Hello, Who Are You, Won't You Tell Me Your Name!
Charly's Column – DNSDiag
If some transactions take an inexplicably long time, you don't have to blame yourself for the delayed transmission of user data. Name resolution issues might be to blame. Sys admin Charly has three tools to study the DNS server.
Pure randomness took me by the hand recently and led me to dnsping
, dnstraceroute
, and dnseval
. The tool collection for name resolution is entitled DNSDiag [1]. You need Python 3 and pip3
to install and run the trio and sudo
to let it create ICMP sockets.
dnsping
lives up to its name, repeatedly querying a DNS server and displaying the response times. The hostname to be resolved is a mandatory parameter. dnsping
prompts you for the system's default name server, which can be changed using -s <nameserver>
. After typing
sudo dnsping.py -v -s 8.8.8.8 linux-magazine.com
I queried a public DNS server from Google. Its responses took 20 milliseconds to reach me, four times more than my provider's DNS.
dnseval
queries several servers in parallel. As a competition judge, it presents the results so that you can immediately see which server responds fastest or slowest. I redirected the list of servers to be checked into a text file, with one server in each line. Lists of public DNS servers are easy to find; I used [2] and took the first five servers from the list. The call looks like this:
sudo dnseval.py -f ./liste.txt -c 5 linux-magazine.com
The result in Figure 1 shows a remarkable discrepancy between minimum and maximum response times.
Highwayman?
dnstraceroute
determines the path my DNS query takes to reach the target. By comparing this with a classic ICMP traceroute
, I can identify an attacker trying to kidnap my DNS queries. My test call is:
sudo dnstraceroute.py --expert --asn -C -s 8.8.4.4 linux-magazine.com
The result is shown in Figure 2. The --expert
parameter provides tips if something seems to be suspicious in the output – for example, if the target server is only a hop away from a private IP address (RFC 1918). False alarms also occur if you are not working on a cloud server, but locally, and a DNS cache such as Dnsmasq [3] is running on the router.
For each hop, the --asn
parameter shows you the autonomous system providing the network for the address. I can thus quickly see where the process crosses my provider's boundaries.
Infos
Buy this article as PDF
(incl. VAT)
Buy Linux Magazine
Subscribe to our Linux Newsletters
Find Linux and Open Source Jobs
Subscribe to our ADMIN Newsletters
Support Our Work
Linux Magazine content is made possible with support from readers like you. Please consider contributing when you’ve found an article to be beneficial.
News
-
Red Hat Adds New Deployment Option for Enterprise Linux Platforms
Red Hat has re-imagined enterprise Linux for an AI future with Image Mode.
-
OSJH and LPI Release 2024 Open Source Pros Job Survey Results
See what open source professionals look for in a new role.
-
Proton 9.0-1 Released to Improve Gaming with Steam
The latest release of Proton 9 adds several improvements and fixes an issue that has been problematic for Linux users.
-
So Long Neofetch and Thanks for the Info
Today is a day that every Linux user who enjoys bragging about their system(s) will mourn, as Neofetch has come to an end.
-
Ubuntu 24.04 Comes with a “Flaw"
If you're thinking you might want to upgrade from your current Ubuntu release to the latest, there's something you might want to consider before doing so.
-
Canonical Releases Ubuntu 24.04
After a brief pause because of the XZ vulnerability, Ubuntu 24.04 is now available for install.
-
Linux Servers Targeted by Akira Ransomware
A group of bad actors who have already extorted $42 million have their sights set on the Linux platform.
-
TUXEDO Computers Unveils Linux Laptop Featuring AMD Ryzen CPU
This latest release is the first laptop to include the new CPU from Ryzen and Linux preinstalled.
-
XZ Gets the All-Clear
The back door xz vulnerability has been officially reverted for Fedora 40 and versions 38 and 39 were never affected.
-
Canonical Collaborates with Qualcomm on New Venture
This new joint effort is geared toward bringing Ubuntu and Ubuntu Core to Qualcomm-powered devices.