Fenix by Takeda11
ãµã€ãã®IPã¢ãã¬ã¹ã倿ŽãããšãDNSã¬ã³ãŒãã®æŽæ°ã«ã€ããŠå€ãã®äººãæ··ä¹±ããŸãããããã®ã¬ã³ãŒãããã£ããæŽæ°ãããã®ã¯ãªãã§ããïŒãã¹ãŠãæŽæ°ããããŸã§æ¬åœã«2æ¥åŸ ã€å¿ èŠããããŸããïŒäžéšã®èšªåè ãæ°ããIPã衚瀺ããä»ã®èšªåè ãå€ãIPã衚瀺ããã®ã¯ãªãã§ããïŒMail.ru Cloud Solutions
ããŒã ã¯ãéçºè ã§ããèšäºã®èè ã§ããJulia Evansã«ããèšäºã翻蚳ããŸããã圌女ã¯ãããã®è³ªåã«çããããã³ããšã³ãã®èгç¹ããDNSæŽæ°äžã«äœãèµ·ããããäžè¬çã«èª¬æããŠããŸãã
DNSã¬ã³ãŒããæŽæ°ãããšãã«ãèå°è£ã§äœãèµ·ããããç°¡åã«èª¬æããŸãã
DNSã®ããã¿ïŒååž°çã§ä¿¡é Œã§ããDNSãµãŒããŒ
ãŸããDNSã·ã¹ãã ã«ã€ããŠå°ã説æããå¿ èŠããããŸãã DNSãµãŒããŒã«ã¯ãæš©éã®ãããã®ãšååž°çãªãã®ã®2çš®é¡ããããŸãã
æš©éã®ããDNSãµãŒããŒïŒããŒã ãµãŒããŒãšãåŒã°ããŸãïŒã¯ãæ åœããåãã¡ã€ã³ã®IPã¢ãã¬ã¹ã®ããŒã¿ããŒã¹ãç¶æããŸããããšãã°ãçŸåšãgithub.comã®æš©éã®ããDNSãµãŒããŒã¯
ns-421.awsdns-52.comã§ãããã®ãªã¯ãšã¹ãã§ã圌ã«github.comã®IPã¢ãã¬ã¹ãå°ããããšãã§ããŸãã
dig @ns-421.awsdns-52.com github.com
ååž°DNSãµãŒããŒèªäœã¯ã誰ãã©ã®IPã¢ãã¬ã¹ãææããŠãããã«ã€ããŠã¯äœãç¥ããŸããããã¡ã€ã³ã®IPã¢ãã¬ã¹ã¯ãé©åãªæš©éã®ããDNSãµãŒããŒããã¯ãšãªãå®è¡ããŠèšç®ããååºŠèŠæ±ãããå Žåã«åããŠãã®IPã¢ãã¬ã¹ããã£ãã·ã¥ããŸãããããã£ãŠã8.8.8.8ã¯ååž°DNSãµãŒããŒã§ãã
人ã ãããªãã®ãŠã§ããµã€ãã«ã¢ã¯ã»ã¹ãããšãã圌ãã¯ããããååž°çãªDNSãµãŒããŒãžã®DNSã«ãã¯ã¢ãããè¡ã£ãŠããŸããã§ã¯ãååž°DNSãµãŒããŒã¯ã©ã®ããã«æ©èœããŸããïŒèŠãŠã¿ãŸãããïŒ
ååž°DNSãµãŒããŒãgithub.comã®IPã¢ãã¬ã¹ãç §äŒããæ¹æ³
github.comã®IPã¢ãã¬ã¹ïŒAã¬ã³ãŒãïŒãèŠæ±ãããšãã«ååž°DNSãµãŒããŒïŒ8.8.8.8ãªã©ïŒãå®è¡ããäŸãèŠãŠã¿ãŸãããããŸãããã§ã«ãã£ãã·ã¥ãããçµæãããå Žåã¯ããããçºè¡ããŸãããããããã¹ãŠã®ãã£ãã·ã¥ãæéåãã«ãªã£ãå Žåã¯ã©ããªããŸããïŒãããäœãèµ·ãã£ãŠããã®ãã§ãã
ã¹ããã1ïŒã«ãŒãDNSãµãŒããŒã®IPã¢ãã¬ã¹ã¯ããœãŒã¹ã³ãŒãã«ããŒãã³ãŒããããŠããŸããããã¯ããã€ã³ããããŠããªããœãŒã¹ã³ãŒãã§ç¢ºèªã§ããŸãã圌ãæåã«198.41.0.4ãéžæãããšããŸãããããããã®ããŒãã³ãŒããããIPã¢ãã¬ã¹ã®å ¬åŒãœãŒã¹ã¯ããã«ãŒããã³ããã¡ã€ã«ããšãåŒã°ããŸãã
ã¹ããã2ïŒgithub.comã«ã€ããŠã«ãŒãããŒã ãµãŒããŒã«åãåãããŸãã
ã³ãã³ãã§äœãèµ·ãã£ãŠãããã倧ãŸãã«åçŸã§ããŸã
dig..ãããã«ãããèŠæ±ããæ°ããä¿¡é Œã§ããããŒã ãµãŒããŒãæäŸã.comããŸããIPã¢ãã¬ã¹ã192.5.6.30ã®ããŒã ãµãŒããŒã§ãã
$ dig @198.41.0.4 github.com
...
com. 172800 IN NS a.gtld-servers.net.
...
a.gtld-servers.net. 172800 IN A 192.5.6.30
...
DNSå¿çã®è©³çްã¯ããå°ãè€éã§ãããã®å Žåãããã€ãã®NSã¬ã³ãŒããå«ãæš©éã»ã¯ã·ã§ã³ãšAã¬ã³ãŒããå«ã远å ã®ã»ã¯ã·ã§ã³ãããããããããã®ããŒã ãµãŒããŒã®IPã¢ãã¬ã¹ãååŸããããã«è¿œå ã®ã«ãã¯ã¢ãããè¡ãå¿ èŠã¯ãããŸããã
å®éã«ã¯ã99.99ïŒ ã®ç¢ºçã§ãã§ã«ãã£ãã·ã¥ãããããŒã ãµãŒããŒã¢ãã¬ã¹
.comããããŸãããå®éã«ã¯æåããå§ããŠããããã«èŠããããŸãã
ã¹ããã3ïŒ
.comgithub.comã«ã€ããŠããŒã ãµãŒããŒã«åãåãããŸãã
$ dig @192.5.6.30 github.com
...
github.com. 172800 IN NS ns-421.awsdns-52.com.
ns-421.awsdns-52.com. 172800 IN A 205.251.193.165
...
ãªã¯ãšã¹ããéä¿¡ããããã®æ°ããIPã¢ãã¬ã¹ããããŸãïŒããã¯ãgithub.comã®ããŒã ãµãŒããŒã®1ã€ã§ãã
ã¹ããã4ïŒgithub.comã®ããŒã ãµãŒããŒã«github.comã®ã¢ãã¬ã¹ãå°ããŸãã
ã»ãŒå®äºã§ãã
$ dig @205.251.193.165 github.com
github.com. 60 IN A 140.82.112.4
ãããã£ãŠãgithub.comã®Aã¬ã³ãŒãããããŸããããã§ãååž°ãµãŒããŒã«github.com IPã¢ãã¬ã¹ãå²ãåœãŠããããããè¿ãããšãã§ããŸãããããŠåœŒã¯ãããŒãã³ãŒããããããã€ãã®IPã¢ãã¬ã¹ïŒã«ãŒãããŒã ãµãŒããŒã®ã¢ãã¬ã¹ïŒããå§ããŠãããã»ã¹å šäœãå®è¡ããããšãã§ããŸããã
ååž°DNSãµãŒããŒã®ãã¹ãŠã®ã¹ãããã衚瀺ããæ¹æ³ïŒdig + trace
ãã¡ã€ã³ã解決ããããã«ååž°DNSãµãŒããŒãäœãè¡ããã確èªããã«ã¯ã次ã®ã³ãã³ããå®è¡ããŸãã
$ dig @8.8.8.8 +trace github.com
ãã®ã³ãã³ãã¯ãã«ãŒãDNSãµãŒããŒããå§ããŠãååž°ãµãŒããŒãèŠæ±ãããã¹ãŠã®DNSã¬ã³ãŒãã衚瀺ããŸããããã¯ãå ã»ã©å®è¡ãã4ã€ã®ã¹ããããã¹ãŠã§ãã
DNSã¬ã³ãŒããæŽæ°ãã
DNSã®åäœã®åºæ¬ãããã£ãã®ã§ãããã€ãã®DNSã¬ã³ãŒããæŽæ°ããŠãäœãèµ·ããããèŠãŠã¿ãŸãããã
DNSã¬ã³ãŒããæŽæ°ããå Žåãäž»ã«2ã€ã®ãªãã·ã§ã³ããããŸãã
- åãååã®ãµãŒããŒãç¶æããŸãã
- ããŒã ãµãŒããŒã倿ŽããŸãã
TTLã«ã€ããŠè©±ããŸããã
ããããç§ãã¡ã¯äœãéèŠãªããšãå¿ããŸãããããã¯TTLã§ããåã«è¿°ã¹ãããã«ãååž°DNSãµãŒããŒã¯ãã¬ã³ãŒããæéåãã«ãªããŸã§ã¬ã³ãŒãããã£ãã·ã¥ããŸããTTLïŒåç¶æéïŒã«åºã¥ããŠã¬ã³ãŒãã®æå¹æéãæ±ºå®ããŸãã
ãã®äŸã§ã¯ãGitHubããŒã ãµãŒããŒã¯DNSã¬ã³ãŒãã«å¯ŸããŠ60ã®TTLãè¿ããŸããããã¯60ç§ãæå³ããŸãã
$ dig @205.251.193.165 github.com
github.com. 60 IN A 140.82.112.4
ããã¯ããªãçãTTLã§ããçè«çã«ã¯ããã¹ãŠã®DNSå®è£ ãDNSæšæºã«åŸã£ãŠããå ŽåãGitHubãgithub.comã®IPã¢ãã¬ã¹ã倿Žããããšã決å®ããå Žåãå šå¡ã60ç§ä»¥å ã«æ°ããIPã¢ãã¬ã¹ãåãåãããšãæå³ããŸãããããå®éã«ã©ã®ããã«çºçããããèŠãŠã¿ãŸãããã
ãªãã·ã§ã³1ïŒåãååã®ãµãŒããŒäžã®DNSã¬ã³ãŒããæŽæ°ãã
ãŸããããŒã ãµãŒããŒïŒCloudflareïŒãæŽæ°ããŠã
test.jvns.ca1.2.3.4ã«ããããããæ°ããDNSã¬ã³ãŒãã§ããAã¬ã³ãŒããååŸããŸããã
$ dig @8.8.8.8 test.jvns.ca
test.jvns.ca. 299 IN A 1.2.3.4
ããã«åããŸããïŒãã®åã¯
test.jvns.caãã£ãã·ã¥ã§ããDNSã¬ã³ãŒãããªãã£ãã®ã§ãåŸ
ã€å¿
èŠã¯ãŸã£ãããããŸããã§ãããåªãããããããæ°ããã¬ã³ãŒãã¯çŽ5åïŒ299ç§ïŒãã£ãã·ã¥ãããŠããããã§ãã
ã§ã¯ããã®IPã¢ãã¬ã¹ã倿Žããããšãããšã©ããªãã§ããããã5.6.7.8ã«å€æŽããŠãããåãDNSã¯ãšãªãå®è¡ããŸããã
$ dig @8.8.8.8 test.jvns.ca
test.jvns.ca. 144 IN A 1.2.3.4
ãã®DNSãµãŒããŒã§ã¯ã1.2.3.4ã¬ã³ãŒãã144ç§éãã£ãã·ã¥ãããŠããããã§ããè峿·±ãããšã«ã8.8.8.8ãè€æ°åã¯ãšãªãããšãäžè²«æ§ã®ãªãçµæãåŸãããŸããæ°ããIPãåŸãããå Žåãããã°ãå€ãIPãåŸãããå ŽåããããŸãããããã8.8.8.8ã¯ãå®éã«ã¯ããããããç¬èªã®ãã£ãã·ã¥ãæã€å€æ°ã®ç°ãªãããã¯ãšã³ãã«è² è·ã忣ããŸãã
5åéåŸ æ©ããåŸããã¹ãŠã®8.8.8.8ãã£ãã·ã¥ãæŽæ°ãããåžžã«æ°ãã5.6.7.8ãšã³ããªãè¿ãããŸãããããããããªãéãã§ãïŒ
åžžã«TTLã«é Œãããšã¯ã§ããŸãã
ã»ãšãã©ã®ã€ã³ã¿ãŒããããããã³ã«ãšåæ§ã«ããã¹ãŠãDNS仿§ã«æºæ ããŠããããã§ã¯ãããŸãããäžéšã®ISPDNSãµãŒããŒã¯ãæå®ãããTTLãããé·ãæéã¬ã³ãŒãããã£ãã·ã¥ããŸããããšãã°ã5åã§ã¯ãªã2æ¥ä»¥å ããããŠã人ã ã¯ãã€ã§ããã¡ã€ã«ã«å€ãIPã¢ãã¬ã¹ãããŒãã³ãŒãã£ã³ã°ã§ããŸã
/etc/hostsã
å®éã«ã¯ã5åã®TTLã§DNSã¬ã³ãŒããæŽæ°ããå Žåãã¯ã©ã€ã¢ã³ãã®å€§éšåãæ°ããIPã¢ãã¬ã¹ã«ãã°ããç§»åãããšäºæ³ã§ããŸãïŒããšãã°ã15å以å ïŒããã®åŸãæ°æ¥ã§ãã£ãããšæŽæ°ããã倿°ã®é å»¶ãçºçããŸãã
ãªãã·ã§ã³2ïŒããŒã ãµãŒããŒãæŽæ°ãã
ãã®ãããããŒã ãµãŒããŒã倿Žããã«IPã¢ãã¬ã¹ãæŽæ°ãããšãå€ãã®DNSãµãŒããŒãæ°ããIPã¢ãã¬ã¹ãéåžžã«è¿ éã«ååŸããããšãããããŸãããåªãããããããããŒã ãµãŒããŒã倿Žãããšã©ããªããŸããïŒãã£ãŠã¿ããïŒ
ããã°ã®ããŒã ãµãŒããŒãæŽæ°ããããªãã£ãã®ã§ã代ããã«å¥ã®ãã¡ã€ã³ãååŸããŠãHTTPãã°ã®äŸexamplecat.comã§äœ¿çšããŸããã
以åãç§ã®ãµãŒããŒã¯ã«èšå®ãããŠããŸãã
dns1.p01.nsone.netãã¢ãã¬ã¹ns-cloud-b1.googledomains.comãªã©ã®ããGoogleãµãŒããŒã«å€æŽããããšã«ããŸããã
倿Žãå ãããšãããã¡ã€ã³ã¬ãžã¹ãã©ã¯ããäžåãªã¡ãã»ãŒãžã衚瀺ããŸããããexamplecat.comãžã®å€æŽã¯ä¿åãããŸããããããã¯48æé以å ã«çºå¹ããŸãããæ¬¡ã«ã1.2.3.4ãæãããã«ãã¡ã€ã³ã®æ°ããAã¬ã³ãŒããèšå®ããŸããã
ããŠãäœããå€ãã£ããã©ããèŠãŠã¿ãŸãããïŒ
$ dig @8.8.8.8 examplecat.com
examplecat.com. 17 IN A 104.248.50.87
倿Žã¯ãããŸãããå¥ã®DNSãµãŒããŒã«åãåããããšãæ°ããIPãããããŸãã
$ dig @1.1.1.1 examplecat.com
examplecat.com. 299 IN A 1.2.3.4
ãããã8.8.8.8ã¯ãŸã äœãç¥ããŸããã5ååã«å€æŽããã°ãããªã®ã«1.1.1.1ã«æ°ããIPã衚瀺ãããçç±ã¯ããããããããŸã§ãã®examplecat.comã«ã€ããŠ1.1.1.1ã«è³ªåããããšããªãããã§ãããããã£ãŠããã£ãã·ã¥ã«ã¯äœããããŸãããããã ã£ãã
ããŒã ãµãŒããŒã«ã¯ãã£ãšå€ãã®TTLããããŸã
ç§ã®ã¬ãžã¹ãã©ãã48æéãããããšèšã£ãã®ã¯ãNSã¬ã³ãŒãã®TTLïŒååž°ãµãŒããŒãã¢ã¯ã»ã¹ããããŒã ãµãŒããŒã«é¢ããæ å ±ïŒãã¯ããã«å€§ããããã§ãã
æ°ããããŒã ãµãŒããŒã¯ãexamplecat.comã®æ°ããIPã¢ãã¬ã¹ã確å®ã«è¿ããŸãã
$ dig @ns-cloud-b1.googledomains.com examplecat.com
examplecat.com. 300 IN A 1.2.3.4
ãã ãã以åã«github.comããŒã ãµãŒããŒã«ã¯ãšãªãå®è¡ãããšãã«äœãèµ·ãã£ãããèŠããŠãããŠãã ããã
$ dig @192.5.6.30 github.com
...
github.com. 172800 IN NS ns-421.awsdns-52.com.
ns-421.awsdns-52.com. 172800 IN A 205.251.193.165
...
172,800ç§ã¯48æéã§ãïŒãããã£ãŠãããŒã ãµãŒããŒã®æŽæ°ã«ã¯éåžžãã¯ããã«é·ãæéãããããŸãããã£ãã·ã¥ã®æå¹æéãåããŠæ°ããã¢ãã¬ã¹ãäŒæããããŸã§ã«ã¯æéãããããŸããããŒã ãµãŒããŒã倿Žããã«IPã¢ãã¬ã¹ãæŽæ°ãããããã¯ããã«æéãããããŸãã
ããŒã ãµãŒããŒã®æŽæ°æ¹æ³
ã®ããŒã ãµãŒããŒãæŽæ°ãã
examplecat.comãšãããŒã ãµãŒããŒ.comã¯æ°ãããã¡ã€ã³ã§æ°ããNSã¬ã³ãŒããååŸããŸãããã®ãããªïŒ
dig ns @j.gtld-servers.net examplecat.com
examplecat.com. 172800 IN NS ns-cloud-b1.googledomains.com
ãããããã®æ°ããNSã¬ã³ãŒãã¯ã©ã®ããã«ããŠããã«å°éããã®ã§ãããããå®éãWebãµã€ãã§æ°ããããŒã ãµãŒããŒãæŽæ°ããŠããã¡ã€ã³ã¬ãžã¹ãã©ã«ã©ã®ããã«è¡šç€ºããããäŒããŠããããã¡ã€ã³ã¬ãžã¹ãã©ãããŒã ãµãŒããŒ
.comã«æŽæ°ãè¡ãããã«æç€ºããŸãã
以äžã®ããã«
.comãããã®æŽæ°ããªãéãïŒæ°å以å
ïŒã§ãããç§ã¯ããã€ãã®ä»ã®TLDãŸãŒã³ã«ãããŒã ãµãŒãã¯ãããšããŠæŽæ°ãé©çšããªããããããªããšæããŸãã
ããã°ã©ã ã®DNSãªãŸã«ãã©ã€ãã©ãªã¯DNSã¬ã³ãŒãããã£ãã·ã¥ããããšãã§ããŸã
TTLãå®éã«èгå¯ãããªãå¯èœæ§ããããã1ã€ã®çç±ã¯ãå€ãã®ããã°ã©ã ãDNSåã解決ããå¿ èŠããããäžéšã®ããã°ã©ã ã¯DNSã¬ã³ãŒããã¡ã¢ãªã«ç¡æéã«ãã£ãã·ã¥ããããšããããŸãïŒããã°ã©ã ãåèµ·åããããŸã§ïŒã
ããšãã°ãDNSã«ãã¯ã¢ããçšã®JVMTTLã®èšå®ã«é¢ããèšäºããããŸããç§èªèº«ã¯DNSã«ãã¯ã¢ããçšã®JVMã³ãŒããããŸãäœæããŠããŸããããJVMãšDNSã«é¢ããã€ã³ã¿ãŒãããæ€çŽ¢ãå°ãè¡ããšããã¹ãŠã®DNSã«ãã¯ã¢ãããç¡éã«ãã£ãã·ã¥ããããã«JVMãæ§æã§ãããšããå°è±¡ããããŸãïŒããšãã°ããã®ElasticSearchãã±ãããåç §ããŠãã ããïŒ ..ã
ããã§å šéšã§ãïŒ
ããããDNSãæŽæ°ããããšãã«äœãèµ·ããããçè§£ããã®ã«åœ¹ç«ã€ããšãé¡ã£ãŠããŸãã
DNSäŒæã®å±¥æŽå šäœãTTLã ãã§ãªã決å®ãããããšãäºçŽããŸããäžéšã®ååž°DNSãµãŒããŒã¯ã8.8.8.8ã®ãããªäž»èŠãªãµãŒããŒã§ãããããããTTLãå°éããŸããããããã£ãŠãå°ããªTTLã§Aã¬ã³ãŒããæŽæ°ããã ãã§ããå®éã«ã¯1ã2æ¥ä»¥å ã«å€ãIPã®èŠæ±ãåä¿¡ããå¯èœæ§ããããŸãã
ãã®èšäºãæçš¿ããåŸãexamplecat.comã®ããŒã ãµãŒããŒã以åã®å€ã«æ»ããŸããã
ä»ã«èªãã¹ãããšïŒ