EFF adds ASCII art to its DNS
pastebin.ca
pastebin.ca
You're aware you can add whatever you want into DNS, it doesn't have to mean anything that computers understand right? you /could/ make your A records the intro to Star Wars- but nobody will be able to use your site.
TXT is a much better option imho, or.. y'know, not doing this.
"string1" "string2" "string3"
instead of on separate lines. However, this is easily remedied with sed.Using TXT for artwork also has the advantage that you don't risk an intermediate resolver re-ordering things.
Source: When this came up about a month ago: https://news.ycombinator.com/item?id=7185326
dig +short txt log.netkine.com | sed $'s/\" \"/\\\n/g'
P!**9N#
9= #(a:?4
{w Tj(d w?#
@(d !nPx A>4
P=W @{d : 9=w\;
V: 9a# td P:d tj
{w 9=W# Px @=# F=+
@(d {d #@= P= P=@:
P=# WJ#sjP:WP= a?tx(a#
P=@=d gawV= 9= wawa\;?
{w : #9:w @!9_axw
@{d 1d P9:wd P9na\;=# WSgmN
P=W @=9=w 9{ # #:w W4Wmm
Pn #(vj P{aW #{d W4Dm
!a P9nW !w# P:d mW
#{d@:w## {d9:/4 P=
P=WP=@=w/# Px{J4Pd {a
P\;H1w Aw9j# :m?(J:W{d
Ynwwaa*:wW## {d 9=V:d
\;44#WWRav*# tj 9:d@=
A?WW#W#W#w==d@(d !a
A?WWUWQ#mNs4:W td
As*XUW#UWNsj@:d
#wv!W4W WW?=#
bw?9*9!="A lot of VoIP deployments simply ignore the whole DNS side of things, or at best use an A record. Especially in wholesale, it's IP only (using domains breaks some things), and authentication is based on IP, too. (Source IP on a UDP packet - very secure.)
$ dig @208.67.222.222 any eff.org
; <<>> DiG 9.9.2-P2 <<>> @208.67.222.222 any eff.org
; (1 server found)
;; global options: +cmd
;; Got answer:
;; ->>HEADER<<- opcode: QUERY, status: NOERROR, id: 61530
;; flags: qr rd ra; QUERY: 1, ANSWER: 5, AUTHORITY: 0, ADDITIONAL: 1
;; OPT PSEUDOSECTION:
; EDNS: version: 0, flags:; udp: 4096
;; QUESTION SECTION:
;eff.org. IN ANY
;; ANSWER SECTION:
eff.org. 3756 IN A 69.50.225.155
eff.org. 6413 IN NS ns6.eff.org.
eff.org. 6413 IN NS ns2.eff.org.
eff.org. 6413 IN NS ns1.eff.org.
eff.org. 507 IN SOA ns1.eff.org. hostmaster.eff.org. 2014031300 3600 1800 604800 1800
;; Query time: 380 msec
;; SERVER: 208.67.222.222#53(208.67.222.222)
;; WHEN: Fri Mar 14 22:26:33 2014
;; MSG SIZE rcvd: 153
Though, explicitly specifying the NAPTR type does display it: $ dig @208.67.222.222 -t naptr eff.org
; <<>> DiG 9.9.2-P2 <<>> @208.67.222.222 -t naptr eff.org
; (1 server found)
;; global options: +cmd
;; Got answer:
;; ->>HEADER<<- opcode: QUERY, status: NOERROR, id: 65029
;; flags: qr rd ra; QUERY: 1, ANSWER: 23, AUTHORITY: 0, ADDITIONAL: 1
;; OPT PSEUDOSECTION:
; EDNS: version: 0, flags:; udp: 4096
;; QUESTION SECTION:
;eff.org. IN NAPTR
;; ANSWER SECTION:
eff.org. 6304 IN NAPTR 300 10 "" " !!!!!!!!!!!!!!!!!!!!!!!!!! " "" .
eff.org. 6304 IN NAPTR 310 10 "" " !!!!!!!!!!!!!!!!!! " "" .
eff.org. 6304 IN NAPTR 320 10 "" " !!!!!!!!!!! " "" .
eff.org. 6304 IN NAPTR 100 10 "" " !!!!!!!!! " "" .
eff.org. 6304 IN NAPTR 110 10 "" " !!!!!!!!!!!!!!!!!! " "" .
eff.org. 6304 IN NAPTR 120 10 "" " !!!!!!!!!!!!!!!!!!!!!!!! " "" .
eff.org. 6304 IN NAPTR 130 10 "" " !!!!!!!!!!!!!!!!!!!!!!!!!!!!!! " "" .
eff.org. 6304 IN NAPTR 140 10 "" " !!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!! " "" .
eff.org. 6304 IN NAPTR 150 10 "" " !!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!! " "" .
eff.org. 6304 IN NAPTR 160 10 "" " @@@@@@@@@@@@@@@@@@!!!!!!!!! !!!!!!!!!!!!!! " "" .
eff.org. 6304 IN NAPTR 170 10 "" " @@@@@@@@@@@@@@@@@@!!!!!!!!! !!!!!!!!!!!!!!!!!! " "" .
eff.org. 6304 IN NAPTR 180 10 "" " @@@@@@@!!!!!!!!!!!!!!!!!!!! !!!!!!!!!!!!!!!! " "" .
eff.org. 6304 IN NAPTR 190 10 "" " @@@@@@@!!!!!!!!!!!!!!!!!!!! !!!!!!!!!!!!!!!!!!! " "" .
eff.org. 6304 IN NAPTR 200 10 "" " @@@@@@@!!!!!!!!!!!!!!!!!!!! !!!!!!!!!!!!!!!!!!! " "" .
eff.org. 6304 IN NAPTR 210 10 "" " @@@@@@@@@@@@@@@@@@!!!!!!!!!!!!!!!!!!!!!!!!!!!!!! " "" .
eff.org. 6304 IN NAPTR 220 10 "" " @@@@@@@@@@@@@@@@@@!!!!!!!!!!!!!!!!!!!!!!!!!!!!!! " "" .
eff.org. 6304 IN NAPTR 230 10 "" " @@@@@@@!!!!!!!!!!!!!!!!!!!! !!!!!!!!!!!!!!!! " "" .
eff.org. 6304 IN NAPTR 240 10 "" " @@@@@@@!!!!!!!!!!!!!!!!!!!! !!!!!!!!!!!!!!!!!! " "" .
eff.org. 6304 IN NAPTR 250 10 "" " @@@@@@@!!!!!!!!!!!!!!!!!!!! !!!!!!!!!!!!!!! " "" .
eff.org. 6304 IN NAPTR 260 10 "" " @@@@@@@@@@@@@@@@@@!!!!!!!!! !!!!!!!!!!!!!!!! " "" .
eff.org. 6304 IN NAPTR 270 10 "" " @@@@@@@@@@@@@@@@@@!!!!!!!!! !!!!!!!!!!!!!!! " "" .
eff.org. 6304 IN NAPTR 280 10 "" " !!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!! " "" .
eff.org. 6304 IN NAPTR 290 10 "" " !!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!! " "" .
;; Query time: 507 msec
;; SERVER: 208.67.222.222#53(208.67.222.222)
;; WHEN: Fri Mar 14 22:28:22 2014
;; MSG SIZE rcvd: 1876
With other resolvers such as Google public dns, or DNS Advantage, it does show up with the any type. Can anyone explain, why it doesn't show up with OpenDNS using the any type? dig ch whois.cloudflare @lee.ns.cloudflare.com
Note its TCP only to prevent abuse. Also overloading the Chaos protocol to avoid messing with real DNS.thus DNS amplification is impossible because spoofing the TCP source would fail a handshake.
Loot at entry 9, they use a similar hack to distribute the DeCSS (DVD DRM decryption program) source code through DNS.
> Mark Baker noticed that you could do the request to any nameserver. Which means for instance that the DeCSS source code is available from the DVDCCA's nameservers !
and in case you want to learn about NAPTR: http://www.ietf.org/rfc/rfc2915.txt
After a quick Google, it turns out some versions of ISC BIND were vulnerable to this... but I'm almost willing to bet a lot of other software that handles NAPTR could be as well.
great work though