-

   rss_rss_hh_new

 - e-mail

 

 -

 LiveInternet.ru:
: 17.03.2011
:
:
: 51

:


firewall

, 15 2017 . 01:13 +

ValdikSS , , IPv4-. "" , .. . :


  • IPv4- DNS ?
  • RIB DNS-, ?

, DNS pcap...


: https-, http "" . . IPv4 , , , . , DoS- .


Looking Glass , - /32 , .. . : aka GIN aka Orange Business Services, Beeline, , , Obit , , ( ).


, IP-, " " LG: 1, 2, 3, 4, 5, 6. - , IPv4 IP, . ߠ, .


14 15:00 DNS- , pcap-, .



16 . .


abuse- netup.ru , URL, 2048 5 . AS DNS "" 8 , - "" , . Tele2 https "" dns, http, http proxy. Miralogic http. SPNet URL , "" . citytelecom , https , , "" , - .


      |         HTTPS          |         HTTP           |      Domain-only
 asn  | tiny | 2k/udp | 2k/tcp | tiny | 2k/udp | 2k/tcp | tiny | 2k/udp | 2k/tcp
------+------+--------+--------+------+--------+--------+------+--------+-------
50317 |  903 |   1416 |   1030 |  285 |   1295 |   1012 |    0 |      0 |      0
57835 |  207 |      0 |      0 |  200 |      0 |      0 |  200 |      0 |      0
38959 |   29 |      0 |      0 |   56 |      0 |      0 |   39 |      0 |      0
39475 |  155 |    217 |    217 |    0 |      0 |      0 |  151 |    209 |    209
42514 |    0 |      0 |      0 |  120 |    136 |     13 |    0 |      0 |      0
12668 |    0 |      0 |      0 |   95 |    103 |     18 |    0 |      0 |      0
43826 |    0 |      0 |      0 |    0 |      0 |      0 |   13 |     33 |     12
56705 |  415 |      0 |      0 |    0 |      0 |      0 |    0 |      0 |      0

16 gist, , ASN .


EDNS & TFO


pcap- EDNS Client Subnet, 1%. , .. google ( "" ) DNS-, , DNS- . ⠗ , , EDNS Client Subnet: AS .


Client Subnet 4 , "" bit 0x20:


            ts             |      src      |        query         |    client4
---------------------------+---------------+----------------------+--------------
2017-06-14 04:47:41.231796 | 187.1.128.119 | udp A zenitbET66.CoM | 200.248.248.0
2017-06-14 04:47:41.748585 | 187.1.128.119 | tcp A ZenItbET66.cOm | 200.248.248.0
2017-06-14 04:47:42.274296 | 187.1.128.119 | udp A zEnItbET66.coM | 200.248.248.0
2017-06-14 04:47:42.798544 | 187.1.128.119 | tcp A zeNitBET66.com | 200.248.248.0

0x20 5% 2.5% ( ASN).


EDNS EDNS UDP payload size, DNS-, . , EDNS 55% 4096 , .


2% , UDP- 512. irc.kristel.ru , "" , TCP. , 512 .


            ts             | proto | qtype |       qname        | udpsz
---------------------------+-------+-------+--------------------+------
2017-06-14 12:41:59.678401 | udp   | A     | zenitbet66.com     |   512
2017-06-14 12:41:59.898596 | tcp   | A     | zenitbet66.com     |   512
2017-06-14 12:42:32.14485  | udp   | A     | m.zenitbet66.com   |  4096
2017-06-14 12:44:40.532815 | udp   | A     | www.kisa54.com     |  4096
2017-06-14 12:56:54.083849 | udp   | A     | diplom-lipetsk.com |  4096
2017-06-14 12:56:54.311013 | tcp   | A     | diplom-lipetsk.com |  4096
2017-06-14 13:06:38.524876 | udp   | A     | www.cool-sino.com  |  4096

, DNS amplification, .. 65527 , . , "" powerdns - resource records, truncated , TCP. powerdns DNS amplification UDP.


, DNS- TCP TCP Fast Open. , , , DNS , TCP.


DNS


10 looking glass /32 "" DNS IPv4 . , RIPE Atlas, , , , , 2049 A :


  • traceroute filter01.dtln.ru,
  • traceroute AS8997 188.254.78.25 95.167.93.150 "" IP, /24 , .. ,
  • ReTN "" , ReTN @amarao.

, .. . , . :


  • DNS resource records ? , , sortlist LUA
  • IPv4-, " "?
  • IPv6 ?
  • ?

- , RIPE Atlas 8844224, 8844225, 8844226, 8844227, 8844228, 8844229, 8844230, 8844231, 8844232, 8844233, 8844234, 8844235. 16 postgres:9.6. pcap- .

Original source: habrahabr.ru (comments, light).

https://habrahabr.ru/post/330934/


: [1] []
 

:
: 

: ( )

:

  URL