This is Warren Kwok's Internet note pad, electronic diary, online rubbish journal, whatever you might name it ! It is an archive of my random thoughts in a chronological order. I am not good at reporting boring things and change them to lively. If you find this blog boring, sorry that it is your problem.
2010/05/29
2010/05/27
2010/05/25
IPv6 Sage T-Shirt
Nice to learn that Hurricane Electric is giving out T-Shirt for those attained the Sage level. When I need to do is to log in, and in the account setup, click the request T-Shirt button and validate the postal address. Upon completion, extra 100 score points will be added so my score is 1500.
The T-Shirt and the extra 100 score are nice gifts. Thanks to Hurricane Electric.
The T-Shirt and the extra 100 score are nice gifts. Thanks to Hurricane Electric.
2010/05/23
My dog, Mark Chai passed away yesterday
My dog (Mark Chai) passed away yesterday after staying with my family for 16 years (6 Dec 1993 -22 May 2010). Things change now. A family of four becomes a family of three.
Looking back, I hate myself for not treating my dog much better. I should have bought more tasty snack for him to eat. I should have spared more time to take the dog for a longer walk in the park. I should not have punished him for occasionally pissing on the floor and making the house a mess. I should have paid more attention to his deteriorating body condition. I promised I will certainly be good to him if God can bring him back to life.
Dogs are our best companion. We only need to give them food, water and shelter and then they will be loyal to us for the rest of their life.
Looking back, I hate myself for not treating my dog much better. I should have bought more tasty snack for him to eat. I should have spared more time to take the dog for a longer walk in the park. I should not have punished him for occasionally pissing on the floor and making the house a mess. I should have paid more attention to his deteriorating body condition. I promised I will certainly be good to him if God can bring him back to life.
Dogs are our best companion. We only need to give them food, water and shelter and then they will be loyal to us for the rest of their life.
2010/05/22
2010/05/15
2010/05/14
林彬之死
林彬之死,鐵證如山,不容抵賴,是民建聯前身及工聯會所幹的醜事,且看中共喉舌《大公報》的標題:

可恨特區政府還不知羞恥,頒大紫荊勳章給楊光 - 當年工聯會的領袖及左派67年暴動的策劃者,真的對當年所有死難者不敬。
可恨特區政府還不知羞恥,頒大紫荊勳章給楊光 - 當年工聯會的領袖及左派67年暴動的策劃者,真的對當年所有死難者不敬。
2010/05/12
GFW poisons DNS resolution
I have heard about GFW purposely poison DNS information but as I am in Hong Kong, I have no way of testing this scenario. Thanks to websitepulse which offers a facility for testing accessibility to websites behind China GFW. The URL is at:
http://www.websitepulse.com/help/testtools.china-test.html
My test on access to www.twitter.com is dumped in the picture below. The fake return IP address is 37.61.54.158. Actually 37.0.0.0/8 Class A range is not assigned yet so there is no route to this IP address.
http://www.websitepulse.com/help/testtools.china-test.html
My test on access to www.twitter.com is dumped in the picture below. The fake return IP address is 37.61.54.158. Actually 37.0.0.0/8 Class A range is not assigned yet so there is no route to this IP address.
2010/05/10
Root Zone Public Keys
Some network administrators are eager to see what the root zone public keys look like which were issued on 5 May. In fact, ICANN has issued the warning inside the key strings that "This is an invalid key and should not be used contact rootsign@icann.org for more information". See my dump below:
***** Root Zone Public Keys *****
[localhost]# dig +dnssec dnskey . @192.5.5.241
; <<>> DiG 9.5.2-RedHat-9.5.2-1.fc10 <<>> +dnssec dnskey . @192.5.5.241
;; global options: printcmd
;; Got answer:
;; ->>HEADER<<- opcode: QUERY, status: NOERROR, id: 47371
;; flags: qr aa rd; QUERY: 1, ANSWER: 4, AUTHORITY: 0, ADDITIONAL: 1
;; WARNING: recursion requested but not available
;; OPT PSEUDOSECTION:
; EDNS: version: 0, flags: do; udp: 4096
;; QUESTION SECTION:
;. IN DNSKEY
;; ANSWER SECTION:
. 86400 IN DNSKEY 257 3 8 AwEAAawBe++++++++++++++++THIS/IS/AN/INVALID/KEY/AND/SHOU LD/NOT/BE/USED/CONTACT/ROOTSIGN/AT/ICANN/DOT/ORG/FOR/MOR E/INFORMATION+++8=
. 86400 IN DNSKEY 257 3 8 AwEAAazdM++++++++++++++++THIS/IS/AN/INVALID/KEY/AND/SHOU LD/NOT/BE/USED/CONTACT/ROOTSIGN/AT/ICANN/DOT/ORG/FOR/MOR E/INFORMATION+++++8=
. 86400 IN DNSKEY 256 3 8 AwEAAavbA++++++++++++++++THIS/IS/AN/INVALID/KEY/AND/SHOU LD/NOT/BE/USED/CONTACT/ROOTSIGN/AT/ICANN/DOT/ORG/FOR/MOR E/INFORMATION+++++++++++++++++++++++++++8
. 86400 IN RRSIG DNSKEY 8 0 86400 20100515235959 20100501000000 19324 . QWXJEkPRYzAu8SpGmzRw1y9B9JOPRNl9C5csTh6Edv4xQRUb0apb7YRD mhbIgqZN4TMMme70pni93z8gn7fqtylFzCObC0prH90vq20DjxcOeZtV ufvoadCQFsUi87G2kgicZjRLSHjz/h2zJO36nmdp/S05wGxT9KX56Yoy hjuSr6AzCCQvsmDKdhL8D8SAPAZGjPs0ftfKsDyEarcy9XYP9nZfskmQ OWbx0ldr41JfibY3+onP/tA61KQdTQYZ2bAU/eQK/6Kq2YEzSzQijwdV Kex+hi4LXWB85u9uY8YMsa1MVJDY/BYkjW4HU1wvKY47oz4G3oDyI23X IR8NSA==
;; Query time: 5 msec
;; SERVER: 192.5.5.241#53(192.5.5.241)
;; WHEN: Mon May 10 09:44:35 2010
;; MSG SIZE rcvd: 1011
****** End *****
***** Root Zone Public Keys *****
[localhost]# dig +dnssec dnskey . @192.5.5.241
; <<>> DiG 9.5.2-RedHat-9.5.2-1.fc10 <<>> +dnssec dnskey . @192.5.5.241
;; global options: printcmd
;; Got answer:
;; ->>HEADER<<- opcode: QUERY, status: NOERROR, id: 47371
;; flags: qr aa rd; QUERY: 1, ANSWER: 4, AUTHORITY: 0, ADDITIONAL: 1
;; WARNING: recursion requested but not available
;; OPT PSEUDOSECTION:
; EDNS: version: 0, flags: do; udp: 4096
;; QUESTION SECTION:
;. IN DNSKEY
;; ANSWER SECTION:
. 86400 IN DNSKEY 257 3 8 AwEAAawBe++++++++++++++++THIS/IS/AN/INVALID/KEY/AND/SHOU LD/NOT/BE/USED/CONTACT/ROOTSIGN/AT/ICANN/DOT/ORG/FOR/MOR E/INFORMATION+++8=
. 86400 IN DNSKEY 257 3 8 AwEAAazdM++++++++++++++++THIS/IS/AN/INVALID/KEY/AND/SHOU LD/NOT/BE/USED/CONTACT/ROOTSIGN/AT/ICANN/DOT/ORG/FOR/MOR E/INFORMATION+++++8=
. 86400 IN DNSKEY 256 3 8 AwEAAavbA++++++++++++++++THIS/IS/AN/INVALID/KEY/AND/SHOU LD/NOT/BE/USED/CONTACT/ROOTSIGN/AT/ICANN/DOT/ORG/FOR/MOR E/INFORMATION+++++++++++++++++++++++++++8
. 86400 IN RRSIG DNSKEY 8 0 86400 20100515235959 20100501000000 19324 . QWXJEkPRYzAu8SpGmzRw1y9B9JOPRNl9C5csTh6Edv4xQRUb0apb7YRD mhbIgqZN4TMMme70pni93z8gn7fqtylFzCObC0prH90vq20DjxcOeZtV ufvoadCQFsUi87G2kgicZjRLSHjz/h2zJO36nmdp/S05wGxT9KX56Yoy hjuSr6AzCCQvsmDKdhL8D8SAPAZGjPs0ftfKsDyEarcy9XYP9nZfskmQ OWbx0ldr41JfibY3+onP/tA61KQdTQYZ2bAU/eQK/6Kq2YEzSzQijwdV Kex+hi4LXWB85u9uY8YMsa1MVJDY/BYkjW4HU1wvKY47oz4G3oDyI23X IR8NSA==
;; Query time: 5 msec
;; SERVER: 192.5.5.241#53(192.5.5.241)
;; WHEN: Mon May 10 09:44:35 2010
;; MSG SIZE rcvd: 1011
****** End *****
2010/05/09
DNSSEC Look-aside Validation and / or IANA’s published Interim Trust Anchor Repository
For those network administrators who have not tried to make their resolvers working with ISC’s DNSSEC Look-aside Validation or IANA’s published Interim Trust Anchor Repository, they need to catch the remaining time left. By 1 July 2010, when the DNSKEY of the root zone is published, these work-around technologies will disappear in the networking world. Don't miss the chance to witness technological changes by yourselves.
2010/05/05
Avoid Error 404 page found by search engine
It is quite embarassing to me that the Error 404 Page of my website can be found by Google. On checking the error 404 html file, I noticed that I have not included the appropriate meta tag in header to tell search engine not to touch on that file. The meta tag should look like:

After 1 - 2 months, the Error 404 Page should not be found again.
Another approach is to place the Error 404 html file in a special directory and use robots.txt to disallow web spider to crawl on that directory which looks like:
[file robots.txt]
User-agent: *
Disallow: /cgi-bin/
Disallow :/404-file/
After 1 - 2 months, the Error 404 Page should not be found again.
Another approach is to place the Error 404 html file in a special directory and use robots.txt to disallow web spider to crawl on that directory which looks like:
[file robots.txt]
User-agent: *
Disallow: /cgi-bin/
Disallow :/404-file/
2010/04/30
NSEC and ldns-walk
In my previous blog post, I discussed the weakness of NSEC in DNSSEC which causes zone walking by means of trying alphabetical combinations in domain names. Actually, for those who have installed the ldns DNS tool, they need not try alphabetcial combinations for zone-walking. Just invoke "ldns-walk ripe.net" will give all sub-domain names under ripe.net and the associated NSEC records.
2010/04/29
Use fail2ban to protect dovecot against brute force attacks
From time to time, I find brute force attacks on pop and imap in addition to ftp and ssh. The fail2ban version I have can offer brute force protection for ftpd and sshd but not dovecot. In order to achieve the same for dovecot, the following files must be added under the fail2ban folder:
/etc/fail2ban/filter.d/dovecot.conf
[Definition]
failregex = dovecot-auth: pam_unix\(dovecot:auth\):
authentication failure; .* rhost=(?:\s+user=\S*)?\s*$
ignoreregex =
/etc/fail2ban/jail.conf
[dovecot-iptables]
enabled = true
filter = dovecot
action = iptables-multiport[name=Dovecot, port="pop3,pop3s,imap,imaps", protocol=tcp]
sendmail-whois[name=Dovecot, dest=you at mail.com]
logpath = /var/log/secure
maxretry = 5
bantime = 1800
ignoreip = 127.0.0.1
This works quite well. No more worry on unlimited meaningless break-in trials on port 110 and port 143.
/etc/fail2ban/filter.d/dovecot.conf
[Definition]
failregex = dovecot-auth: pam_unix\(dovecot:auth\):
authentication failure; .* rhost=
ignoreregex =
/etc/fail2ban/jail.conf
[dovecot-iptables]
enabled = true
filter = dovecot
action = iptables-multiport[name=Dovecot, port="pop3,pop3s,imap,imaps", protocol=tcp]
sendmail-whois[name=Dovecot, dest=you at mail.com]
logpath = /var/log/secure
maxretry = 5
bantime = 1800
ignoreip = 127.0.0.1
This works quite well. No more worry on unlimited meaningless break-in trials on port 110 and port 143.
2010/04/28
Reverse lookup in Postfix
I recalled that once I successfully amended the config file of postfix (/etc/postfix/main.cf) to require mandatory reverse lookup of connecting IP addresses and if no hostname could be returned, then the connections would be rejected. The directive for this is :
reject_unknown_reverse_client_hostname,
There is yet another more stringent settting
reject_unknown_client_hostname,
which requires not only that the address->name and name->address mappings exist, but also that the two mappings must reproduce the same client IP address. This one must be used with care. My experience is that not many SMTP servers can satisfy the requirements.
reject_unknown_reverse_client_hostname,
There is yet another more stringent settting
reject_unknown_client_hostname,
which requires not only that the address->name and name->address mappings exist, but also that the two mappings must reproduce the same client IP address. This one must be used with care. My experience is that not many SMTP servers can satisfy the requirements.
2010/04/21
Weakness of NSEC in DNSSEC
Some zone administrators might have heard that an obstacle to DNSSEC implementation is that the early design of DNSSEC provided the resource record of NSEC (next secure record) which tells interrogating resolvers that the domain names they are asking do not exist at all. When a zone file is signed, all the original resource records will be arranged in alphabetical order and the NSEC records are properly inserted indicating which domain name to be followed after each other. This is a huge vulnerability giving rise to zone walking and a bad guy can dig out all domain records. The illustrations are below:
[Please click on the link to see the second screen dump]
In the screen dump above, I tried to find the a record of "a.ripe.net" and the query was dnssec-enabled. The remote side just told me that this one did not exist and the next available record which best matches my query is "adder.ripe.net". Please note that I have already installed the the public key of ripe.net so all data returned are tagged with "ad" which means "authenticated data".
Next, I tried to find the a record of "ooo.ripe.net" and the result told me that the next available was "openpgp.ripe.net" as below:
[Please click on the link to see the second screen dump]
By trying different alphabetical combinations, thanks to NSEC, I can find out all domain names in a zone. NSEC is now replaced by NSEC3 for zone signing. It is quite new indeed and Windows 2008 Server R2 and Bind 9.6 or above can support it.
The IETF has recommended that all early implementations of DNSSEC signed zones must be resigned with NSEC3 for security reason.
[Please click on the link to see the second screen dump]
In the screen dump above, I tried to find the a record of "a.ripe.net" and the query was dnssec-enabled. The remote side just told me that this one did not exist and the next available record which best matches my query is "adder.ripe.net". Please note that I have already installed the the public key of ripe.net so all data returned are tagged with "ad" which means "authenticated data".
Next, I tried to find the a record of "ooo.ripe.net" and the result told me that the next available was "openpgp.ripe.net" as below:
[Please click on the link to see the second screen dump]
By trying different alphabetical combinations, thanks to NSEC, I can find out all domain names in a zone. NSEC is now replaced by NSEC3 for zone signing. It is quite new indeed and Windows 2008 Server R2 and Bind 9.6 or above can support it.
The IETF has recommended that all early implementations of DNSSEC signed zones must be resigned with NSEC3 for security reason.
2010/04/19
DNSSEC-enabled name hosting service
I guess no ISPs in Hong Kong right now has the capability to provide domain name hosting service with DNSSEC. I find one in Germany which is Exanemes (http://exanames.com/)
The standard rate is 5€ per month per domain. It is really not expensive if you consider the heavy workload of signing and resigning zones. key rollovers and publish the KSK to parent zone.
I am not going to use it as I have decided to do all the DNSSEC config by myself.
The standard rate is 5€ per month per domain. It is really not expensive if you consider the heavy workload of signing and resigning zones. key rollovers and publish the KSK to parent zone.
I am not going to use it as I have decided to do all the DNSSEC config by myself.
2010/04/17
HKNET is testing out IPv6
My IPv6 email autoreply facility (autoreply@v6-mail.com) has received test emails from HKNET Network Operation Center (noc@ipv6-test.hknet.com) and the v6 addresses in use are:
2001:2e0:4::5
2001:2e0:4::6
From the mail transaction tests, I visualize that IPv6 paths of HKNET are already well-established. It is just a matter of time for HKNET to offer to corporate customers.
In fact, HKNET was the first ISP to get IPv6 address block dated back to year 2001.
2001:2e0:4::5
2001:2e0:4::6
From the mail transaction tests, I visualize that IPv6 paths of HKNET are already well-established. It is just a matter of time for HKNET to offer to corporate customers.
In fact, HKNET was the first ISP to get IPv6 address block dated back to year 2001.
2010/04/16
IPv6 Reverse DNS Zone Builder for BIND 8/9
For those who need help in configuring IPv6 reverse lookup information, they may use “IPv6 Reverse DNS Zone Builder for BIND 8 & 9” available at:
http://www.fpsn.net/index.cgi?pg=tools&tool=ipv6-inaddr
This tool is a quick and easy way of creating BIND 8, and BIND 9 named.conf configuration entries, along with creating a zone file with the correct syntax for domain name mapping to IPv6 addresses. Users just need to input the file name, assigned IPv6 Block (e.g. 2002:ca51:1234::/48), zone managers E-mail address, primary Domain server, secondary Domain server(s) and the forward lookup records.
I have never found any websites that offer similar function.
http://www.fpsn.net/index.cgi?pg=tools&tool=ipv6-inaddr
This tool is a quick and easy way of creating BIND 8, and BIND 9 named.conf configuration entries, along with creating a zone file with the correct syntax for domain name mapping to IPv6 addresses. Users just need to input the file name, assigned IPv6 Block (e.g. 2002:ca51:1234::/48), zone managers E-mail address, primary Domain server, secondary Domain server(s) and the forward lookup records.
I have never found any websites that offer similar function.
2010/04/12
2010/04/08
Bind 9.7makes DNSSEC human touchable
BIND 9.7 promises to make DNSSEC much easier, much more human. From ISC website, it says the improvements are :
- support NSEC3;
- easier to resign zone;
- automated trust anchor management;
- support DLV;and
- support dynamic DNS configuration.
I am not sure I will be impressed by these additional features BIND 9.7. I have decided to use “Unbound” as the recursive validator and “NSD” as the DNSSEC-enabled authoritative server.
- support NSEC3;
- easier to resign zone;
- automated trust anchor management;
- support DLV;and
- support dynamic DNS configuration.
I am not sure I will be impressed by these additional features BIND 9.7. I have decided to use “Unbound” as the recursive validator and “NSD” as the DNSSEC-enabled authoritative server.
Subscribe to:
Posts (Atom)

