2019-11-27 16:10:55 +00:00
package dns
import (
"fmt"
"github.com/google/gopacket/layers"
2023-09-02 21:49:02 +00:00
"github.com/maride/pancap/common"
2019-11-27 16:10:55 +00:00
"golang.org/x/net/publicsuffix"
"log"
)
var (
2023-09-02 21:49:02 +00:00
numAnswers int
answerDomains [ ] string
answerBaseDomains [ ] string
2019-11-27 16:10:55 +00:00
answerPrivateDomains [ ] string
2023-09-02 21:49:02 +00:00
answerType = make ( map [ layers . DNSType ] int )
answerPublicIPv4 [ ] string
answerPrivateIPv4 [ ] string
2019-11-27 16:10:55 +00:00
)
// Called on every DNS packet to process response(s)
2019-12-09 11:14:01 +00:00
func ( p * Protocol ) processDNSAnswer ( answers [ ] layers . DNSResourceRecord ) {
2019-11-27 16:10:55 +00:00
for _ , answer := range answers {
// Raise stats
numAnswers ++
// Add answer to answers array
name := string ( answer . Name )
basename , basenameErr := publicsuffix . EffectiveTLDPlusOne ( name )
if basenameErr != nil {
// Encountered error while checking for the basename
log . Printf ( "Encountered error while checking '%s' domain for its basename: %s" , name , basenameErr . Error ( ) )
continue
}
// Process type answers
2019-12-09 11:14:01 +00:00
p . processType ( answerType , answer . Type )
2019-11-27 16:10:55 +00:00
// Append full domain and base domain
2019-11-29 13:32:07 +00:00
answerDomains = common . AppendIfUnique ( name , answerDomains )
2019-11-27 16:10:55 +00:00
// Check if we need to add the base name to the private list
_ , icannManaged := publicsuffix . PublicSuffix ( name )
if icannManaged {
// TLD is managed by ICANN, add to the base list
2019-11-29 13:32:07 +00:00
answerBaseDomains = common . AppendIfUnique ( basename , answerBaseDomains )
2019-11-27 16:10:55 +00:00
} else {
// it's not managed by ICANN, so it's private - add it to the private list
2019-11-29 13:32:07 +00:00
answerPrivateDomains = common . AppendIfUnique ( name , answerPrivateDomains )
2019-11-27 16:10:55 +00:00
}
// Check if we got an A record answer
if answer . Type == layers . DNSTypeA {
// A record, check IP for being private
if ipIsPrivate ( answer . IP ) {
2019-12-03 17:14:49 +00:00
answerPrivateIPv4 = common . AppendIfUnique ( answer . IP . String ( ) , answerPrivateIPv4 )
2019-11-27 16:10:55 +00:00
} else {
2019-12-03 17:14:49 +00:00
answerPublicIPv4 = common . AppendIfUnique ( answer . IP . String ( ) , answerPublicIPv4 )
2019-11-27 16:10:55 +00:00
}
}
}
}
2019-12-03 22:51:03 +00:00
// Generates a summary of all DNS answers
2019-12-09 11:14:01 +00:00
func ( p * Protocol ) generateDNSAnswerSummary ( ) string {
2019-12-03 22:51:03 +00:00
summary := ""
2019-11-27 16:10:55 +00:00
// Overall question stats
2019-12-03 22:51:03 +00:00
summary = fmt . Sprintf ( "%s%d DNS answers in total\n" , summary , numAnswers )
2019-12-09 11:14:01 +00:00
summary = fmt . Sprintf ( "%s%s records\n" , summary , p . generateDNSTypeSummary ( answerType ) )
2019-12-03 22:51:03 +00:00
summary = fmt . Sprintf ( "%s%d unique domains of %d base domains, of which are %d private (non-ICANN) TLDs.\n" , summary , len ( answerDomains ) , len ( answerBaseDomains ) , len ( answerPrivateDomains ) )
2019-11-27 16:10:55 +00:00
// Output base domains answered with
if len ( answerBaseDomains ) > 0 {
2019-12-03 22:51:03 +00:00
summary = fmt . Sprintf ( "Answered with these base domains:\n%s" , common . GenerateTree ( answerBaseDomains ) )
2019-11-27 16:10:55 +00:00
}
// Output private domains
if len ( answerPrivateDomains ) > 0 {
2019-12-03 22:51:03 +00:00
summary = fmt . Sprintf ( "%sAnswered with these private (non-ICANN managed) domains:\n%s" , summary , common . GenerateTree ( answerPrivateDomains ) )
2019-11-27 16:10:55 +00:00
}
// Check for public and private IPs
2019-12-03 22:51:03 +00:00
summary = fmt . Sprintf ( "%sAnswered with %d public IP addresses and %d private IP addresses\n" , summary , len ( answerPublicIPv4 ) , len ( answerPrivateIPv4 ) )
2019-11-27 16:10:55 +00:00
if len ( answerPrivateIPv4 ) > 0 {
2019-12-03 22:51:03 +00:00
summary = fmt . Sprintf ( "%sPrivate IP addresses in answer:\n%s" , summary , common . GenerateTree ( answerPrivateIPv4 ) )
2019-11-27 16:10:55 +00:00
}
2019-12-03 22:51:03 +00:00
// Return summary
return summary
2019-11-27 16:10:55 +00:00
}