OS:Ubuntu 12.04 64位

Zero、Introduction

DNS pollution:

DNS cache pollution—also known as DNS cache poisoning—refers to a situation where certain DNS packets are created intentionally or accidentally, but the domain name ends up pointing to an incorrect IP address. Generally, trusted DNS servers already exist on the Internet; however, to reduce traffic load on the network, DNS servers typically temporarily cache resolution records received from upstream DNS servers. Then, when another machine requests the same domain name later, the server can respond immediately.

If the cache on a local DNS server serving the relevant domain is poisoned, computers in that local domain can be redirected to the wrong server or to the wrong website/URL. 1

OpenDNS:

OpenDNS provides DNS solutions for both personal users and businesses. Users can choose to use OpenDNS’s service or use the DNS provided by their local ISP. Placing server groups strategically and using a large amount of cached domain data allows DNS queries to complete much faster, which in turn speeds up page discovery/loading.

DNS query results are sometimes cached by the local operating system or applications, so speed improvements may not be obvious on every query. But if the desired result is not present in the local cache, the speed-up will be clearly noticeable. Other features include an anti-phishing filter and input correction (type correction)—for example, if you type wikipedia.og, it will be automatically replaced with wikipedia.org.

By collecting lists of malicious websites, OpenDNS blocks these sites when users try to access them through its service. OpenDNS has recently launched an anti-phishing service (PhishTank), so users worldwide can report and review untrusted phishing sites.

OpenDNS is not open-source software as its name might suggest. 2

Why DNSCrypt can prevent DNS pollution

Put simply and in a way that’s easy to grasp

Traditional DNS transmits data in plaintext—like a postcard. On a postcard, in designated fields, you write who you are, who it’s going to, and what information you’re asking for. That way, the person who delivers the postcard can see exactly what you wrote. If they’re unhappy, they can take your postcard, forge a modified version of its contents, and send it back to trick you (or simply intercept it before it reaches the destination, depending on what they intend to do).

The same principle applies to the answer the DNS server sends back to you.

DNSCrypt encrypts DNS information. What’s “written on the postcard” becomes a language that both you and the DNS server can understand, but that the postal courier and other third parties cannot. The courier assumes it’s a normal letter and delivers it to the destination with almost no changes.

Of course, one day the courier might notice: “Hey… this DNS server’s stuff looks a bit off.” At that point, they could potentially corrupt the contents for all messages from that server—or even just drop them. But so far, they haven’t done that…

Some people mention using TCP, but that’s not the core reason. DNSCrypt can also work over UDP. The TCP option is more like an extra feature; in networks with a higher packet loss rate, UDP can be less reliable to use in practice. 3

Dnsmasq

Dnsmasq is a lightweight open-source DNS forwarder, and it also acts as a DHCP/TFTP server. It is written in C. Dnsmasq is designed for small networks such as home LANs: it uses low resources and is easy to configure. Supported platforms include Debian, Fedora, Smoothwall, IP-Cop, floppyfw, Firebox, LEAF, Freesco, fli4l, CoyoteLinux, and Android. It is also used in router firmware systems like dd-wrt and OpenWrt. 4

Ubuntu

Ubuntu (international phonetic transcription: English pronunciation /ʊˈbʊntuː/, roughly uu-buun-too) is a GNU/Linux operating system focused mainly on desktop applications. Its name comes from the word “ubuntu” in Zulu or Xhosa languages from Southern Africa (translated as “ubantu”), meaning “humanity” and “my existence is because everyone exists”—reflecting traditional African values.

Ubuntu was created by Mark Shuttleworth. The first version—4.10—was released on October 20, 2004, using Debian as its development baseline. Unlike Debian’s stable upgrade strategy, Ubuntu releases a new version every six months so users can obtain and use new software on time.

The purpose of Ubuntu’s development is to make personal computers easier to use, while also providing server versions for business/enterprise usage. Each new Ubuntu version usually includes the latest GNOME desktop environment available at that time, and typically ships within one month after GNOME releases a new version. Compared with other Debian-based Linux distributions such as MEPIS, Xandros, Linspire, Progeny, and Libranet, Ubuntu is closer to Debian’s development philosophy: it mainly uses free and open-source software, while other distributions often come bundled with many proprietary (closed-source) components.

Ubuntu is built on Debian’s unstable branch—whether it’s the software format (deb) or the software management and installation system (Debian Apt). Ubuntu developers feed their software modifications back to the Debian community in real time, not only when new releases are announced. In fact, many Ubuntu developers are also maintainers of key Debian packages. However, Debian and Ubuntu are not always 100% compatible: installing Debian packages on Ubuntu may cause compatibility issues, and vice versa.

Ubuntu’s operation relies mainly on support from Canonical, along with assistance from Linux community enthusiasts. Ubuntu developers often refer to Mark Shuttleworth as SABDFL (an abbreviation of self-appointed benevolent dictator for life, meaning a self-appointed “benevolent dictator for life”). On July 8, 2005, Mark Shuttleworth and Canonical announced the formation of the Ubuntu Foundation and provided 10 million USD as initial operating capital. The foundation’s purpose is to ensure that Ubuntu can continue developing and receive support in the future, but until 2006, the foundation still had not started actual operations. Mark Shuttleworth described this foundation as emergency operating funds during Canonical’s financial crisis.

In previous versions, users could obtain free installation discs through the shipit service. Ubuntu 6.06 offered free shipit; however, the subsequent Ubuntu 6.10 no longer provided free shipit-posted installation discs—users only needed to download the disk image from the website and burn it to install. Around the time Ubuntu 6.06 was released, there were reports that shipit would no longer be offered for non-LTS releases. But when Ubuntu 7.04 was released, the shipit service resumed—though this version was not an LTS. Before the Ubuntu 11.04 release, the shipit service was stopped.

Currently, Ubuntu has five Long Term Support (LTS) versions: Ubuntu 6.06, 8.04, 10.04, 12.04, and 14.04. Ubuntu 12.04 and 14.04 have a 5-year support cycle for both desktop and server. Earlier LTS versions supported desktop for 3 years and server for 5 years. 5

Ubuntu release list: 6

Ubuntu release list

Version number Codename Chinese meaning
Ubuntu 4.10 Warty Warthog 多疣的疣猪
Ubuntu 5.04 Hoary Hedgehog 白发的刺猬
Ubuntu 5.10 Breezy Badger 活泼的獾
Ubuntu 6.06 LTS Dapper Drake 整洁的公鸭
Ubuntu 6.10 Edgy Eft 尖利的小蜥蜴
Ubuntu 7.04 Feisty Fawn 烦躁不安的小鹿
Ubuntu 7.10 Gutsy Gibbon 胆大的长臂猿
Ubuntu 8.04 LTS Hardy Heron 坚强的苍鹭
Ubuntu 8.10 Intrepid Ibex 勇敢的野山羊
Ubuntu 9.04 Jaunty Jackalope 得意洋洋的怀俄明野兔
Ubuntu 9.10 Karmic Koala 幸运的考拉
Ubuntu 10.04 LTS Lucid Lynx 清醒的猞猁
Ubuntu 10.10 Maverick Meerkat 标新立异的的狐獴
Ubuntu 11.04 Natty Narwhal 敏捷的独角鲸
Ubuntu 11.10 Oneiric Ocelot 有梦的虎猫
Ubuntu 12.04 LTS Precise Pangolin 精准的穿山甲
Ubuntu 12.10 Quantal Quetzal 量子的格查尔鸟
Ubuntu 13.04 Raring Ringtail 铆足了劲的环尾猫熊
Ubuntu 13.10 Saucy Salamander 活泼的蝾螈
Ubuntu 14.04 LTS Trusty Tahr 可靠的塔尔羊
Ubuntu 14.10 Utopic Unicorn 乌托邦的独角兽

One、Configure PPA

sudo apt-get install python-software-properties
sudo add-apt-repository ppa:shnatsel/dnscrypt

Two、Install DNSCrypt Proxy

Install:

sudo apt-get update
sudo apt-get install dnscrypt-proxy

Configure:

Since DNSCrypt’s default port is 53, it will conflict with DNSMasq. So we need to change the port to another one—e.g., change it to 40.

Modify /etc/default/dnscrypt-proxy 7: find that line and change the port to 40. Of course, you can choose a different port as long as it doesn’t conflict with other ports on the system:

# What local IP the daemon will listen to, with an optional port. The default port is 53.
local
-address=127.0.0.2:40

Test:

$ sudo service dnscrypt-proxy restart
dnscrypt-proxy stop/waiting
dnscrypt-proxy start/running, process 1561

$ dig g.cn @127.0
.0.2 -p 40
; > DiG 9.8
.1-P1 <<>> g.cn @127.0.0.2 -p 40;; global options: +cmd
;; Got answer:
;; ->>HEADER<<- opcode: QUERY, status: NOERROR, id: 30656
;; flags: qr rd ra; QUERY: 1
, ANSWER: 5, AUTHORITY: 0, ADDITIONAL: 1
;; OPT PSEUDOSECTION:
; EDNS: version: 0
, flags:; udp: 4096;; QUESTION SECTION:
;g.cn.				IN	A

;; ANSWER SECTION:
g.cn.			227
	IN	A	203.208.48.148g.cn.			227
	IN	A	203.208.48.144g.cn.			227
	IN	A	203.208.48.145g.cn.			227
	IN	A	203.208.48.146g.cn.			227
	IN	A	203.208.48.147
;; Query time: 113
 msec;; SERVER: 127.0
.0.2#40(127.0.0.2);; WHEN: Sun Aug 23
 22:28:37 2015;; MSG SIZE  rcvd: 113

Explanation:

DNSCrypt has three run modes:

Command line mode: set the start command directly using parameters on the command line 8

Supported commands are:

$ dnscrypt-proxy --help
dnscrypt-proxy 1.4
.0
Options:

  -a
	--local-address=...			# 监听的地址,例如: 127.0.0.1:53  -d
	--Daemonize模式				# 守护进程模式  -e
	--edns-payload-size=...		# 后面略,详情见官方文档[^2]  -h	--help
  -L	--resolvers-list=...
  -R	--resolver-name=...
  -l
	--logfile=...  -m	--loglevel=...
  -n	--max-active-requests=...
  -p	--pidfile=...
  -X	--plugin=...
  -N	--provider-name=...
  -k	--provider-key=...
  -r	--resolver-address=...
  -u	--user=...
  -t	--test=...
  -T	--tcp-only
  -V	--version

Please consult the dnscrypt-proxy(8
) man page for details.

Daemonize mode: run as a background process.

Start it directly with sudo dnscrypt-proxy -d. No command-line parameters are needed; all parameters are read from the configuration file /etc/default/dnscrypt-proxy.

System service mode: the default run mode

After installation, or when the system starts, it will start automatically. Like Daemonize mode, the start parameters are read from the configuration file /etc/default/dnscrypt-proxy

  • Stop: sudo service dnscrypt stop
  • Start: sudo service dnscrypt start
  • Restart: sudo service dnscrypt restart

Two、Install DNSMasq

Install:

sudo apt-get update
sudo apt-get -y install dnsmasq

Configure:

Edit the configuration file /etc/dnsmasq.conf. You can adjust the file contents as needed. Here we won’t go into the detailed functions of every option and all the cautions—see google 9 for details. At this point, you only need to change one line: set DNSMasq’s upstream server to the DNSCrypt-Proxy you configured just now. Find it and change it to this:

# You can control how dnsmasq talks to a server: this forces
# queries to 10.1.2.3 to be routed via eth1
# server=10.1.2.3@eth1
server=127.0
.0.2#40

Test

Note: the port here is -p 53, which is different from the -p 40 port of dnscrpyt-proxy discussed earlier.

$ sudo service dnsmasq restart
Stopped Name Service Cache Daemon: nscd.
 * Starting Name Service Cache Daemon nscd                               [ OK ]
 * Restarting DNS forwarder and DHCP server dnsmasq                      [ OK ]
Stopped Name Service Cache Daemon: nscd.
 * Starting Name Service Cache Daemon nscd                               [ OK ]

$ dig g.cn @127.0
.0.1 -p 53
; > DiG 9.8
.1-P1 <<>> g.cn @127.0.0.1 -p 53;; global options: +cmd
;; Got answer:
;; ->>HEADER<<- opcode: QUERY, status: NOERROR, id: 52188
;; flags: qr rd ra; QUERY: 1
, ANSWER: 5, AUTHORITY: 0, ADDITIONAL: 1
;; OPT PSEUDOSECTION:
; EDNS: version: 0
, flags:; udp: 4096;; QUESTION SECTION:
;g.cn.				IN	A

;; ANSWER SECTION:
g.cn.			295
	IN	A	203.208.48.144g.cn.			295
	IN	A	203.208.48.146g.cn.			295
	IN	A	203.208.48.148g.cn.			295
	IN	A	203.208.48.145g.cn.			295
	IN	A	203.208.48.147
;; Query time: 113
 msec;; SERVER: 127.0
.0.1#53(127.0.0.1);; WHEN: Sun Aug 23
 22:41:00 2015;; MSG SIZE  rcvd: 113

Explanation:

dnsmasq can also use other upstream servers, such as the well-known 8.8.8.8 and 114.114.114.114. By default, dnsmasq listens on the external port, so you don’t need to specifically configure the “listen IP”. You can test by directly accessing the external IP, for example:

nslookup g.cn 192.168
.31.139

Three、OpenDNS effectiveness test

Visit OpenDNS的测试页面. If you see the check mark, it means the configuration succeeded. If there are problems, please leave a comment :)


1.

DNS cache pollution, Wikipedia:https://zh.wikipedia.org/wiki/域名服务器缓存污染↩ 2.

OpenDNS, Wikipedia:https://zh.wikipedia.org/wiki/OpenDNS↩ 3.

What is the working principle of DNSCrypt? Why can it prevent DNS pollution?,Zhihu:http://www.zhihu.com/question/24253866/answer/29272628↩ 4.

Dnsmasq, Wikipedia:https://zh.wikipedia.org/wiki/Dnsmasq↩ 5.

Ubuntu, Wikipedia:https://zh.wikipedia.org/wiki/Ubuntu↩ 6.

Ubuntu release list, Wikipedia:https://zh.wikipedia.org/wiki/Ubuntu发行版列表↩ 7.

This file is automatically generated when installing DNSCrypt ↩ 8.

This is the standard startup format in the documentation; see official documentation:https://github.com/jedisct1/dnscrypt-proxy#usage↩ 9.

DNSMasq configuration:https://www.google.com/search?q=dnsmasq.conf%20%E7%9A%84#newwindow=1&safe=active&q=dnsmasq.conf+%E9%85%8D%E7%BD%AE↩