ã¿ãªãããããã«ã¡ã¯ïŒ
ãããŒã¿ããé£çµ¡ããããŸãã - äŒç€Ÿã®ã·ã¹ãã ãšã³ãžã㢠SEMrushã仿¥ã¯ãäžåœã§ã® semrush.com ãµãŒãã¹ã®å®å®æ§ã確ä¿ãããšãã課é¡ã«ç§ãã¡ãã©ã®ããã«åãçµãã ãããããŠãã®å®è£ äžã«ã©ã®ãããªåé¡ã«ééãããã«ã€ããŠã話ããŸã (ããŒã¿ ã»ã³ã¿ãŒã®äœçœ®ãç±³åœã®æ±æµ·å²žã«ããããšãèæ ®ããŠ)ã
ããã¯å€§ããªè©±ã«ãªããããã€ãã®èšäºã«åãããŸããäžåœã®å®å šã«æ©èœããªããµãŒãã¹ãããã¢ã¡ãªã«äººåãã®ã¢ã¡ãªã«çã¬ãã«ã®ãµãŒãã¹ã®ããã©ãŒãã³ã¹ææšã«è³ããŸã§ããã¹ãŠãç§ãã¡ã«ã©ã®ããã«èµ·ãã£ããã説æããŸããé¢çœããŠåœ¹ã«ç«ã€ããšãçŽæããŸãããããè¡ããã
äžåœã®ã€ã³ã¿ãŒãããã®åé¡ç¹
ãããã¯ãŒã¯ç®¡çã®è©³çŽ°ã«æã詳ãããªã人ã§ãããã®ããšã«ã€ããŠèããããšãããã§ãããã äžåœã®ã°ã¬ãŒããã¡ã€ã¢ãŠã©ãŒã«ããããŒãçŽ æµã§ãã?ãããããããäœã§ãããå®éã«ã©ã®ããã«æ©èœãããã¯ãããªãè€éãªåé¡ã§ããããã«ã€ããŠèª¬æããèšäºã¯ã€ã³ã¿ãŒãããäžã§ããããèŠã€ãããŸãããæè¡çãªèгç¹ããèŠããšããã®ãã¡ã€ã¢ãŠã©ãŒã«ã®æ§é ã«ã€ããŠã¯ã©ãã«ã説æãããŠããŸãããããããããã¯é©ãã¹ãããšã§ã¯ãããŸããã 1 幎éã®äœæ¥ã®çµæã«åºã¥ããŠããããã©ã®ããã«æ©èœããããæ£ç¢ºã«èšãããšã¯ã§ããªãããšãããã«èªããŸãããç§ã®ã³ã¡ã³ããšå®éçãªçµè«ã«ã€ããŠã¯ã話ããŸãããããŠããã®ãã¡ã€ã¢ãŠã©ãŒã«ã«é¢ããåããå§ããŸãã
ãã®ãã¡ã€ã¢ãŠã©ãŒã«ã«ã€ããŠã¯å€ãã®åããããŸãããã®äžã§æãè峿·±ããã®ã 1 ã€ã®ãªã¹ãã«éããŠã¿ãŸãããã
- GoogleãFacebookãTwitterããã®ä»åæ§ã®ãµãŒãã¹ã¯äžåœã§ã¯ãããã¯ãããŠãããæ©èœããŸããã
- äžåœåœå€ããã³äžåœåœå ã«åãããã©ãã£ãã¯ã¯ãã¹ãŠãæ©æ¢°åŠç¿ã䜿çšããŠè§£æããã³å¶éãã (äžå¯©ãªãã©ãã£ãã¯ã®å Žå)ãåœå¢ãééãããã©ãã£ã㯠(ãã©ãã£ãã¯) ãå€§å¹ ã«é ããªããŸãã
- äžåœã®è«å ±æ©é¢ã¯ããã¡ã€ã¢ãŠã©ãŒã«ãééããæå·åããããã©ãã£ãã¯ããããã³ã°ããã§ãããã
- VPN ãã³ãã«ãIPSEC ãã³ãã«ã¯äžå®å®ã§ã¯ã©ãã·ã¥ããåžžã«ãããã¯ãããŸãã
- æå·åãåçŽã§ããã°ããã»ã©ããã©ãã£ãã¯ã®èªèšŒ/æå·åã«äœ¿çšããããã¹ãã¬ãŒãºãåçŽã«ãªããäžåœã®ãã¡ã€ã¢ãŠã©ãŒã«ãééããé床ãéããªããŸãã
ãããã®åã«ã€ããŠããã£ãããšã¯æ¬¡ã®ãšããã§ãã
- GoogleãFacebookãTwitterãããã³ãã®ä»ã®åæ§ã®ãµãŒãã¹ã¯ç¢ºãã«ãããã¯ãããŠããŸã (KO) ããããšãã°ãå€ãã®æè¡ç㪠Google ãã¡ã€ã³ã¯çŠæ¢ãããŠããããæ©èœããŸã (åã gstatic.com)ãããããçµè«ã¯ããããã¯ãããŠãããšæããã Google ããã®ä»ã®ãªãœãŒã¹ãç¡è¬ã«ãã¹ãŠåé€ãã¹ãã§ã¯ãªããšããããšã§ãã
- åœå¢ãééãã亀éã¯å®éã«æéã«é倧ãªé ãããããããŸãã 2 ã€ã®çµæãèŠãŠãã ããã 1 ã€ã®ãµã€ãã1 ããŒãžãç°¡å㪠GET curlãããæåã®æž¬å®ã¯äžåœãã®ãã® (çŸããéœåžæ·±ã»ã³) ããã®ãã®ã§ããã 30 ã€ç®ã¯éŠæž¯ã®å€åŽããæž¬å®ãããŸãã (éŠæž¯ã«ã¯äž»æš©ããããäžçãšã®éã«ãã¡ã€ã¢ãŠã©ãŒã«ã¯ãããŸãã)ãéœåžéã®çŽç·è·é¢ã¯çŽ40ïœXNUMXkmã§ãã
nikita@china-shenzhen:~# curl -o /dev/null -w@curl_time "https://www.semrush.com/info/ebay.com"
% Total % Received % Xferd Average Speed Time Time Time Current
Dload Upload Total Spent Left Speed
100 381k 0 381k 0 0 71824 0 --:--:-- 0:00:05 --:--:-- 82832
time_namelookup: 0.004500
time_connect: 0.169342
time_appconnect: 0.723189
time_pretransfer: 0.723499
time_redirect: 0.000000
time_starttransfer: 1.532912
----------
time_total: 5.443407
----------
size_download: 390968 Bytes
speed_download: 71824.000B/s
nikita@china-hongkong:~# curl -o /dev/null -w@curl_time "https://www.semrush.com/info/ebay.com"
% Total % Received % Xferd Average Speed Time Time Time Current
Dload Upload Total Spent Left Speed
100 319k 0 319k 0 0 2555k 0 --:--:-- --:--:-- --:--:-- 2573k
time_namelookup: 0.029366
time_connect: 0.030742
time_appconnect: 0.047310
time_pretransfer: 0.047388
time_redirect: 0.000000
time_starttransfer: 0.120793
----------
time_total: 0.124871
----------
size_download: 326755 Bytes
speed_download: 2616740.000B/sã«æ³šæãæã æé_æ¥ç¶ããããŠäžè¬ã«ããã®çµââæãããããŸãããã¡ã€ã¢ãŠã©ãŒã«ã«ãã 4 ç§ãäœåã«è¿œå ãããããã¯éæ¹ããªãé·ãã§ãã
- VPN ããã³ IPSEC ãã³ãã«ã¯é »ç¹ã«å€±æããŸããããã«ã€ããŠã¯åŸã»ã©è©³ãã説æããŸãããŠãŒã¶ãŒã䜿çšãã VPN ãµãŒããŒã¯ãæéã®çµéãšãšãã« (éåžžã¯äœ¿çšéå§ãã 1 æ¥ä»¥å ã«) ãããã¯ãããŸãã
- äžåœåšäœè ããã¯ãéä¿¡ã®æå·åãåçŽã§ããã°ããã»ã©ãéæ³æ§ããªãããšãåããããããããåœå¢ãééããé床ãéããªããšããæèŠãå¯ããããŠããããããŠåæ§ã«ããã¯ãªãŒã³ãªããã©ãã£ãã¯ã¯ããå€ãã®åž¯åå¹ ãšééé床ãåãåããŸãããäœãçè§£ã§ããªããããŒãã£ããã©ãã£ãã¯ã¯éã«ããé ãééãåãåããŸããããšãã°ãcurl ã䜿çšããŠã ifconfig.co HTTPS ããã³ HTTP ãããã³ã«çµç±ã
curl -o /dev/null -w@curl_time "https://ifconfig.co/"
% Total % Received % Xferd Average Speed Time Time Time Current
Dload Upload Total Spent Left Speed
100 13 100 13 0 0 2 0 0:00:06 0:00:05 0:00:01 3
time_namelookup: 0.004305
time_connect: 0.397465
time_appconnect: 5.149305
time_pretransfer: 5.149393
time_redirect: 0.000000
time_starttransfer: 5.568847
----------
time_total: 5.568893
----------
size_download: 13 Bytes
speed_download: 2.000B/s
curl -o /dev/null -w@curl_time "http://ifconfig.co/"
% Total % Received % Xferd Average Speed Time Time Time Current
Dload Upload Total Spent Left Speed
100 13 100 13 0 0 28 0 --:--:-- --:--:-- --:--:-- 28
time_namelookup: 0.004282
time_connect: 0.212457
time_appconnect: 0.000000
time_pretransfer: 0.212484
time_redirect: 0.000000
time_starttransfer: 0.450565
----------
time_total: 0.450620
----------
size_download: 13 Bytes
speed_download: 28.000B/såèšããŠã³ããŒãæé㯠5 ãã€ãã§ã13 ç§ã®å·®ã§ããããã«ããã®ãããªãã¹ããæ°åè¡ããšãHTTP ã§ã® GET ã¯æ¯åã»ãŒåãæéã§å®äºããã®ã«å¯ŸããHTTPS ã§ã¯ãµã€ãã 3ã5ã10ãããã«ã¯ 17 ç§ã§å¿çããå ŽåãããããšãããããŸãã SSL ãšã©ãŒãçºçããå ŽåããããŸãã
Unknown SSL protocol error in connection to ifconfig.co:443.
ããã§ãç§ãã¡ãæã£ãŠãããã®ã¯æ¬¡ã®ãšããã§ãã
- äžåœã®ãã¡ã€ã¢ãŠã©ãŒã«ã«ãã£ãŠçããåé¡ã¯äžã§èª¬æããŸããã
- å€éšãªãœãŒã¹ããã³ãã³ãã«å ãžã® ping ã宿çã«å€±ãããŸãã
- 2 ç¹éã®åŸ ã¡æéã¯åžžã«å€åããŠãããå€ãã®å Žåãåã«äºæž¬äžå¯èœã§ããç°ãªãéœåž/å°åãæ¥ç¶ããå Žåãå°åã®å°ççãªäœçœ®ã«åºã¥ããŠé å»¶ãå°ãªããªãããšãæåŸ ãããŸããããŸã£ããéã®ç¶æ³ãçºçããŸãã
- ã€ã³ã¿ãŒããããšéä¿¡ãã£ãã«ã¯éããé ããã®ã©ã¡ããã§ããæéåž¯ãææ¥ã«ãã£ãŠå€å°ã®åœ±é¿ã¯ãããŸãããåžžã«ãããšã¯éããŸããã
- äžåœããå€éšãžã® DNS ãªã¯ãšã¹ãããèš±å¯ãããã¿ã€ã ã¢ãŠããè¶ ããããšããããŸãã
æµ®ãã³äžãã£ãŠããçµµã¯ãŸãã«ãçŽ æŽããããã§ãã
ãã§ã«è¿°ã¹ãããã«ãããŒã¿ã»ã³ã¿ãŒã¯ç±³åœæ±éšã«ãããSEMrush å šäœã¯ãDC ãšã¯ã©ãŠãã«ããçžäºæ¥ç¶ãããæ°åã®è£œåãããã¯ãšã³ããããã³ããšã³ããããŒã¿ããŒã¹ãããã³ããããã¹ãŠã§æ§æãããŠããŸããç§ãã¡ã·ã¹ãã 管çè ã®ããŒã ã¯ãã»ãšãã©åŽåããããã«ããã«äžåœã§ã®äœæ¥ãéå§ãããšããä»»åãäžããããŸããã
ç§ãã¡ã¯éèŠãªè³ªåã«çããªããã°ãªããŸããã§ãããå°ãªãè²»çšã§ããããããäžåœã®ã€ã³ã¿ãŒããããšãã¡ã€ã¢ãŠã©ãŒã«ã«é¢é£ãããã¹ãŠã®åé¡ããããã¯ãŒã¯/ã¯ã©ãŠã/ãµãŒã㌠ã¬ãã«ã§è§£æ±ºããããšã¯å¯èœã§ãããã?
ç§ãã¡ã¯åãåãããšããå§ããŸãã .
ICPã©ã€ã»ã³ã¹
äžåœ (äžåœæ¬å) å ã§ãµãŒãã¹ããã¹ããããã¹ãã宿œã§ããããã«ããã«ã¯ããŸããã¡ã€ã³ã® ICP ã©ã€ã»ã³ã¹ãååŸããå¿ èŠããããŸãã
ãµã€ãã®ãŠãŒã¶ãŒ ãã©ãã£ãã¯ãäžåœæ¬åå ã§çµäºããŠããããã¡ã€ã³ã« ICP ã©ã€ã»ã³ã¹ããªãå Žåããã©ãã£ãã¯ã¯ ISP/ãã¹ãã£ã³ã°åŽã§ãããã¯ãããŸããè峿·±ãããšã«ãICP ã©ã€ã»ã³ã¹ã«ã¯ Cloudflare ã§ãã Alibaba Cloud ã§ãããç¹å®ã®ãããã€ããŒãå«ãŸããŠããŸãããããã£ãŠãCloudflare ã® ICP ã©ã€ã»ã³ã¹ãååŸããããã䜿çšã㊠Web ãµã€ãããã¹ãããŠããå Žåã¯ãAlibaba Cloud ã«ãã·ãŒã ã¬ã¹ã«ãç§»è¡ããããšã¯ã§ããŸããããã®ã©ã€ã»ã³ã¹ã«å¥ã®ãã¹ãã£ã³ã°ã远å ããå¿ èŠããããŸãã
ãã®ãã¡ã€ã³ã® ICP ã©ã€ã»ã³ã¹ãååŸããããšã§ãå ·äœçãªæè¡çãªã¢ã€ãã¢ãšãœãªã¥ãŒã·ã§ã³ãèæ¡ããå®è£ ããããšãã§ããŸããã
ãã¹ããœãªã¥ãŒã·ã§ã³
ãã ããã¹ããŒãžã³ã° ãªãã·ã§ã³ãçŽæ¥äœæãããããåãããµã€ãã®ããã©ãŒãã³ã¹ãšé床ãæé©åããåã«ãã©ã®ã¢ã¯ã·ã§ã³ããµã€ãã®ããã©ãŒãã³ã¹ãåäžããããããããã¯éã«æªåããããã確èªããããã«ããã¹ãçšã®ããŒã«ãéžæããå¿ èŠããããŸãã
ç§ãã¡ã®ãã¹ã ããŒã«ã¯ã次㮠2 ã€ã®äž»ãªèŠä»¶ãæºããå¿ èŠããããŸããã
- äžåœãããã¹ããå®è¡ã§ããã¯ãã§ãã
- ãã©ãŠã¶ãã¹ããå¿ èŠã§ãã
ããã§ç§ãã¡ã¯èŠã€ããŸãã ïŒåœŒãã¯äžçäžã®è©Šéšå Žæãç¶²çŸ ããŠããŸããäžåœã§ã¯ããã®ããŒã«ãéã㊠100500 ã®çãããã¹ããå®è¡ããããšãã§ããŸããããããã«ããã€ãã®ç°ãªããããã€ããŒãšå®è¡ã§ããæ©èœããããŸãã ããã¯ããŒã³-ãã¹ã (ããŒã¿ã»ã³ã¿ãŒã®ä»®æ³ãã·ã³ã®ãããªãã®) ããã³ ã©ã¹ããã€ã«- ãã¹ã (å¯èœãªéããŠãŒã¶ãŒã®æ¡ä»¶ã«è¿ããã®ãå¥åã¯ãŒã¯ã¹ããŒã·ã§ã³)ãåŸè ã®ã¿ã€ãã®æ€æ»ã¯ããé«äŸ¡ã§ãã
幎éå¥çŽãç· çµãïŒããæªæºã¯äžå¯ïŒãç§ãã¡ã¯æ¥œåšã®ç ç©¶ãå§ããŸãããççŽã«èšã£ãŠãç§ãã¡ã¯ãã®æ©èœã«å¬ããé©ããæããŸããã以äžãå®è¡ã§ããŸãã
- DNSãã¹ãã
- Web ãã¹ã (ãã©ãŠã¶ ãã¹ããåçŽãª GET/POSTãã¢ãã€ã« ã¯ã©ã€ã¢ã³ã ãšãã¥ã¬ãŒã·ã§ã³ãªã©)ã
- ãã©ã³ã¶ã¯ã·ã§ã³ã®ãã§ã㯠(ãã°ã€ã³ãªã©)ã
- APIãã¹ãã
- PingãtracerouteãNTP ãªã©
ãã¹ãŠããªã¹ãããããšã¯ã§ããŸããããããŠæãéèŠãªããšã¯ãåãã¹ãã¯ã倿°ã®ããããŒããã®ä»ã®ãã©ã¡ãŒã¿ãŒã远å ããããšã§éåžžã«ããŸãã«ã¹ã¿ãã€ãºã§ããããšã§ããåºåã¯ããã¹ããå®å šã«èª¬æããèšå€§ãªéã®æ å ±ã§ããç§ãã¡ã«ãšã£ãŠæãè峿·±ãããš (ãã©ãŠã¶ ãã¹ã) ã«ã€ããŠè©±ããšãçµæã«ã¯æ¬¡ã®ãã®ãå«ãŸããŸãã
- æ¥ç¶ãåŸ æ©ãããŒããSSLãDNS æéã
- TTFBãTTLBãããã¥ã¡ã³ãå®äºãã¬ã³ããªã³ã°æéãDOM ããŒãã
- å¿ç (æåã®ãã€ããŸã§ã®æéã«è¿ããã®)ãWeb ããŒãžã®å¿ç (æåŸã®ãã€ããŸã§ã®æéã«è¿ããã®)ã
- ä»»æã®ããŒã»ã³ã¿ã€ã«ãå¹³åæéãäžå€®å€æé
- ãªã©
ãããã£ãŠãããããã¹ãŠã®ææšã¯ãå€åã確èªããç¶æ³ãæ¹åãããã©ãããçè§£ããã®ã«æé©ã§ããç§ãã¡ãäž»ã«èŠãŠããã®ã¯ã ã¬ã¹ãã³ã¹ãWebããŒãžã®ã¬ã¹ãã³ã¹ãäžå€®å€ã75ããã³95ããŒã»ã³ã¿ã€ã«.
éåžžã«æåããååšããŠããéèŠãªè³ªå: ãã£ãããã€ã³ããä¿¡é Œã§ããŸãã??ãã®ããŒã«ã¯ãäžåœã®ããŸããŸãªéœåžããã®å®éã®ãµã€ãã®èªã¿èŸŒã¿é床ãåæ ããŠããã®ã§ããããããããšãå®éã®ãŠãŒã¶ãŒ ãšã¯ã¹ããªãšã³ã¹ãšã¯äœã®é¢ä¿ããªããåãªãç空ãã¹ãã®ãããªãã®ãªã®ã§ãããã?
ãã·ã¢ã«ãããšäžåœã®ãµã€ããã©ã®ããã«æ©èœãããã確å®ã«ç¥ãããšã¯ã»ãŒäžå¯èœã§ãããããããã¯å€§ããªåé¡ã§ããä»®æ³ãã·ã³ãä»ã㊠Socks ãããã·ãå®è¡ãããšãæçµçµæãšããŠãµã€ãã¯æ°å以å
ã«ããŒããããŸãããããã¯ãã¹ãã«ã¯ãŸã£ããåãå
¥ããããŸããããã®ãããæåãã¹ãã®å¯äžã®ãªãã·ã§ã³ã¯ãã¿ã€ããŒã䜿çšããŠã³ã³ãœãŒã«ããã«ãŒã«ãšåçŽãª GET ãå®è¡ããããšã§ãã ããã®ãã¹ãã¯ãããã¯ãŒã¯ ãœãªã¥ãŒã·ã§ã³ã®é床ãããåæ ããŠãããããããã¯åœ¹ã«ç«ã¡ãŸãããã©ãŠã¶ ãã¹ããããã°ãéåžžã«åªããŠããŸãã
ãã®åŸãç§ãã¡èªèº«ãäžåœã«è¡ã£ãŠç¢ºä¿¡ããŸããã Catchpoint ã¯å®éã®ããã©ãŒãã³ã¹ææšãéåžžã«æ£ç¢ºã«åæ ããŠãããããä¿¡é Œã§ããŸãã
Cloudflareäžåœãããã¯ãŒã¯
ã¡ã€ã³ãã¡ã€ã³ semrush.com ã« Cloudflare ã䜿çšããããšã«æåãããããããã«ãã®æ©èœã詊ããŠã¿ãããšã«ããŸããã ããã®ãªãã·ã§ã³ã¯ããšã³ã¿ãŒãã©ã€ãº ãµã€ãã«å¯ŸããŠã®ã¿ãå¥ã®ãªã¯ãšã¹ããšè¿œå æéã§æå¹ã«ãªããŸãããŸããCloudflare ããããã€ããŒãšããŠãªã¹ãããé©å㪠ICP ã©ã€ã»ã³ã¹ãæã€ãµã€ãã§ã®ã¿å©çšã§ããŸãããããæå¹ã«ãããšãCloudflare ã®ãäžåœ CDNãããµã€ãã§å©çšå¯èœã«ãªããŸããäžåœå°åããã®ãã©ãã£ãã¯ã¯æå¯ãã® PoP (Points of Presence) CF ã«å°éãããã®ãããã¯ãŒã¯ãŸãã¯ãããã€ããŒ/ããŒãããŒã®ãããã¯ãŒã¯ãä»ããŠçºä¿¡å ã«é ä¿¡ãããŸãã ã
ãã®ãã¹ããã³ãã®å³ã以äžã«ç€ºããŸãã
ããã¯ç§ãã¡ã«ãšã£ãŠçŽ æŽãããéžæè¢ã§ãã 2 çªç®ã®ãã¡ã€ã³ã CF çšã§ããããšã倿ããŸãããããã«ããã瀟å ã§äœ¿çšããããœãªã¥ãŒã·ã§ã³ã®æ°ãå¢ããããšã¯ãªããã€ã³ãã©ã¹ãã©ã¯ãã£ãäºå®äžè€éã«ãªããŸããã
ãã©ãŠã¶ãŒã®ãã¹ããå®è¡ãããšãããæ¬¡ã®ãããªããšãèµ·ãããŸããã
èµ€ãã²ã圢ã¯ãã¹ãã®äžåæ Œã§ãã以äžã®ãã¡ã€ã«ã¯ DNS ãšã©ãŒ (ã¿ã€ã ã¢ãŠã解決) ã§ããäžçªäžã®å€±æã¯ã¿ã€ã ã¢ãŠãã§ãã
皌åæé: 86.6
äžå€®å€: 18ç§
75 ããŒã»ã³ã¿ã€ã«: 29.3 ç§
95 ããŒã»ã³ã¿ã€ã«: 60 ç§
äžå€®å€ãè² è·ãé€å»ããåŸ reCAPTCHAã® (Google ãµãŒãã¹ã¯äžåœã§ãããã¯ãããŠãã) 㯠28 ç§ãã 18 ç§ã«æžå°ããŸãããããããsemrush.com (ç±³åœ) ã®åããã¹ãã§ãåãããŒãž (éç + åç) ã®ãŠãŒã¶ãŒ (ç±³åœ) ã® 10% ã 95 ç§æªæºã ã£ãããšãèãããšããããã¯äŸç¶ãšããŠã²ã©ãçµæã§ãã
åãã¹ãã«å ¥ã£ãŠç¢ºèªããããšãã§ããŸã ãŠã©ãŒã¿ãŒãã©ãŒã« ããã³ãã®ä»ã®ãã詳现ãªãã©ã¡ãŒã¿ãç§ãã¡ã¯ãšã©ãŒã®çç±ã調æ»ãå§ããŸãããã¿ã€ã ã¢ãŠãã«ã€ããŠã¯ããã¹ãŠãå€ããå°ãªããæããã§ããäžåœã®ã€ã³ã¿ãŒãããã¯ãåºå ¥ããããŠããããã®ãããæµ·å€ããã®ãªãœãŒã¹ã®æ¥ç¶ãšèªã¿èŸŒã¿ã®é床ã¯äžå®å®ã§äžåäžã§ãããã®åŸãDNS ãšã©ãŒã«éåžžã«é©ããŸãããç§ãã¡ã¯ãããçºèŠããŸãã ããã Cloudflareã¯å®éã«ã¯äžåœã«ããããµã€ãã¢ãã¬ã¹ã¯1ã€ã®ãšããŒãã£ã¹ãIPã«è§£æ±ºãããŸãããDNSãµãŒããŒã¯ã¢ã¡ãªã«ã®ãã®ã§ãããããDNSãªã¯ãšã¹ãã¯åœå¢ãè¶ããããšãäœåãªãããã倱æããããšããããŸãã
CF ã«ãã®è³ªåãæç¢ºã«ãããšãããæ¬¡ã®ããšã倿ããŸããã äžåœã«ã¯ç¬èªã®DNSãµãŒããŒãæã£ãŠããŸãããããããã€ã«ãªããã¯ãŸã äžæã§ãã
ãããã£ãŠãCloudflare DNS ã®ã¿ããã¹ãããããšã決å®ãããµã€ãã® Cloudflare åäœã¡ã«ããºã ããDNSã®ã¿ãããã¯ãCloudflareãããèªäœãä»ããŠãã©ãã£ãã¯ããããã·ããªãå Žåã®ã¢ãŒãã§ããã€ãŸããDDoSä¿è·ãCDNããã®ä»ã®æ©èœã¯æäŸããããéåžžã®DNSãµãŒããŒã®ã¢ãŒãã§åäœããŸãã
ãã®ã¹ã¿ã³ããæ¬¡ã®å³ã«æŠç¥çã«ç€ºããŸãããã®æ°åã¯ãCloudflare ã® DNS ãµãŒããŒããã¡ã€ã¢ãŠã©ãŒã«ã®èåŸã«ãããšããæ°ããªç¥èãèæ ®ã«å ¥ããŠããŸãã
Catchpoint ã§ã¯ã(ãã©ãŠã¶ãŒ ãã¹ãã§ã¯ãªã) åçŽãª GET ãã¹ããå®è¡ããŸããããå€ãã®å€±æã瀺ãããŸããããããã¯åã DNS ãšã©ãŒãåå ã§ããã
ãããã®ãšã©ãŒã®ãããã°ãéå§ããŸãã dig æåã®ãªã¯ãšã¹ãã§ã¯ã¢ãã¬ã¹ãæ£ããæ±ºå®ãããç¹°ãè¿ãã®ãªã¯ãšã¹ãã§ã¯æ¯ååä¿¡ããããšãããããŸããã ãµãŒããã§ã€ã« О èŠã€ãããŸããããªãçªç¶ãã®ãããªããšãèµ·ãã£ãã®ã§ãããã?
root@iZwz97n2wgbp61qucbfrjsZ:~# host semrushchina.cn
semrushchina.cn has address 220.170.186.192
Host semrushchina.cn not found: 2(SERVFAIL)
root@iZwz97n2wgbp61qucbfrjsZ:~# host semrushchina.cn
semrushchina.cn has address 220.170.186.192
Host semrushchina.cn not found: 2(SERVFAIL)
root@iZwz97n2wgbp61qucbfrjsZ:~# host semrushchina.cn
semrushchina.cn has address 220.170.186.192
Host semrushchina.cn not found: 2(SERVFAIL)
root@iZwz97n2wgbp61qucbfrjsZ:~# host semrushchina.cn
semrushchina.cn has address 220.170.186.192
Host semrushchina.cn not found: 2(SERVFAIL)Cloudflare NSãµãŒããŒã«çŽæ¥ã¯ãšãªãå®è¡ããå Žåã«ã¯ããã®ãããªãšã©ãŒã¯çºçããŸããã
root@iZwz97n2wgbp61qucbfrjsZ:~# for i in `seq 1 2`; do host semrushchina.cn ray.ns.cloudflare.com.; done
Using domain server:
Name: ray.ns.cloudflare.com.
Address: 173.245.59.138#53
Aliases:
semrushchina.cn has address 220.170.186.192
semrushchina.cn has address 220.170.186.192
Using domain server:
Name: ray.ns.cloudflare.com.
Address: 173.245.59.138#53
Aliases:
semrushchina.cn has address 220.170.186.192
semrushchina.cn has address 220.170.186.192ããã¯ãåé¡ããããŒã«ã«ãDNS ãµãŒããŒãŸãã¯ãããã€ããŒã®ãµãŒããŒåŽã«ããããšãæå³ããŸãã
ãããªã調æ»ã«ããã ãµãŒããã§ã€ã« ç§ãã¡ã¯æ±ºæãåºããŸã AAAA-èšé²ã
Cloudflareãããªã¯ãšã¹ããããšå€æãã AAAA-ãã¡ã€ã³ã«ååšããªãã¬ã³ãŒããCloudflareãå¿ç Ð- ãšã©ãŒã§ãããRFC ã«æºæ ããŠããªããšã³ããªããªãããŒã«ã« ãªãŸã«ã㌠(xxxxïŒç§ã¯ãããæ°ã«å ¥ããªãã£ããšåœŒã¯çããŸãã ãµãŒããã§ã€ã«ããã®åäœã¯ã以äžã®ãã°ã§ã¯ã£ãããšç¢ºèªã§ããŸãã
root@iZwz97n2wgbp61qucbfrjsZ:~# dig -t AAAA semrushchina.cn @x.x.x.x
; <<>> DiG 9.10.3-P4-Ubuntu <<>> -t AAAA semrushchina.cn @x.x.x.x
;; global options: +cmd
;; Got answer:
;; ->>HEADER<<- opcode: QUERY, status: SERVFAIL, id: 55467
;; flags: qr rd ra; QUERY: 1, ANSWER: 0, AUTHORITY: 0, ADDITIONAL: 1
;; OPT PSEUDOSECTION:
; EDNS: version: 0, flags:; udp: 4096
;; QUESTION SECTION:
;semrushchina.cn. IN AAAA
;; Query time: 334 msec
;; SERVER: x.x.x.x#53(x.x.x.x)
;; WHEN: Tue Aug 14 23:38:50 CST 2018
;; MSG SIZE rcvd: 44
root@iZwz97n2wgbp61qucbfrjsZ:~# dig -t AAAA semrushchina.cn @dana.ns.cloudflare.com.
; <<>> DiG 9.10.3-P4-Ubuntu <<>> -t AAAA semrushchina.cn @dana.ns.cloudflare.com.
;; global options: +cmd
;; Got answer:
;; ->>HEADER<<- opcode: QUERY, status: NOERROR, id: 63944
;; flags: qr aa rd; QUERY: 1, ANSWER: 1, AUTHORITY: 0, ADDITIONAL: 1
;; WARNING: recursion requested but not available
;; OPT PSEUDOSECTION:
; EDNS: version: 0, flags:; udp: 512
;; QUESTION SECTION:
;semrushchina.cn. IN AAAA
;; ANSWER SECTION:
semrushchina.cn. 300 IN A 220.170.186.192
;; Query time: 185 msec
;; SERVER: 173.245.58.105#53(173.245.58.105)
;; WHEN: Tue Aug 14 23:43:03 CST 2018
;; MSG SIZE rcvd: 60
ç§ãã¡ã¯Cloudflareã«ãã°ã¬ããŒããæåºãããã°ããããŠããä¿®æ£ããŠãããŸãããè峿·±ãããšã倿ããŸãããçŸæç¹ã§ã¯äžåœã§ã¯ãŸã IPv6 ããµããŒããããŠããªããããCloudflare ã¯èŠæ±ã«å¿ããŠäžåœã§ IPv6 ã¢ãã¬ã¹ãçºè¡ã§ããŸããã§ããã AAAA-èšé²ãæçµçã«ã¯ãCloudflare ãäžåœã«ä»£ãã£ãŠå¯Ÿå¿ãå§ãããšãã圢ã§ãã¹ãŠã解決ãããŸããã ããŒã¿ãªã ãããªãèŠæã«ã
ãããã£ãŠããã£ãããã€ã³ã ãã¹ãã§ã® DNS ãšã©ãŒã¯æ¥æ¿ã«æžå°ããŸããããå®å šã«ã¯æžå°ããŸããã§ãããã¿ã€ã ã¢ãŠãã¯ãŸã çºçããŠããŸã:
ãããŠç§ãã¡ã¯å¥ã®è§£æ±ºçãæ¢ãå§ããŸããã
次ã®ããŒãã§ã¯ãäžåœã®ã¯ã©ãŠããã©ã®ããã«ãã¹ããããã«ã€ããŠèª¬æããŸãã ã¢ãªããã¯ã©ãŠããNginx ã®ã¡ãã£ãšãããéæ³ãã®å©ããåããŠãã©ã®ããã«ã㊠PoC (æŠå¿µå®èšŒ) ãœãªã¥ãŒã·ã§ã³ãè¿ éã«äœæã§ããã®ããã©ã®ããã«ããŠãã«ãã¯ã©ãŠã ãœãªã¥ãŒã·ã§ã³ãäœæããã®ãããã® 1 ã€ã¯æçµçã«ãµãŒãã¹ã®äœæ¥é床ã®åäžã«å€§ããè²¢ç®ããŸããäžåœããã
ä¹ããæåŸ ïŒ
次ã®ããŒã
åºæïŒ habr.com
