia make us incredibly privileged compared to much of the world. But this whole online censorship and thought policing our government seems fond of is something I disagree with. In addition to banning certain forms of speech and text, they're now pushing through an act that sets the stage for de-anonymising all users online with a government-issued "Digital ID", the next step presumably being making it illegal to provide and use anonymous web services in Australia. That has broad implications for things like Reporters Without Borders, corporate and government whistleblowers, etc.
Coupled with a historical record of every blocked or "suspect" DNS attempt, and these trends paint a dire picture for individuals who may have legitimate interests or even just curiosity about something like "how are drugs made." Handing this information to the federal government seems risky to me because I don't know what they're going to decide to make illegal to read and write about in the future. Our government has talked seriously about banning encryption many times over the years, and are currently at war against social media, so who knows what they'll do.
That doesn't mean I agree that people should get away with heinous acts or organised crime, but it's why I personally avoid using my ISP's DNS resolution in Australia. I don't exactly trust Google either, but I'd rather they deal with my DNS lookup than our technophobe government.
Sorry for the long rant, probably could have just left it at my first sentence, but it all touches on the one subject in Australian politics that really rubs me the wrong way, and most people I talk to here are of the mind "if you're not doing something wrong, there's nothing to worry about." Just, gah!
Just be careful, because TWNIC/Quad101 was subjected to a BGP hijack in 2019[0]
101.101.101.101 [TWNIC]
80.80.80.80 [FREENOM][1]
4.2.2.2 [Level 3]
[0] https://www.manrs.org/2019/05/public-dns-in-taiwan-the-lates...Short and easy to remember thanks to the classic 2600 zine (named after the Captain Crunch cereal whistle which emitted the 2600hz tone for payphones). I wonder if someone at Sprint is a fan.
X509v3 Subject Alternative Name:
DNS:dns.google, DNS:dns.google.com,
DNS:*.dns.google.com, DNS:8888.google,
DNS:dns64.dns.google,
IP Address:8.8.8.8, IP Address:8.8.4.4,
IP Address:2001:4860:4860:0:0:0:0:8888,
IP Address:2001:4860:4860:0:0:0:0:8844,
IP Address:2001:4860:4860:0:0:0:0:6464,
IP Address:2001:4860:4860:0:0:0:0:64
I'm guessing this is in part for network device auth? DNS over HTTPS?In some ways the actual rules for IP addresses are less strict than for DNS names. Perhaps this will get tightened up. Google Trust Services (the part of Google which issues certificates, as distinct from say, Chrome, which on behalf of Relying Parties has to decide if the certificates are trustworthy) expressed interest in issuing IP address certificates via ACME, ie automatically to anyone who asks. The pushback (including from people in other parts of Google) was considerable, even though what GTS proposed to do was actually more robust than what's technically required for issuance today. But it's nice that they asked (and indeed one argument to allow what they requested is, hey, there was no requirement for them to ask, if somebody had just done this without asking would we have been even more unhappy about that or would we let it slide?)
In practical terms, you likely don't get and don't want certificates with ipAddress SANs in them. You probably don't get them because (unless GTS went ahead subsequently) this is a Special Request item not something your Certbot or acme.sh or whatever can get for you, and you probably don't want them because unless you're a DNS server people expect to type in a name, not a sequence of arcane numbers.
Sounds like a good unit of measurement for Javascript
Almost all of IPv4 is allocated by IANA to Regional Internet Registries that in turn allocate them to customers like Google and Verizon. You pay yearly maintenance fees to keep the addresses assigned to you.
This is most commonly seen with large clouds like AWS buying millions of IPs from owners that weren't using them.
You can use "whowas" to track the ownership shifts, but I don't know of a global index-- each NIC has their own implementation and restrictions.
Cloudflare is way better. It doesn't even look like an IP. And you just can't have shorter.
The practical benefit is that some ISPs run bad DNS servers that e.g. automatically redirect nxdomains to their spam pages. If you use Google or Cloudflare you can bypass this particular anti-feature.
As I discussed here[0], my goto DNS server is 192.168.xxx.91.
Which is to say I run my own recursive resolver. This avoids ISP DNS server issues as well as other issues (like these[1][2]). Also, Google/Cloudflare/whoever don't get to log my DNS queries.
[0] https://news.ycombinator.com/item?id=29026077
[1] https://news.ycombinator.com/item?id=19828317
[2] https://community.spotify.com/t5/Desktop-Windows/Random-Stop...
AFAIK, the only way to prevent your ISP from collecting the domains you visit is if you use something like dns over https. Even then, you're tls connection leaks the domain via sni (hopefully this hole will get plugged by tls 1.3).
Of course. Just as they can see every other packet that comes out of my network.
>AFAIK, the only way to prevent your ISP from collecting the domains you visit is if you use something like dns over https. Even then, you're tls connection leaks the domain via sni (hopefully this hole will get plugged by tls 1.3).
Actually, they can capture or log all your network traffic if they want, not just DNS traffic.
As for DoH/DoT, that's a huge can of worms that I dislike immensely. Why? Because it uses tcp/443. As such, any device that I don't roll myself (roku, fire stick, etc.) could (and with wider adoption, will) perform their own DoH/DoT requests that I can't intercept with my network-based ad/tracking/spying blocker (e.g., Pi-Hole).
That means that blocking ads/tracking is going to become enormously more difficult, unless I block tcp/443, limiting my ability to connect to pretty much any website these days.
And I am much more concerned about that than I am about my ISP logging netflow[0] data, or even capturing all my packets.
What's more, they are extremely unlikely to do the latter. Even with cheap storage, capturing all my packets (and even just the hundreds of other customers that connect to my head-end, let alone the millions of customers they have) isn't economically (or likely even physically) viable.
That said, if you're afraid that your ISP might be doing so, I suggest using a VPN. Then they only see the envelope of the encrypted VPN traffic and that's it.
Given that most data is going to be encrypted anyway (https, ssh, etc.), the fact that they can see where I'm going (which they need to know anyway to route the packets) doesn't really concern me.
As such, if my ISP really wants to capture all my DNS queries and other network connections (assuming they do so for all their customers, as I'm not anyone state-level actors are interested in), they're going to need some ginormous data centers for all that data storage.
Yes, NSA has their ginormous data center in Utah, but they're pulling data from Tier 1 peering points and nothing I do will impact that -- not even using a VPN.
As I said, I'm much more concerned with ads/tracking/spyware, as that's much more likely to be tied to me personally, as those folks want to maintain the fiction that they can effectively "target" advertising at me so they can keep charging the advertisers more and more.
So unless you're someone who some state actor wants to mess with (in which case, you're hosed anyway), blocking the corporate ad spies is more useful than worrying about your ISP. I'd note that Google is one of the biggest of those spies too.
As such, I'm going to focus on a real threat to my privacy that I can actually do something about (which includes doing my own recursive DNS queries), rather than worrying about stuff over which I have no control.
I'm not telling you what to do, just what I do.
[0] https://en.wikipedia.org/wiki/NetFlow
Edit: Added the missing link.
The reason Google provides DNS should be obvious: when people experience a better web, Google makes more money. ISP DNS fuckery is bad for users. Since Google already needs to cache the DNS for its internal purposes, presenting it to the public as a service is close to free for them.
See also: https://01.01.01.01/
(btw: .google and .goog are valid TLDs)
This leaves no room for the ambiguity of the text rendering something like 010.010.010.010 in the certificate itself.
Likewise the dnsName SAN type is defined in an alphabet for X.509 that literally can't represent fancy Unicode, so you can't mistakenly write certificates with dnsName SANs that give the Unicode name instead of the unambiguous punycode name stored in DNS.
These two choices mean your browser can mechanically with 100% reliability check certificates in the Web PKI match the IP address or DNS name from the URL you believed you were visiting, whereas historically the abuse of "Common Name" features to write a human representation had nasty edge cases for both IP addresses and some DNS names.
Whether your URL parser considers that octal IPv4 addresses are a reasonable thing is up to each individual parser. On the whole I'd suggest user-facing software should not permit this because it's pointlessly confusing.
Rust took a patch that says if you try to convert (for example) 010.010.010.010 to an IPv4 address that's an error, which again I think is reasonable for the same reason.
In the patch feedback several people want it to mean 10.10.10.10 and others think it should mean 8.8.8.8 and eventually it seems to become clear to both groups that this is itself a terrible sign for their positions, since if you expected one but got the other now your software has unexpected behaviour, whereas if you got an error you can fix your program to do whatever it was you intended. So hence the error behaviour won.
[Edited to add: It has been pointed out to me that maybe the poster meant .google. Yes, that's a TLD owned by Google. They applied for, and received a number of "new gTLDs" from ICANN, some like .dev are open for you to register 2LDs in, others like .google are only for their own use. Running TLDs likely costs Google somewhere in the region of a million dollars per year to maintain, but that's a drop in the ocean for a large tech company.]
[0] https://en.m.wikipedia.org/wiki/.google [1] https://en.m.wikipedia.org/wiki/Sponsored_top-level_domain
I think what I meant was mostly
> will all or most DNS servers other than Google's resolve .google addresses
I didn't realize Google had bought their own TLD.
I'm not sure how I feel about the sponsored TLDs. I think I like them, mostly. I think I don't love how .google is centered on a single corporation in the same way that I don't like how .gov and .mil have always been so US-centric.
In a way it feels like an intrusion, or somehow misplaced
I've changed the URL above back to https://010.010.010.010/ now. Thanks!
Using your ISP's DNS decreases privacy. I assume you mean that because UDP/53 DNS is unencrypted, if you switch to another DNS provider, then both the ISP and the new DNS can see your requests? In which case I present to you DNS over HTTPS
[1]: See SNI: https://www.cloudflare.com/learning/ssl/what-is-sni/
Also, I remember reading something like HTTPS was leaking URLs...
Though as mentioned this is moot due to SNI, in most cases :(
> Also, I remember reading something like HTTPS was leaking URLs...
Yep, that's SNI
https://www.icsi.berkeley.edu/pubs/networking/redirectingdns...