2024/11/11ã12 ã«è¡ããã JPAAWG 7th General Meeting ã§çºè¡¨ããè³æã§ã https://meetings.jpaawg.org/
ã¾ã¨ã æ¤ç´¢ã¨ã³ã¸ã³ã¯ DuckDuckGo ã使ã£ã¦ãã DNS 㯠NextDNS ã使ã£ã¦ãã macOS / iOS / iPadOS ã§å©ç¨ãã¦ãã èªç¤¾ã§ã NextDNS ãæ¡ç¨ãã ãã°ã¯ãªãã§éç¨ ãªã DuckDuckGo ? DuckDuckGo â Privacy, simplified. Google ã®æ¤ç´¢çµæããã¾ãã«ãé ·ãã¨æãã¦ããã uBlacklist ãå©ç¨ãã¦ãããã¯ãã¦ããããããç¡ããªã£ã¦ããã®ã§ãåãæ¿ããã DuckDuckGo ãã©ã¦ã¶ã¯å©ç¨ãã¦ããã Chrome ãç¶ç¶ãã¦å©ç¨ãã¦ãã Chrome Extension ã¨ã㦠DuckDuckGo Privacy Essentials ã追å ãã¦å©ç¨ãã¦ãã ç¹ã«å°ããã¨ã¯ãªããä»å¾ã DuckDuckGo ã使ã£ã¦ãããã¨æãã DuckDuckGo Privacy Pro ãæ¥æ¬
ã¡ã¼ã«ãéãéããéä¿¡å ãæ¬ã«ã¯ã©ããªå 容ã§ãè¨å ¥ãããã¨ãå¯è½ãªãããç°¡åã«ä»äººã«ãªããã¾ããã¨ãã§ãã¾ãã誰ããèªåã®ææãã¦ãããã¡ã¤ã³ã«ãªããã¾ãã¦ã¡ã¼ã«ãéã£ãæãåä¿¡è ã«ãã®ã¡ã¼ã«ãããªããã¾ãã¡ã¼ã«ãã§ãããã¨ãä¼ããããã®DNSè¨å®ã«ã¤ãã¦ã¨ã³ã¸ãã¢ã®ã´ã£ã´ã§ã¯ã»ã¬ã¤ãæ°ã解説ãã¦ãã¾ãã DNS settings to avoid email spoofing and phishing for unused domain - nixCraft https://www.cyberciti.biz/security/dns-settings-to-avoid-email-spoofing-and-phishing-for-unused-domain/ ã¬ã¤ãæ°ã®è§£èª¬ã¯ãã¡ã¼ã«ã使ç¨ãã¦ããªããã¡ã¤ã³ãã対象ã«ãããã®ãã¡ã¤ã³ãã¡ã¼ã«ãéä¿¡ããªããã¨ãããã³ããããã®ãã¡ã¤ã³ã
å ´æ OHGAKI(å®å ¨ãªã¢ã¼ã) æ¥æ Day3 2021å¹´7æ16æ¥(é) 14:45ï½15:15(05å) æ¦è¦ HTTPSã¨ããDNSã¬ã³ã¼ãã¿ã¤ããå®ç¾©ããdraft-ietf-dnsop-svcb-httpsãããããRFCã«ãªãã¾ããå®å©ç¨ã¯ãã§ã«ã¯ãã¾ã£ã¦ãããWebãµã¼ãã®DNSã¸ã®ç»é²ã¯å¾æ¥ã®A/AAAAã¬ã³ã¼ãããä»å¾ã¯æ°ããHTTPSã¬ã³ã¼ãã«ç§»è¡ãã¦ãããã¨ã«ãªãã§ããããæ¬çºè¡¨ã§ã¯HTTPSã¬ã³ã¼ãã®ç°¡åãªç´¹ä»ã¨ãããã«ã¨ããªã注æç¹ã説æãã¾ãã çºè¡¨è å±±å£ å´å¾³(æ ªå¼ä¼ç¤¾ã¤ã³ã¿ã¼ãããã¤ãã·ã¢ãã£ã) è³æ å ¬éè³æ DNSã§HTTP (DNS Summer Day 2021)
ãã¢ããªã±ã¼ã·ã§ã³ã¨ã³ã¸ãã¢ãç¥ãã¹ãDNSã®åºæ¬ãã¨ããã¿ã¤ãã«ã§ãbuilderscon tokyo 2018 ã§ç»å£ããã¹ã©ã¤ãã§ã
2016 å¹´ 6 æ 14 æ¥ (ç«) ç波大å¦çºãã³ãã£ã¼ ã½ããã¤ã¼ãµæ ªå¼ä¼ç¤¾ 代表åç· å½¹ ç» å¤§é ãOPEN IPv6 ãã¤ããã㯠DNS for ãã¬ããã»å ãã¯ã¹ãããµã¼ãã¹ãå ¬é NTT æ±æ¥æ¬ã®ãã¬ããåç·é㧠VPN æ©å¨ã IoT æ©å¨å士ã®ãã¬ãã網å ã®é«éã»ä½é 延ã®ç´æ¥éä¿¡ãå®ç¾ ã½ããã¤ã¼ãµæ ªå¼ä¼ç¤¾ã¯ãæ¬æ¥ããOPEN IPv6 ãã¤ããã㯠DNS for ãã¬ããã»å ãã¯ã¹ãããµã¼ãã¹ (https://i.open.ad.jp/) ã®ãã¼ã¿çãæä¾éå§ãã¾ããã ãã®ç¡åã®ãã¤ããã㯠DNS (DDNS) ãµã¼ãã¹ãå©ç¨ããã¨ãNTT æ±æ¥æ¬ã®ãã¹ã¦ã®ã¨ãªã¢ã® 1,066 ä¸æ¬ã®ãã¹ã¦ã®ãã¬ããåç·ä¸ã§ãã¤ã³ã¿ã¼ããããã絶対ã«ä¸æ£ä¾µå ¥ããããããã®ãªãã大å¤é«éãã¤ä½é 延㪠VPN ããç°¡åã«æ§ç¯ã§ãã¾ã (注 1)ãã¾ããIoT æ©å¨ããã¬ãã網ã«ç´
Nginxã§ã¯, serverã³ã³ããã¹ãã®locationã³ã³ããã¹ãã«ããã¦, proxy_passãã£ã¬ã¯ãã£ããå©ç¨ãããã¨ã§ä»»æã®ãã¹ãã«ã¢ã¯ã»ã¹ã転éãããã¨ãã§ãã¾ã. ä¾ãã°, serverã³ã³ããã¹ãã«ããã¦, location / { proxy_pass http://127.0.0.1:5000; } ã¿ããã«æ¸ãã¦ãããã°, localhostã®5000çªãã¼ãã«ã¢ã¯ã»ã¹ã転éãããã¨ãåºæ¥ã¾ã. Webãµã¼ãã¹ã§ã¯, ããããæãã§Nginxã443çª(HTTPS)ã80çªãã¼ã(HTTP)ã§åããã¢ã¯ã»ã¹ã5000çªãã¼ããªã©ã§åãã¦ããWebã¢ããªã±ã¼ã·ã§ã³ã«è»¢éãã¦ãã訳ã§ã. ã§, ãã®proxy_passãã£ã¬ã¯ãã£ãã¯, IPããã®ã¾ã¾æ¸ãã®ã§ã¯ãªã, 次ã®ããã«ãã¡ã¤ã³ãæ¸ããã¨ãã§ãã¾ã. location / { proxy_pass http
2. ãã®ææ¸ã«ã¤ã㦠⢠ãã£ãã·ã¥ãµã¼ã(ãã«ãªã¾ã«ã)ã¨ãã¦åä½ããã Unboundã»BIND9両æ¹ã«ã¤ãã¦ã大è¦æ¨¡ç°å¢ã«é©ãã ãã¥ã¼ãã³ã°ã¨ãã¦ããã«ããã¯ã«ãªããããé¨åãç´¹ä» â¢ å¯¾è±¡ver㯠Unbound 1.4.22ï¼BIND 9.9.5 ãåºæºã¨ã㦠ãããããã以åã§ãåæ§ã®è¨å®ãå¯è½ãªå ´åããã ⢠DNS権å¨ãµã¼ãã¯å¯¾è±¡å¤ ⢠OSããããã¯ã¼ã¯ç°å¢ã®ãã¥ã¼ãã³ã°é ç®ãæ§è½ãã¥ã¼ ãã³ã°ä»¥å¤ã®ããããè¨å®ãåããã¦ç´¹ä» 2 3. ãã¥ã¼ãã³ã°ã®å¿ è¦æ§ ⢠Unbound/BIND9ãOSã®ããã©ã«ãè¨å®ã¯ããã¼ãã¦ã§ã¢ã®æ§è½ãæ大ã«çº æ®ããè¨å®ã«ãªã£ã¦ããªã ⢠é©åãªãã¥ã¼ãã³ã°ãããªãã¨ãCPU使ç¨çãå°ãªãã®ã«æ§è½ãé æã¡ï¼CPU ã°ããé£ã£ã¦æ§è½ãä¸ãããªããã¨ããç¶æ³ã«é¥ã ⢠ãè¨å®ãã¨ã¯ãã¼ãã¦ã§ã¢è³æºã®é åæ¹æ³ è¨å®ã¯ãã»ã¨ãã©ã®å ´åãªããã¿
ä»å¹´ã«å ¥ã£ã¦ãDNSã®å帰çãªåãåããã使ã£ãDDosæ»æãå ±åããã¦ããããã§ãã DNSãã£ãã·ã¥ãµã¼ãã¼ã¨ãã¦éç¨ãã¦ããå ´åã§ããå¶éãè¨ãã¦é©åã«è¨å®ããã¦ãããªãã¨ã DDosæ»æã®è¸ã¿å°ã«ããã¦ãã¾ãã¾ãã 詳ããã¯ãã¡ãã®ãµã¤ããåèã«ãã¦ãã ããã http://www.jpcert.or.jp/pr/2013/pr130002.html 管çãã¦ãããµã¼ãã¼ããªã¼ãã³ãªã¾ã«ãã¼ã«ãªã£ã¦ããªããã©ããã確èªãããµã¤ããéè¨ããã¦ãã¾ãã http://www.openresolver.jp/ OSãBINDã®ãã¼ã¸ã§ã³ã«ãã£ã¦ãç°ãªãã¾ãããè¨å®ä¾ããç´¹ä»ãã¾ãã ã¾ãããªã¼ãã³ãªã¾ã«ãã¼ã«ãªã£ã¦ããªããã確èªãã¾ãã åè¿°ãããªã¼ãã³ãªã¾ã«ãã¼ç¢ºèªãµã¤ãã確èªã§ãã¾ãããããã§ã¯ã³ãã³ãã©ã¤ã³ã§ç¢ºèªãã¾ãã $ wget -qO - http://www.openre
æè¿DNSã«å¯¾ãã¦ã®ã¢ã¿ãã¯ãè¦ãããã ãã©ã³ã¸ããå¤å´ããDNSã¯ã¨ãªã網å ã«è¦æ±ã ãã®è¦æ±ã網å 端æ«ã«ã¦å¿çããã£ãã·ã¥ãµã¼ããå¿çãã¦è² è·ä¸æã è¦æ±ãã¦ããå 容㯠ripe.netãANYãã®ã¯ã¨ãª 60byteç¨åº¦ã®è¦æ±ã400byteã®å¿çãã¼ã¿ã«å¢å ããã DDoSæ»æã§æåãªã¯ã¨ãªã¯isc.orgã§ã ããã¤ã¯60byteç¨åº¦ã®è¦æ±ã1500byteç¨åº¦ã®å¿çãã¼ã¿ã«å¢å¹ ãããã 対å¿ç㯠1.ãã©ã³ã¸ããå´ã§ããããè¦æ±ãåºãIPããã£ã«ã¿ãã 2.ãµã¼ãå´ã§ç¹å®ã®è¦æ±ãæå¦ãã 1.ã§ãã£ã«ã¿ãã¦ãã¾ãã°ç¶²å 端æ«ã«è¦æ±ãé£ã¶ãã¨ããªã äºè±¡ãåæããããã¨ãã§ãããã IPãå¤ãããã¦ãã¾ãã¨ãã®é½åº¦ãã£ã«ã¿ã®æ¶ãæ¿ããå®æ½ããå¿ è¦ãããã 2.ã®å ´åãµã¼ãå´ã§DNSã¯ã¨ãªãå¤å¥ãã¦ãã£ã«ã¿ããããã¨ã§ç¹å®ã®ã¯ã¨ãªã«å¿çãããªããããã¨ãå¯è½ã iptables -
Copyright © 2013 æ ªå¼ä¼ç¤¾æ¥æ¬ã¬ã¸ã¹ããªãµã¼ãã¹ 1 Copyright © 2013 æ ªå¼ä¼ç¤¾æ¥æ¬ã¬ã¸ã¹ããªãµã¼ãã¹ 1 Copyright © 2013 æ ªå¼ä¼ç¤¾æ¥æ¬ã¬ã¸ã¹ããªãµã¼ãã¹ 1 åå¿è ã®ããã®DNSéç¨å ¥é - ãã©ãã«ã¨ãã®è§£æ±ºã®ãã¤ã³ã - 2013å¹´7æ19æ¥ DNS Summer Days 2013 æ ªå¼ä¼ç¤¾æ¥æ¬ã¬ã¸ã¹ããªãµã¼ãã¹ï¼JPRSï¼ æ°´é è²´å² Copyright © 2013 æ ªå¼ä¼ç¤¾æ¥æ¬ã¬ã¸ã¹ããªãµã¼ãã¹ 2 Copyright © 2013 æ ªå¼ä¼ç¤¾æ¥æ¬ã¬ã¸ã¹ããªãµã¼ãã¹ 2 Copyright © 2013 æ ªå¼ä¼ç¤¾æ¥æ¬ã¬ã¸ã¹ããªãµã¼ãã¹ 2 è¬å¸«èªå·±ç´¹ä» ⢠æ°åï¼æ°´é è²´å²ï¼ã¿ãã® ãããµã¿ï¼ ⢠çå¹´ææ¥ï¼1988å¹´3æ3æ¥ï¼25æ³ï¼ ⢠æå±ï¼æ ªå¼ä¼ç¤¾æ¥æ¬ã¬ã¸ã¹ããªãµã¼ãã¹ï¼JPRSï¼ ã·ã¹ãã é¨ â¢ Unixæ´ï¼8å¹´ç®ï¼F
2014å¹´5æ14æ¥ 13æ00å ä¿®æ£ ã¿ã¤ãã«ã誤解ãæããã®ã ã£ãã®ã§ãããªã URL ã« www ãä»ããã®ããã¾ãã¯ããµããã¡ã¤ã³ãªãã§ã¯ CNAME ã使ããªã件ãããå¤æ´è´ãã¾ãããä½µãã¦ãç»åã« Public IP 㨠Private IP ã®æè¨ãè¡ãã¾ããã çãããããã«ã¡ã¯ãMUGENUP ã® osada ã§ãã ä»åã¯ãã¹ã±ã¼ã«ã¢ã¦ãæã«ELB(Amazon Elastic Load Balancer) ã使ãã¨ãã®æ³¨æç¹ã«ã¤ãã¦ã®è¨äºã§ãã ã¨ãã£ã¦ããã¤ã³ãã©ã»ã¨ã³ã¸ãã¢ã«ã¯èªæã®ãã¨ã¨æãã¾ãã®ã§ãèªè ã®å¯¾è±¡ã¯ ã¤ã³ãã©ã»ã¨ã³ã¸ãã¢ã§ã¯ãªããã©ãã¤ã³ãã©ãããã¨ãããã³ãã£ã¼ãªãã§ã¯ã®ã¨ã³ã¸ãã¢åãã§ãã è¦æ¨ ELBã«ã¯EIPãªã©ã®Aã¬ã³ã¼ããé¢é£ä»ãããã¨ãåºæ¥ãããã¡ã¤ã³ã¨ãµã¼ãã¼ãçµã³ã¤ããã«ã¯æä¾ãããCNAMEã使ãå¿ è¦ãããã¾ã ãµããã¡ã¤ã³ç¡
/etc/hosts ã«ãã¹ãåãæ¸ãã¦é ãã¨ããã®ã¯ãæ°å°ã®ãã·ã³ã管çããç¶æ³ã§ã¯èª°ãããã£ããã¨ãããã¨æãã¾ããDNSã¯ã¨ãªãçºçããªãã®ã§ã¨ã¦ãæ©ããã¾ãåä¸é害ç¹ãçºçããªãã¡ãªãããããã¾ãããã®åé¢ãå°æ°ãå¢ãã¦ããã¨å ¨é¨ãæ´æ°ããã®ãã¨ã¦ã大å¤ã«ãªãã ãã§ãªããè´å½çãªé度ä½ä¸ãããããã¾ãã ãã¹ãç°å¢ã¯ OS: CentOS 6.4 64bit, Linux 3.10.2 CPU: Intel Core i7-2600 @ 3.4GHz ã§ãã ãã¹ãã«ã¯ã²ããã getaddrinfo(3) ãç¶ããããã°ã©ã ãä½æããååã解決ãã¾ããã /etc/hosts ã«ã¯ 10.234.130.1 host1301 10.234.130.2 host1302 10.234.130.3 host1303 ã®ããã«é©å½ãªã¢ãã¬ã¹ã¨ãã¹ãåã並ã¹ããã®ãä½ããå©ç¨ãã¾ããããª
æ¥æ¬ã¢ãã¡åã®å¿«æï¼æµ·å¤ã¢ãã¡è³ãåè³ãããã¹ãããã¨ãã¼ãã¡ã¼ãæµ·å¤ã©ã¤ã»ã³ã¹é¨é·&ãããã¥ã¼ãµã¼ãèªãã奮éã®èå°è£
æ¥æ¬ã¢ãã¡åã®å¿«æï¼æµ·å¤ã¢ãã¡è³ãåè³ãããã¹ãããã¨ãã¼ãã¡ã¼ãæµ·å¤ã©ã¤ã»ã³ã¹é¨é·&ãããã¥ã¼ãµã¼ãèªãã奮éã®èå°è£
æ¥æ¬ã¢ãã¡åã®å¿«æï¼æµ·å¤ã¢ãã¡è³ãåè³ãããã¹ãããã¨ãã¼ãã¡ã¼ãæµ·å¤ã©ã¤ã»ã³ã¹é¨é·&ãããã¥ã¼ãµã¼ãèªãã奮éã®èå°è£
BIND 10ã®éçºããã¸ã§ã¯ãã¯çµäºãã¾ãããï¼æ³¨è¨: 2014å¹´9æï¼ BINDã®æ¬¡ä¸ä»£ãã¼ã¸ã§ã³BIND 10 1.0.0ã®ãã¼ã¿çãISCï¼Internet Systems Consortiumï¼ãã2012å¹´12æ20æ¥ã«ãªãªã¼ã¹ããã¾ãããæ£å¼ãªãªã¼ã¹ã¯æ¥å¹´ã®1æã2æã«ãªãã¨æããã¾ãããç¾æç¹ã§ã®ç¶æ³ãæ¢ã£ã¦ã¿ã¾ãããã ãªããæ¬è¨äºã¯2åã«åãã¦ç´¹ä»ãã¾ãã åç·¨: BIND 10ã®ç´¹ä» ï¼ä»åï¼ å¾ç·¨: BIND 10ã®ã¤ã³ã¹ãã¼ã« BIND 10ã®æ¦è¦ ã¾ãã次ã®ç»é¢ãè¦ã¦ãã ãããBIND 10ã権å¨ãµã¼ãã¨ãã¦åããã¦ããã¨ãã®psã³ãã³ãã®åºåçµæã§ãã $ ps axf PID TTY STAT TIME COMMAND 21071 ? Ss 0:00 /usr/local/sbin/bind10 21072 ? S 0:00 \_ b10-sockcreat
2012-11-02 çµè«ããè¨ãã°ãã¨ãããã RHLE6/CentOS6 ãªäººã¯ /etc/resolv.conf ã« options single-request-reopen ãæ¸ãã¦ãããã¨ãã話ã§ã(å ¨é¨å°æåã§ããã念ã®ããï¼ ãªããï¼ RHEL5/CentOS5/Ubuntu 10.04ãªLinuxã¨ãã§ã¯ãFQDN ã®è§£æ±ºãããã¨ãã« DNSãã£ãã·ã¥ãµã¼ãã« AAAA RR ã® Queryãæãã AAAA RR ã® Reply ãåãã DNSãã£ãã·ã¥ãµã¼ãã« A RR ã® Queryãæãã A RR ã® Reply ãåãã ã¨ããæåã§ããããRHEL6/CentOS6 ã§ã¯ DNSãã£ãã·ã¥ãµã¼ãã« A RR ã® Queryãæãã DNSãã£ãã·ã¥ãµã¼ãã« AAAA RR ã® Queryãæãã A RR ã® Reply ãåãã AAAA RR ã® Re
ãªãªã¼ã¹ãé害æ å ±ãªã©ã®ãµã¼ãã¹ã®ãç¥ãã
ææ°ã®äººæ°ã¨ã³ããªã¼ã®é ä¿¡
å¦çãå®è¡ä¸ã§ã
j次ã®ããã¯ãã¼ã¯
kåã®ããã¯ãã¼ã¯
lãã¨ã§èªã
eã³ã¡ã³ãä¸è¦§ãéã
oãã¼ã¸ãéã
{{#tags}}- {{label}}
{{/tags}}