Net_DNS2 Version 1.3.0 – More DNSSEC Features

This release includes many new DNSSEC changes, including a new, simple “dnssec” flag that tells the server to send all the DNSSEC related resource records for the given zone, as well as include the AD flag indicating if the data is authentic. This is analogous to the “+dnssec” option on the command line dig command.

Setting “dnssec” to true makes Net_DNS2 automatically add an OPT record to the additional section of the request, with the DO bit set to 1, indicating that we would like the DNSSEC information related to the given zone.

$resolver = new Net_DNS2_Resolver(array('nameservers' => array('8.8.8.8')));

$resolver->dnssec = true;

$result = $resolver->query('org', 'SOA', 'IN');

print_r($result);

Produces:

Net_DNS2_Packet_Response Object
(
    [answer_from] => 8.8.8.8
    [answer_socket_type] => 2
    [header] => Net_DNS2_Header Object
        (
            [id] => 31102
            [qr] => 1
            [opcode] => 0
            [aa] => 0
            [tc] => 0
            [rd] => 1
            [ra] => 1
            [z] => 0
            [ad] => 1
            [cd] => 0
            [rcode] => 0
            [qdcount] => 1
            [ancount] => 2
            [nscount] => 0
            [arcount] => 1
        )

    [question] => Array
        (
            [0] => Net_DNS2_Question Object
                (
                    [qname] => org
                    [qtype] => SOA
                    [qclass] => IN
                )

        )

    [answer] => Array
        (
            [0] => Net_DNS2_RR_SOA Object
                (
                    [mname] => a0.org.afilias-nst.info
                    [rname] => noc.afilias-nst.info
                    [serial] => 2010472684
                    [refresh] => 1800
                    [retry] => 900
                    [expire] => 604800
                    [minimum] => 86400
                    [name] => org
                    [type] => SOA
                    [class] => IN
                    [ttl] => 886
                    [rdlength] => 51
                )

            [1] => Net_DNS2_RR_RRSIG Object
                (
                    [typecovered] => SOA
                    [algorithm] => 7
                    [labels] => 1
                    [origttl] => 900
                    [sigexp] => 20130429014033
                    [sigincep] => 20130408004033
                    [keytag] => 31380
                    [signname] => org
                    [signature] => KBWEIC7BTypmbMTPU2KjCkPDbN1tV29ShWqa2zoGb4uQcRDBgYhz2ajpOaaJPrK+YY2E7BavLI+kulhJn9r/5kjXlOHQG/34B+OFlQwTTwHIRqtSmBu1qJorJSrSObQGVjZt4hteNVF6rfbS2u1m/Rh43eaoVCHfhJaeyr+MzLA=
                    [name] => org
                    [type] => RRSIG
                    [class] => IN
                    [ttl] => 886
                    [rdlength] => 151
                )

        )

    [authority] => Array
        (
        )

    [additional] => Array
        (
            [0] => Net_DNS2_RR_OPT Object
                (
                    [option_code] => 
                    [option_length] => 0
                    [option_data] => 
                    [extended_rcode] => 0
                    [version] => 0
                    [do] => 1
                    [z] => 0
                    [name] => 
                    [type] => OPT
                    [class] => 512
                    [ttl] => 32768
                    [rdlength] => 0
                    [rdata] => 
                )

        )
)

You can see that the response includes the original OPT RR in the additional section, with the DO bit set to 1. The header section also includes the AD bit set to 1, indicating that the server considers the data authentic.

I’ve also included the ability to adjust the AD flag  when making a query (to indicate to the server that we’d like the value of the AD bit, without having to set the DO bit in the OPT RR – see RFC6840 section 5.7), and to adjust the CD flag (telling the server that the client will perform it’s own signature validation).

Net_DNS2 does not validate the DNSSEC signatures itself, but it does provide all the data from DNS needed so that users can. Future versions of Net_DNS2 may provide support for this.

See the change log page for a full list of changes in this release.

You can install Net_DNS2 version 1.3.0 directly from PEAR, using the command line PEAR installer:

pear install Net_DNS2

Or download it directly from the Google Code page here.

Generator Labs: Automated, Real-Time Black List (RBL) Tracking

Generator Labs is a new project I’ve been working on- an automated, real-time black list (RBL) tracking service.

RBL and URIBL Monitoring

The Generator Labs system automatically scans over 60 RBLs,  and 20 URIBLs, multiple times per day, to see if any of your IP addresses or website domains are listed, giving you the peace of mind you need to focus on your business.

The list of RBLs that Generator Labs monitors will always be kept up to date with the most current list.

Hosts

Generator Labs is a fully automated monitoring service, which checks your IP addresses and website domains against the most frequently used real-time black lists (RBLs) and Safe Browsing Databases.

 

Contacts

Get alerted immediately when one of your hosts is found on an RBL, URIBL, or in a Safe Browsing database.

Your Generator Labs account can be configured with multiple email addresses and phone numbers, for receiving alerts about your hosts. Each contact can be individually configured with different notification rules, to control how each contact receives alerts when one of your hosts is blocked.

Google Safe Browsing

The Google Safe Browsing database includes lists of website domains that may be dangerous to visitors, because they are suspected of phishing or malware.

Generator Labs will check your websites against the Google Safe Browsing database, and alert you immediately if any errors are found, ensuring that your visitors can reach your websites.

API Access

Generator Labs includes a simple, read-only, REST based API, that lets you poll our database for the current status of your hosts.

The Generator Labs API can easily be integrated into existing monitoring systems, like Nagios or Zabbix, by performing a simple HTTP GET request for the list of currently blocked hosts. The response data can be returned either as simple XML, or as a JSON object.

<?php
    echo file_get_contents('https://generatorlabs.com/api/blocks.json?api_token=123');
?>

{
    "status_code": 200,
    "status_message": "Ok",
    "total_blocks": 1,
    "data": [
        {
            "id": "5afd618836c251cbb066803f25b87fa1",
            "host": "192.168.1.1",
            "name": "Primary Mail Server",
            "status": "active",
            "last_checked": "2012-12-30 21:00:07 EST",
            "first_blocked": "2012-12-17 11:05:03 EST",
            "block_period": "13 days 13:35:58",
            "blocked": "1"
        }
    ]
}

Don’t let your customers be the first to know when your email systems or websites get blocked.

Signup for FREE today!

 

Net_DNS2 Version 1.2.5 Released

I’ve released version 1.2.5 of the PEAR Net_DNS2 library- you can install it now through the command line PEAR installer:

pear install Net_DNS2

Or download it directly from the Google Code page here.

This release includes some important fixes to the way I was calculating the offset values when building the DNS packets. Here is the full list of changes for this release:

  • changed the socket_connect() code to start off non-blocking, and call select() after connect() so a timeout on a invalid server works properly
  • added the new TLSA RR – RFC 6698
  • fixed the socket defines again; apparently the values of the SOCK are different under solaris
  • changed the Net_DNS2_Updater::update() so you can pass a reference to a variable that will be populated with the response object
  • moved the lines that add the response server/type to after the is_null() check- it should have been there to begin with.
  • fixed a whole bunch of cases where I wasn’t incrementing the offset values properly
  • added support to set the RD (recursion desired) bit when making a request

My Animals for Kids! – Free iPhone/iPad Game

My Animals for Kids is a fun and educational game that helps kids visually recognize animal shapes, and learn pronunciation and spelling of each animal’s name.

Kid tested and Parent approved! My Animals was developed for toddlers, preschoolers, ESL students, and people with disabilities.

Download for FREE here.

Quality Learning Tool

My Animals for Kids! features high resolution photographs, crisp animal shapes, and a clean, easy to use interface made specifically for little fingers.

Listen for the catchy music, fun sound FX’s, and a professionally recorded voice actor.

Content & Replay Value

My Animals for Kids! contains 10 Animals to try out for FREE! Don’t want the fun to stop? Upgrade to the 33 Animal FULL version!

For LESS than the price of a chocolate bar you get hours of fun and learning for your child!

Two modes of play (Manual / Auto); No internet connection required to play!

By Parents for Parents

Share in the fun by playing together, or let your child play on their own. Simple, straightforward- with lots to explore.

Children are rewarded for every touch with Magic Sparkles! If they’re old enough to ask for your phone, they’re old enough for our game.