DNS Toys
dns.toys
dns.toys
I love this. It doesn’t need a reason to exist. It’s interesting on its own.
That being said, can anyone think of additional interesting reasons for why this would be useful rather than the same toys over HTTP?
How did DNS resolution work? Do they force you to use their proxy server?
Anyway if you're using a 14.4 modem in a rusty bunker at the bottom of the sea you'll notice a substantial improvement :)
On a TLS1.3 QUIC connection with a session supporting 0-rtt would DNS still require less round trips?
I measured the difference using `tcpdump`, and this was my conclusion:
> A big advantage of using DNS queries instead of HTTP queries is bandwidth: querying ns-aws.sslip.io requires a mere 592 bytes spread over 2 packets; Querying https://icanhazip.com/ requires 8692 bytes spread out over 34 packets—over 14 times as much! Admittedly bandwidth usage is a bigger concern for the one hosting the service than the one using the service.
(I had set up a service to determine your IP address via DNS, i.e. `dig @ns.sslip.io txt ip.sslip.io +short`, and measured why it was (marginally) better than using HTTP)
https://resources.infosecinstitute.com/topic/bypassing-secur...
That availability can also be used for good.
Just setup openvpn with port 53 UDP with cheap vps, then connect it, and get unlimited internet access
Internet connection in my country is very limited and expensive in that day
I never thought to use DNS as a tunnel, but I have seen some pretty interesting loopholes that I was trying to find. Some airline's captive portal used to rely on some google service (captcha probs), and for a period of time didn't block any google-owned IP address that wasn't a consumer website (eg search, yt) so GCP and developer docs would load if you had the URL. I couldn't reliably get to user-generated content through it though.
Most firewalls drop or hijack packets on port 53.
Add a bonus withering stare for assuming JSON is the only data serialization/interchange format.
Typically these are used like this: your mail server gets an SMTP connection from some address (let's use the familiar IPv4 example): 10.20.30.40.
You reverse these octets and do an "A" record dns query to some 40.30.10.10.dnsbl.example.com to look up that IP in example.com's list. If a match is returned, the address is listed. If you do a "TXT" record query, you can find out why it's listed.
Block lists are typically blacklists, but they can be whitelists as well.
DNSBL's are hammered with queries from vast numbers of mail servers; DNS keeps things efficient.
> dig pi.neomantra.net +short
3.141.59.26
> dig pi.neomantra.net +short -t AAAA
3141:5926:5358:9793:2384:6264:3383:2795
Just added pi support to it:
https://github.com/knadh/dns.toys/pull/9Recursive
DNSCACHEIP=185.49.141.200 dnstxt 4.9.+.3.+.7.+.7.+.7.+.5.+.rp.secret-wg.org
dq txt 4.9.+.3.+.7.+.7.+.7.+.5.+.rp.secret-wg.org
drill 4.9.+.3.+.7.+.7.+.7.+.5.+.rp.secret-wg.org txt
kdig 4.9.+.3.+.7.+.7.+.7.+.5.+.rp.secret-wg.org txt
dig 4.9.+.3.+.7.+.7.+.7.+.5.+.rp.secret-wg.org txt
Non-recursive dnsq txt 4.9.+.3.+.7.+.7.+.7.+.5.+.rp.secret-wg.org 185.49.141.200
dq -a txt 4.9.+.3.+.7.+.7.+.7.+.5.+.rp.secret-wg.org 185.49.141.200
drill -ord 4.9.+.3.+.7.+.7.+.7.+.5.+.rp.secret-wg.org @185.49.141.200 txt
kdig +nord 4.9.+.3.+.7.+.7.+.7.+.5.+.rp.secret-wg.org @185.49.141.200 txt
dig +nord 4.9.+.3.+.7.+.7.+.7.+.5.+.rp.secret-wg.org @185.49.141.200 txt
Two different TXT RRs will be returned. The second one is new as of last year.Read more at https://bert.secret-wg.org/Tools/index.html
Instead of DoH it would be HoD.
Eg.
dig newyork.time.dns.toys with a low ttl?
This way folks operating in an environment where they can't egress on port 53 can still use the tools?
dig +short
instead of dig +noall +answer +additional
i.e. dig +short mumbai.time @dns.toys
gives you the short and breve answer you probably expect :-) dig +short london.time @dns.toys |head -n 1 |cut -d '"' -f4
In order to get clean time for a city, for example. At which point you'd be better learning the arguments to local tools. But anyway, cute hack and cool mountain-name. :)And furthermore, +short gives you the same multiple answers that +noall +answer +additional does, without the extra dns stuff that you don't need.
$ dig seat2222tle.time @dns.toys +short "Seattle (America/Los_Angeles, US)" "Sat, 11 Jun 2022 08:22:42 -0700"
dig seattlr.time @dns.toys +short
It appears to work by responding with TXT records when given a query for A records. I have a `.digrc` file setup to query for AAAA records by default (since I mostly deal with IPv6 only networks). So I have to set the query for either A or TXT. Unfortunately, AAAA doesn't get the special treatment that A gets.
I see that dns.toys use it.
You'll notice this behavior goes away if you select the URL bar and hit enter (as if you were navigating to the site manually).
Also, no browser that wants to make any claim of caring about privacy should still be sending cross-domain Referer headers by default which is yet another reason why Mozilla's privacy marketing is just that: marketing without substance.
Since I was in the process of implementing plugins for kittendns (https://github.com/fusion/kittendns), I felt I should at least implement the timezone toy as proof of concept. This forced me to implement 'fetch' in the javascript plugin so, I guess, everyone wins :)
I am not a DNS expert, but if one format for DNS queries is <x>.<y>, i.e., "mumbai.time", "berlin.weather" as seems to be the case -- then I think it would be interesting to see if a general-purpose query in this format -- could be passed along to a search engine, then get the result back from that, strip the HTML, and pass the resulting text back in the answer section...
Why?
Well, it could have emergency preparedness applications -- imagine that for whatever reason, all computers complex enough to run modern web browsers suddenly stopped working -- and all that still works are dumb terminals and mostly text-based computers from the 1980's...
In that scenario (and we hope it never happens!) -- it would be awesome, truly awesome, to have a way to still be able to query search engines and possibly other Internet services -- if most of the other infrastructure is no longer working.
It might also be possible to implement some type of rudimentary email system over this, as well...
Anyway, I think what you've done is absolutely brilliant!
$ dig 42km-mi.unit @dns.toys
; <<>> DiG 9.16.27-Debian <<>> @dns.toys 42km-mi.unit
; (1 server found)
;; global options: +cmd
;; Got answer:
;; ->>HEADER<<- opcode: QUERY, status: NXDOMAIN, id: 2059
;; flags: qr rd ra ad; QUERY: 1, ANSWER: 0, AUTHORITY: 1, ADDITIONAL: 1
;; OPT PSEUDOSECTION:
; EDNS: version: 0, flags:; udp: 4096
; COOKIE: efe3c6f9e0b6e4da56aba44d62a4e63ba7a19bed262b0e1a (good)
;; QUESTION SECTION:
;42km-mi.unit. IN A
;; AUTHORITY SECTION:
. 6959 IN SOA a.root-servers.net. nstld.verisign-grs.com. 2022061100 1800 900 604800 86400
;; Query time: 44 msec
;; SERVER: 138.197.68.199#53(138.197.68.199)
;; WHEN: Sat Jun 11 14:00:11 CDT 2022
;; MSG SIZE rcvd: 144 dig TXT trevormanternach.comMaybe we could formalize this into a new protocol? Send some text, get some text back, with minimal overhead. Let’s call it “ask” or “q” (for query)
Firefox has a hidden simple unit conversion tool that can be enabled by setting browser.urlbar.unitConversion.enabled to true. It only has a few conversions, though, and doesn't give much detail about what it thinks you asked for.
It looks like there is a rust unit conversion utility called rink that seems better although, like many rust utilities, it lacks a man page or any local documentation besides a brief --help message (there is an online manual). Some units are a bit annoying; you can't just do c to f, only degC to degF (and not even degc to degf either). But much nicer than units and can also be easily be used as an interactive calculator.
Edit: Playing around with rink a bit more it has some neat stuff. It gives info if you enter a unit (or constant or substance), usually defined in terms of the base unit of each type but if you give the base unit it has a brief text explaining how the base unit is defined. "c to f" not working is because it doesn't use context and c is the speed of light. You can use 'units for' to see available units for a particular type, although it doesn't look like you can show all available units other than checking the source (based on the GNU units definitions but with some differences, such as degC). It suggests a supported unit if you type one it doesn't understand.
units -t '12 * 45 * 11'
This can be combined with unit conversion of course: units -t '(8 lbf) / (9.8 m/s^2)' slug
Be careful using it for temperature conversion. You need to use tempC and tempF functions, not degC and degF units, because of the linear offset from absolute zero.Correct way (absolute temperature):
units -t 'tempF(71)' tempC
Incorrect way (temperature difference): units -t '71 degF' degC
I use units a ton, so I have the following in my .zshrc: # in-terminal calculator: e.g. `calc 60 * 60 * 4`
_calc () {
units -t "$*"
}
alias calc='noglob _calc'
# units convenience, use ( and * without quoting
alias u='noglob units -t'e.g.
finger new_york@graph.nodns.toys runs a DNS server that dynamically returns answers such as times, currency information, etc (instead of domain name information) if you format your query right.
So for example, `dig mumbai.time @dns.toys` returns the time in Mumbai in a DNS TXT record instead of an IP address (or an NXDOMAIN response, saying the domain does not exists).
Play around with the `dig` command, it is an intuitive tool that you will eventually use if you are a CS or a related Freshman.
I can't make it work from the explorer bar, powershell prompt, dos shell.
Bye.