You are browsing as a guest. Sign up (or log in) to start making projects!

DNS-Tracker

  • 9 Devlogs
  • 59 Total hours

Real-time monitoring of DNS changes in the [hackclub/dns](https://github.com/hackclub/dns) repository, including all its forks. Reports all DNS record updates and change attempts in [#dns-tracker](https://hackclub.enterprise.slack.com/archives/C0B6EV1FYKU) (you are welcome to join)

Open comments for this post

11h 0m 5s logged

I worked on the Site Checker System, and it is now ready enough.

The Programm checks every site in the hackclub/dns repo. I makes a simple GET Request to it.

I watch the request and wait for it to fail, than I check what exactly went wrong.
Or if it was successful if read the response and check if it is maybe the site of a hosting provider which tells that the deployment could not be found (example). I also want to do this with other hosting providers like Orchard, the problem is Orchard does not give me enough information to be sure that it is orchard and not the deployment.

When I figured that a site has a problem (or not) I do three things:

  1. I write it in the database (or delete it)
  2. I create/update/delete the row in the slack list (view it in slack)
  3. I write a message to the #dns-alerts channel

The messages I write to #dns-alerts contains:

  1. the type of the message (new problem, updated problem or problem resolved)
  2. the link to the site
  3. the problem type (and I am really proud on this one, because it is colored and has the same style like the links or list items, see the screenshot, or join the channel, this is done vie the slack tag block)
  4. The link to the list record unless it was resolved (because than the record does no longer exist)
0
0
22
Open comments for this post

10h 5m 20s logged

Since the last devlog, I have made some changes: Hosting Emojis, Memory improvements, better Proxy. And I am currently working on Site-Checker.

Hosting Emojis

When the target of a record matches the following hosting providers an emoji is displayed next to it in brackets:
:orchard: Orchard
🅰️ Coolify A
🅱️ Coolify B
:vercel: Vercel
:github: GitHub Pages
:netlify: Netlify
:nest: Nest
:cloudflare: Cloudflare Pages

This is done with regexes (see them here)

Memory improvement

In my last devlog, I wrote that the program is always killed by the OOM-Killer because it uses too much RAM, that is now fixed.

The problem was that for each commit I cached all records that exists at that commit, which was not only complete waste of resources, but also completely unnecessary because I didn’t use the cache afterwards.

better Proxy

There were also some improvements for the Proxy, such as blocking Permanent Redirects for unsafe Location headers and caching the HTTPS state for a site.

Site Checker

That is my new big feature for this project. It is going to check all the sites in the dns zones. And if it finds a problem it is going to send it to a special channel and write it in a slack list (see the attached image). The checker will check for problem in the DNS or server deployment.

I already working on it. See the feature/site-chechker branch

0
0
6
Open comments for this post

11h 30m 22s logged

Previews

I have a really cool new feature (actually it is really old, the first version was already working on the 26. 6. (two months ago), but I kinda forgot to write about it):

Previews

The problem is pretty simple: Imagine someone is adding a new record like super-cool-site.hackclub.com.

The record is not merged yet, so the DNS record does not exist. Because of that you normally can’t just open the domain in your browser to check if the site is working.

So how do I solve this?

Well, to understand this you need to understand how the hostname actually works.
When you open a site in your browser like hackclub.com, it resolves to an IP address, in this case 216.150.1.1 (owned by Vercel).
But on Vercel many sites are hosted on the same IP, so how does Vercel know which site to serve.

The Host Header

The Host Header is a HTTP header which is automatically added by the browser and contains the original hostname that was requested in this case hackclub.com

So the server can look at this header and then serve the correct page.

With HTTPS it is a little bit more complicated, because the hostname is needed before the HTTP request even exists. This is where SNI comes in. I did some tricky and hacky stuff to make it work.

How the preview works

When a new proposal is detected, the Slack message now has a link next to the name of the proposal:

https://dns-tracker.fantamomo.com/preview/<host>

When the link is opened, my server looks in the database for the target IP or CNAME.
Then it makes a request to the target, but instead of using the target hostname as the Host header, it uses the hostname from the proposal.
So even tho super-cool-site.hackclub.com does not exist in DNS yet, the upstream server gets a request which looks like it came for super-cool-site.hackclub.com.
Nearly all headers and the full body are passed through to the upstream server.

When the response comes back, I check what it is.
If it is a redirect and it targets the upstream server, I rewrite it so that it goes through the preview server.
If it is anything besides HTML, I just pass it through.

But if it is HTML, I parse the HTML and do two things:
First I rewrite all links, relative or absolute, so that they point to the preview server instead of the real domain. I also inject the /preview/<host> path so my server knows what it is supposed to preview.
Second I inject a small JS script which overrides the fetch function.

This is needed because otherwise the website could load correctly, but JavaScript could still make requests directly to the real domain (which does not exist).

The script is here if you are interested: proxied_fetch.js

There is one problem

While this allows the client to basically pretend that the DNS record already exists, it doesn’t work with every hosting provider.

The problem is that the hosting provider itself may expect the domain to be configured before it serves the website.

My server can make the requests like if the DNS record exists, but I can’t make the hosting provider believe that the domain really exists.

More problems

Another problem I have is that the program uses to much RAM, so much that it gets all the time killed by the Out-of-Memory-Killer.
So I am going to investigate what exactly takes so much RAM.
If I can’t find out or it actually needs that much, then I am going to request more RAM for my nest server.

So until then, it is possible that the server gets killed, or change detection gets delayed. If you really need it, I recommend you to just wait 1-2 days until I fixed that, or ping me in Slack so that I can restart the server.

1
0
16
Open comments for this post

2h 49m 39s logged

Slack id finding

The Programm now checks the follows the links in the slack profiles to check if the may redict to GitHub (because some hackclubbers habe www.github.com instead of GitHub.com, and some other use there own url shortener so that my program broke). And due this the number of found slack ids is the first time higher then the not found (310 to 276).

Also if a found some new records and the author/commiter hasn’t been indexed, the program prioritize them so that I can hopefully send the message with the mentions.

Link

If the records I an A, AAAA, CNAME or ALIAS the link in the slack message is clickable so that you can directly open the page.

I also added a link message to the GitHub repository where the change came from.

Deleted records

In my last devlog I said that I want to detect deleted and removed records. I tried that, but it is easier to say then to implement.

0
0
78
Open comments for this post

3h 22m 42s logged

Changes

Slack id finder

I updated the GitHub to slack id finder, it now also search for messages, because the chance that someone sendet a link to his/her GitHub account is really high. Before this change I found from the 603 users only 70. After the change I found from 488 users, 234 which is near at 50% (some users are missing, because I couldn’t check does due the rate limiting from Slack).

Records parsing

Due a bug in the parsing logic more then half of the records in the repo are ignored. Like this one:

test:
- type: CNAME
   value: hackclub.com.

The bug is -, the parser has read it as an list instead of an map so I missed 1018 records, it is now fixed.

Ignoring

I also added the possibility to ignore specific repos. Like this one. I use this to test my code locally without spamming the #dns-tracker channel.

Next

The next thing is to detect deleting records on any possible way (removing the lines, reseting head, merging, branch deleting, etc.)

The image contains an proposals from @parth one of the Stardance developers, who adds an new domain staging.stardance.hackclub.com

0
0
69
Open comments for this post

13h 27m 17s logged

I have done a lot in the 13 hours

What I added

I build a database migration system so that if I change some tables (which I do more then a should), a migration script is generated and on the next start executed so that I don’t have to manually update the db.

Mentions

Since the start of this project, I always wanted to mention the user, in my dns update message, which has done the changes. Which is easier to say than to make. Before this devlog I tried to do this by Slack APIs which didn’t work, so I thought where all of Hackclubs Users have there Slack Id and there GitHub account: Hackatime. I experimented which there API to find a way to get the slack id from an GitHub-account, which is sadly not possible. So I got back to Slack API and found a way:

  1. If I want to get an User I request the Slack API with the account name
  2. Then I go through every user id that I found and check the profile of it, if there GitHub profile matches my requested name, then I have the user id
    When a new changes is detected I look in the DB and check if there is a connection.

There is only one problem: The api I use is heavily rate limited, so that I can currently check one user every 5 minutes, but it works.

(Yeah I know 13 hours is to much, but I needed to finish this feature)

0
0
27
Open comments for this post

3h 35m 47s logged

Since my last devlog the bot found some new interesting records (before #hackclub-leeks knew them), like the one in the image.

What I added

I changed the logging so that it also logs to a file and is colorful in the console.

What I tried to add

I wanted to make it so that in the message the person is mentioned that added/changed a record. The problem is: There is no way to for my to get a Slack user from its GitHub account. I know there is a profile field for the GitHub account, but I am not able to search for it. So I have some options:

  1. I could index all users on Slack, by 124.265 users with 100 requests per minute it takes around ~21 hours (and I don’t think that the FD would like that)
  2. Then I found a API. It is called “Slack SCIM API”, and it is perfect, because I can request all users that match a rule (like field GitHub == something). Until I found out that only Admins can use it.
  3. I could do it manually. It will take some time (currently 664 users have contributed or forked the hackclub/dns repo) and that is not the only reason why I will not do it

Other things

Also due to some unknown reasons the bot sometimes gets killed by the OOM Killer and I couldn’t figure out why it needs so much ram.

Btw, 3h 10m where coded on my new MacBook Air (from flavortown) and because of the new keyboard layout it takes four times longer to write every line of code and the @ is killing me

0
0
46
Open comments for this post

2h 33m 20s logged

Updated the slack message so that it is more clear what changes.
Also made the app more efficient in checking if the main repo or fork had been updated. (It makes 2 http requests which together only take around 1 second). And if nothing has changed, nothing will be added to the github rate limit.

It also runs on Nest and post messages in #dns-tracker.
There are still some bugs with detecting deleted records (in forks)

2
0
164
Open comments for this post

17m 5s logged

I created a program that scans the Hackclub/DNS repository, including its forks, to look for new entries or updates.
(Also i think i have the first devlog of stardance) (not the first, but the second)

9
1
148

Delete project?

Are you sure you want to permanently delete this project? This action cannot be undone.

All devlogs, followers, and associated data will be removed.

Followers

Loading…