Research
Security News
Threat Actor Exposes Playbook for Exploiting npm to Build Blockchain-Powered Botnets
A threat actor's playbook for exploiting the npm ecosystem was exposed on the dark web, detailing how to build a blockchain-powered botnet.
dynsdjs-plugin-doh-dot
Advanced tools
DNS-over-HTTPS/DNS-over-TLS plugin for dynsdjs
Just install the package via npm by doing
$ npm install -g dynsdjs-plugin-doh-dot
You can configure this plugin through Environment variables
DYNSD_USE_DOH
: This variable will tell the plugin if you want to use DNS-over-HTTPS to resolve your queries. Possible values: false
, true
. Default value: false
DYNSD_USE_DOT
: This variable will tell the plugin if you want to use DNS-over-TLS to resolve your queries. Possible values: false
, true
. Default value: false
DYNSD_DOHT_PROVIDER
: This variable will tell the plugin which provider you want to use. Possible values: google
, cloudflare
, cleanbrowsing
, quad9
. Default value: cloudflare
DYNSD_DOT_PRIVATE_KEY
: This variable will tell the plugin the path to your private key to make DNS-over-TLS requests correctly. Used only when DYNSD_USE_DOT==true
.DYNSD_DOT_CERTIFICATE
: This variable will tell the plugin the path to your certificate to make DNS-over-TLS requests correctly. Used only when DYNSD_USE_DOT==true
.If both DYNSD_USE_DOH
and DYNSD_USE_DOT
are enabled, DNS-over-HTTPS will take precedence and will be used for every query.
In order to use the DNS-over-TLS feature you are required to generate a set of private key and certificate.
To make this job simpler for you, I suggest you using the awesome tool name mkcert
by FiloSottile.
In order to generate your certificates you can simply run these commands:
$ mkcert -install
$ mkcert localhost 127.0.0.1 ::1
The last command will let you know the name of the certificate files to use, which you can then pass as a parameter to this plugin.
$ DYNSD_USE_DOH=true dynsdjs
$ DYNSD_USE_DOT=true DYNSD_DOT_PRIVATE_KEY=path/to/keyfile.pem DYNSD_DOT_CERTIFICATE=path/to/certfile.pem dynsdjs
FAQs
Dynsd DoH/DoT Plugin
The npm package dynsdjs-plugin-doh-dot receives a total of 1 weekly downloads. As such, dynsdjs-plugin-doh-dot popularity was classified as not popular.
We found that dynsdjs-plugin-doh-dot demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Research
Security News
A threat actor's playbook for exploiting the npm ecosystem was exposed on the dark web, detailing how to build a blockchain-powered botnet.
Security News
NVD’s backlog surpasses 20,000 CVEs as analysis slows and NIST announces new system updates to address ongoing delays.
Security News
Research
A malicious npm package disguised as a WhatsApp client is exploiting authentication flows with a remote kill switch to exfiltrate data and destroy files.