<?xml version="1.0" encoding="utf-8"?><rss version="2.0"><channel><title>Simple DNS Plus News</title><description>The latest news about Simple DNS Plus</description><link>http://www.simpledns.com/whatsnew.aspx</link><language>en-us</language><copyright>Copyright JH Software ApS</copyright><pubDate>Fri, 09 Jul 2010 14:12:00 GMT</pubDate><lastBuildDate>Fri, 09 Jul 2010 14:12:00 GMT</lastBuildDate><image><url>http://www.jhsoft.com/news/channel.gif</url><title>JH Software</title><link>http://www.jhsoft.com</link></image><item><title>Simple DNS Plus v. 5.2 build 117 released / Problem resolving WebMD.com</title><description>

&lt;p&gt;Simple DNS Plus v. 5.2 build 117 is now available at &lt;a href="http://www.simpledns.com/download.aspx"&gt;http://www.simpledns.com/download.aspx&lt;/a&gt; &lt;br /&gt;
	For more details on the updates and changes in this build, please see &lt;a href="http://www.simpledns.com/relnotes-5-2.aspx"&gt;release notes&lt;/a&gt;.&lt;/p&gt;

&lt;p&gt;Over the last few days, several users have reported not being able to&amp;nbsp;resolve &lt;a href="http://www.webmd.com"&gt;www.webmd.com&lt;/a&gt;.&lt;br /&gt;
	The problem is an erroneous response (details below) from the DNS servers hosting the domain name.&lt;br /&gt;
	We have contacted WebMD.com and their DNS provider (UltraDNS) about this and anticipate that they will fix the problem shortly.&lt;br /&gt;
	However since WebMD.com is a very popular web-site (and UltraDNS is one of the larger DNS providers), we felt it was best to provide a quick workaround with above update to Simple DNS Plus.&lt;br /&gt;
	&lt;br /&gt;
	When we do a lookup for &lt;a href="http://www.webmd.com"&gt;www.webmd.com&lt;/a&gt; against one of the authoritative DNS servers (for example "pdns1.ultradns.net"), we get a response with a CNAME-record (alias) pointing to &lt;a href="http://www.phx1.webmd.com"&gt;www.phx1.webmd.com&lt;/a&gt; and a SOA-record in the authority section:&lt;br /&gt;
	&lt;br /&gt;
	&lt;img border="0" alt="" src="http://www.jhsoft.com/news/images/2424/webmd1.png" /&gt;&lt;br /&gt;
	&lt;br /&gt;
	The standard (RFC) interpretation of this SOA-record is that no records exist for the current name (&lt;a href="http://www.phx1.webmd.com"&gt;www.phx1.webmd.com&lt;/a&gt;) and the requested record type (A) - a so called "NO DATA" response.&lt;br /&gt;
	Therefore previous builds of Simple DNS Plus naturally stopped the resolving process here - no need to do anything more since we know the final answer (no data).&lt;br /&gt;
	&lt;br /&gt;
	However if we do another DNS lookup for &lt;a href="http://www.phx1.webmd.com"&gt;www.phx1.webmd.com&lt;/a&gt; against the same DNS server, we get a surprising response - now all of a sudden there IS an A-record for this name:&lt;br /&gt;
	&lt;br /&gt;
	&lt;img border="0" alt="" src="http://www.jhsoft.com/news/images/2424/webmd2.png" /&gt;&lt;br /&gt;
	&lt;br /&gt;
	This is an error in the configuration or operation of the DNS servers hosting&amp;nbsp;&lt;a href="http://www.webmd.com"&gt;www.webmd.com&lt;/a&gt;, and we obviously recommend that they get this fixed as quickly as possible.&lt;br /&gt;
	&lt;br /&gt;
	In this new build of Simple DNS Plus, we have made an exception for this very specific situation:&lt;br /&gt;
	For responses received containing a CNAME-record in the Answer section, a "NODATA" SOA-record in Authority section is now ignored, and the CNAME alias is attempted resolved in a new outbound request.&lt;br /&gt;
	This immediately makes it possible&amp;nbsp;for Simple DNS Plus to resolve &lt;a href="http://www.webmd.com"&gt;www.webmd.com&lt;/a&gt; and any other domain with the same problem.&lt;br /&gt;
	The trade off is that&amp;nbsp;this will also cause a few more outbound&amp;nbsp;requests in certain situations. These extra requests would normally not be necessary, but it does make Simple DNS Plus more resilient against this type of problem.&lt;/p&gt;</description><pubDate>Fri, 09 Jul 2010 14:12:00 GMT</pubDate><guid isPermaLink="false">jhsoft.com-news-2424</guid><link>http://www.simpledns.com/newsitem.aspx?id=2424</link><comments>http://www.simpledns.com/newsitem.aspx?id=2424#comments</comments><category>Front Page</category><category>JHMAIN</category><category>Simple DNS Plus</category></item><item><title>Windows Server 2008 R2 Active Directory "Bad DNS Packet" error</title><description>There is a bug in Windows Server&amp;nbsp;2008 R2 causing a "Bad DNS Packet" error when you try to setup (or promote) Active Directory using Simple DNS Plus and other non-MS DNS servers.&lt;br /&gt;
&lt;br /&gt;
The problem is described in MS KB 977158 - see &lt;a href="http://support.microsoft.com/kb/977158/EN-US"&gt;http://support.microsoft.com/kb/977158/EN-US&lt;/a&gt;&lt;br /&gt;
&lt;br /&gt;
The solution is to install the mentioned Windows hotfix.&lt;br /&gt;
However the MS KB article only links to the IA64 version of the hotfix - not the X64 version which most people need.&lt;br /&gt;
You can get a copy of the X64 version from &lt;a href="http://www.simpledns.com/outbox/KB977158-x64.zip"&gt;http://www.simpledns.com/outbox/KB977158-x64.zip&lt;/a&gt;&lt;br /&gt;
&lt;br /&gt;
Note that this hotfix will likely be included in a future automatic Windows update and/or a service pack.&lt;br /&gt;
So this temporary solution will only be necessary until then.&lt;br /&gt;
&lt;br /&gt;
For more information on using Simple DNS Plus with Active Directory, see &lt;a href="http://www.simpledns.com/kb.aspx?kbid=1049"&gt;http://www.simpledns.com/kb.aspx?kbid=1049&lt;/a&gt;</description><pubDate>Wed, 23 Dec 2009 20:26:00 GMT</pubDate><guid isPermaLink="false">jhsoft.com-news-2423</guid><link>http://www.simpledns.com/newsitem.aspx?id=2423</link><comments>http://www.simpledns.com/newsitem.aspx?id=2423#comments</comments><category>Simple DNS Plus</category></item><item><title>Expiration of support for Simple DNS Plus v. 4.00</title><description>Note that from January 17th 2010 we will no longer provide support&amp;nbsp;for Simple DNS Plus v. 4.00 (or earlier versions).&lt;br /&gt;
&lt;br /&gt;
As per our &lt;a href="http://www.simpledns.com/kb.aspx?kbid=1223"&gt;Support Life-Cycle Policy&lt;/a&gt;, a Simple DNS Plus version is supported for 3 years after it is first released, and&amp;nbsp;for 2 years after we stop selling&amp;nbsp;it (whichever comes last).&lt;br /&gt;
V. 4.00 was originally released on April 10th 2005, and we stopped selling it on January 17th 2008 when v. 5.0 was released.&lt;br /&gt;
&lt;br /&gt;
We encourage users of v. 4.00 and earlier version to &lt;a href="http://www.simpledns.com/upgrade.aspx"&gt;upgrade&lt;/a&gt; to the current v. 5.2.&lt;br /&gt;
For details on all the new features and other improvements see:&lt;br /&gt;
v. 5.0: &lt;a href="http://www.simpledns.com/kb.aspx?kbid=1215"&gt;http://www.simpledns.com/kb.aspx?kbid=1215&lt;/a&gt;&lt;br /&gt;
v. 5.1: &lt;a href="http://www.simpledns.com/kb.aspx?kbid=1246"&gt;http://www.simpledns.com/kb.aspx?kbid=1246&lt;/a&gt;&lt;br /&gt;
v .5.2: &lt;a href="http://www.simpledns.com/kb.aspx?kbid=1265"&gt;http://www.simpledns.com/kb.aspx?kbid=1265&lt;/a&gt;&lt;br /&gt;
&lt;br /&gt;
</description><pubDate>Thu, 17 Dec 2009 13:16:00 GMT</pubDate><guid isPermaLink="false">jhsoft.com-news-2422</guid><link>http://www.simpledns.com/newsitem.aspx?id=2422</link><comments>http://www.simpledns.com/newsitem.aspx?id=2422#comments</comments><category>JHMAIN</category><category>Simple DNS Plus</category></item><item><title>Simple DNS Plus v. 5.2 build 116 / v. 5.1 build 138 released</title><description>

&lt;p&gt;Simple DNS Plus v. 5.2 build 116 is now available at &lt;a href="http://www.simpledns.com/download.aspx"&gt;http://www.simpledns.com/download.aspx&lt;/a&gt;&lt;br /&gt;
	For details on the updates and changes in this build, please see &lt;a href="http://www.simpledns.com/relnotes-5-2.aspx"&gt;release notes&lt;/a&gt;.&lt;/p&gt;

&lt;p&gt;Simple DNS Plus v. 5.1 build 138 is now available at &lt;a href="http://www.simpledns.com/download-oldver.aspx"&gt;http://www.simpledns.com/download-oldver.aspx&lt;/a&gt;&lt;br /&gt;
	For details on the updates and changes in this build, please see &lt;a href="http://www.simpledns.com/relnotes-5-1.aspx"&gt;release notes&lt;/a&gt;.&lt;br /&gt;
	&lt;br /&gt;
	These are NOT a critical updates. We do recommend that all users update to these builds, but there is no urgency unless you are directly affected by the issues addressed by the updates.&lt;/p&gt;</description><pubDate>Thu, 10 Dec 2009 23:57:00 GMT</pubDate><guid isPermaLink="false">jhsoft.com-news-2421</guid><link>http://www.simpledns.com/newsitem.aspx?id=2421</link><comments>http://www.simpledns.com/newsitem.aspx?id=2421#comments</comments><category>JHMAIN</category><category>Simple DNS Plus</category></item><item><title>Update to the Simple DNS Plus API for .NET and COM</title><description>

&lt;p&gt;We have just released version 1.1 build 4 of the Simple DNS Plus API for .NET and COM.&lt;/p&gt;

&lt;p&gt;Updates in this build:&lt;/p&gt;

&lt;ul&gt;
	
&lt;li&gt;Update: Uses Simple DNS Plus v. 5.2 code base (various optimizations and bug fixes). &lt;/li&gt;
	
&lt;li&gt;Update: Setting Zone.DefaultTTL value now updates TTL value of all records which had the old default TTL value. &lt;/li&gt;
	
&lt;li&gt;Update: Record TTL values now automatically synchronized in RRSet (records with same name / type) when adding new records. &lt;/li&gt;
	
&lt;li&gt;Fixed: Setting DNSZone.AllowZoneTransfer property was not always saved correctly. &lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;Version 1.1 build 4 is now available for download:&lt;br /&gt;
	&lt;a href="http://www.simpledns.com/outbox/sdnsapi-setup.exe"&gt;sdnsapi-setup.exe (720 KB)&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;If you have a previous version/build installed, simply run above installation file to upgrade. &lt;/p&gt;

&lt;p&gt;For more information about the Simple DNS Plus API for .NET and COM, see the on-line documentation at &lt;a href="http://www.simpledns.com/help/api/" target="_blank"&gt;http://www.simpledns.com/help/api/&lt;/a&gt;&lt;/p&gt;</description><pubDate>Fri, 30 Oct 2009 17:39:00 GMT</pubDate><guid isPermaLink="false">jhsoft.com-news-2418</guid><link>http://www.simpledns.com/newsitem.aspx?id=2418</link><comments>http://www.simpledns.com/newsitem.aspx?id=2418#comments</comments><category>JHMAIN</category><category>Simple DNS Plus</category></item><item><title>Freeware DNS Client Library for .NET</title><description>We have just released &lt;em&gt;"JH Software's DNS Client Library for .NET"&lt;/em&gt;.&lt;br /&gt;
&lt;br /&gt;
This&amp;nbsp;can be used to perform simple as well as advanced DNS lookups from any .NET code (.NET v. 2.0 or later).&lt;br /&gt;
&lt;br /&gt;
For details and download see &lt;a href="http://www.simpledns.com/dns-client-lib.aspx"&gt;http://www.simpledns.com/dns-client-lib.aspx&lt;/a&gt;</description><pubDate>Thu, 29 Oct 2009 11:55:00 GMT</pubDate><guid isPermaLink="false">jhsoft.com-news-2416</guid><link>http://www.simpledns.com/newsitem.aspx?id=2416</link><comments>http://www.simpledns.com/newsitem.aspx?id=2416#comments</comments><category>Front Page</category><category>JHMAIN</category><category>Simple DNS Plus</category></item><item><title>SPF checking HELO/EHLO host names</title><description>It has come to our attention that more e-mail servers are now&amp;nbsp;performing SPF checks on the SMTP session HELO/EHLO greeting host name (in addition to checking the domain name part of the sender's e-mail address).&lt;br /&gt;
&lt;br /&gt;
Therefore always make sure that your e-mail server is configured to use a correct host name (like "mail.example.com") in the HELO/EHLO greeting, and that an A- and/or AAAA-record exists for this host name in DNS.&lt;br /&gt;
&lt;br /&gt;
Also, when using the&amp;nbsp;"Automatic SPF" feature in Simple DNS Plus, make sure that the automatic SPF-record data is also valid for the HELO/EHLO host name, or define a specific SPF-record for the HELO/EHLO name in the zone where this belongs (this will override the automatic SPF record).&lt;br /&gt;
&lt;br /&gt;
Note that the default automatic SPF record data "v=spf1 mx -all" will fail such a test if no MX-record exists for your HELO/EHLO name.&lt;br /&gt;
For example, if your domain name is "example.com" and your mail server is named "mail.example.com" (and uses this in HELO/EHLO greetings), you would probably only have an MX-record for "example.com" - not for "mail.example.com", and therefore "v=spf1 mx -all"&amp;nbsp;fails to validate "mail.example.com".&lt;br /&gt;
Instead you could use "v=spf1 ip4:1.2.3.4 -all" (where 1.2.3.4 is the IP address of your mail server), which would work for both types of tests.&lt;br /&gt;
&lt;br /&gt;
For more information about SPF in Simple DNS Plus, see &lt;a href="http://www.simpledns.com/kb.aspx?kbid=1148"&gt;KB1148&lt;/a&gt;.</description><pubDate>Fri, 16 Oct 2009 12:30:00 GMT</pubDate><guid isPermaLink="false">jhsoft.com-news-2415</guid><link>http://www.simpledns.com/newsitem.aspx?id=2415</link><comments>http://www.simpledns.com/newsitem.aspx?id=2415#comments</comments><category>Front Page</category><category>JHMAIN</category><category>Simple DNS Plus</category></item><item><title>New "Clone Response" plug-in</title><description>
&lt;p&gt;This new plug-in provides DNS responses by cloning the DNS records from responses to requests for another specified domain name.&lt;br /&gt;
	
	This is an easy way to host many domain names that have the exact same records (except for their zone names).&lt;br /&gt;
	
	&lt;br /&gt;
	
	For more details see &lt;a href="http://www.simpledns.com/kb.aspx?kbid=1289"&gt;KB1289&lt;/a&gt;.&lt;/p&gt;


&lt;p&gt;Download &lt;a href="http://www.simpledns.com/outbox/plugins/v52/cloneresponse-plugin.zip"&gt;cloneresponse-plugin.zip (9 KB)&lt;/a&gt; and un-zip it to the "plugins" sub-directory under the directory where Simple DNS Plus is installed. After this the plug-in will be available in the Simple DNS Plus Options dialog / Plug-Ins section.&lt;/p&gt;


&lt;p&gt;Note that this plug-in requires an "unlimted zones" license and works with Simple DNS Plus v. 5.2 &lt;strong&gt;build 111&lt;/strong&gt;&amp;nbsp;and later only.&lt;/p&gt; </description><pubDate>Thu, 20 Aug 2009 14:06:00 GMT</pubDate><guid isPermaLink="false">jhsoft.com-news-2414</guid><link>http://www.simpledns.com/newsitem.aspx?id=2414</link><comments>http://www.simpledns.com/newsitem.aspx?id=2414#comments</comments><category>Front Page</category><category>JHMAIN</category><category>Simple DNS Plus</category></item><item><title>New "TCP Port Forwarder" plug-in</title><description>
&lt;p&gt;This new plug-in provides simple TCP port forwarding.&lt;br /&gt;
	
	&amp;nbsp;&lt;br /&gt;
	
	If the Simple DNS Plus computer is connected to both the Internet and to a private network (LAN), this can be used to forward connections from the Internet to a computer on the LAN. For example mapping remote desktop connections (port 3389).&lt;br /&gt;
	
	&lt;br /&gt;
	
	For more details see &lt;a href="http://www.simpledns.com/kb.aspx?kbid=1288"&gt;KB1288&lt;/a&gt;.&lt;/p&gt;


&lt;p&gt;Download &lt;a href="http://www.simpledns.com/outbox/plugins/v52/tcpforward-plugin.zip"&gt;tcpforward-plugin.zip (18 KB)&lt;/a&gt; and un-zip it to the "plugins" sub-directory under the directory where Simple DNS Plus is installed. After this the plug-in will be available in the Simple DNS Plus Options dialog / Plug-Ins section.&lt;/p&gt;


&lt;p&gt;Note that this plug-in works with Simple DNS Plus v. 5.2 and later only.&lt;/p&gt; </description><pubDate>Tue, 18 Aug 2009 11:47:00 GMT</pubDate><guid isPermaLink="false">jhsoft.com-news-2412</guid><link>http://www.simpledns.com/newsitem.aspx?id=2412</link><comments>http://www.simpledns.com/newsitem.aspx?id=2412#comments</comments><category>Front Page</category><category>JHMAIN</category><category>Simple DNS Plus</category></item><item><title>Updated "Remote DNS Look Up" function</title><description>Our on-line &lt;a href="http://www.simpledns.com/lookup.aspx"&gt;Remote DNS Look Up&lt;/a&gt; function has been updated to much closer match the features of the&amp;nbsp;GUI based DNS Look Up tool that comes with Simple DNS Plus.&lt;br /&gt;
&lt;br /&gt;
It now supports a long list of additional record types, it supports EDNS0 options including payload size and DNSSEC, and it supports displaying native characters in IDNs in the repose output.&lt;br /&gt;
&lt;br /&gt;
The output is formatted the same way as in the GUI tool - in fact the on-line and GUI tools now shared much of their program code (both .NET based).&lt;br /&gt;
&lt;br /&gt;
And finally the on-line function is now AJAX based for a smoother experience.</description><pubDate>Sun, 05 Jul 2009 15:18:00 GMT</pubDate><guid isPermaLink="false">jhsoft.com-news-2407</guid><link>http://www.simpledns.com/newsitem.aspx?id=2407</link><comments>http://www.simpledns.com/newsitem.aspx?id=2407#comments</comments><category>JHMAIN</category><category>Simple DNS Plus</category></item><item><title>GeoDNS plug-in for Simple DNS Plus</title><description>

&lt;p&gt;This new plug-in provides a different DNS response depending on what country a DNS request originates from. This can be used to direct Internet traffic (web, FTP, streaming media, etc.) to a server geographically closer to the end-user, or with contents specific for a geographical area.&lt;br /&gt;
	&lt;br /&gt;
	This is exactly the&amp;nbsp;same that large web-sites such as Google.com and CNN.com do, and what companies like Akamai charge a lot of money to provide.&lt;br /&gt;
	Now this functionality is available as a free plug-in&amp;nbsp;for Simple DNS Plus.&lt;br /&gt;
	&lt;br /&gt;
	For more&amp;nbsp;details see &lt;a href="http://www.simpledns.com/kb.aspx?kbid=1284"&gt;KB1284&lt;/a&gt;.&lt;/p&gt;

&lt;p&gt;Download &lt;a href="http://www.simpledns.com/outbox/plugins/v52/geodns-plugin.zip"&gt;geodns-plugin.zip (31 KB)&lt;/a&gt;&amp;nbsp;and un-zip it to the "plugins" sub-directory under the directory where Simple DNS Plus is installed. After this the plug-in&amp;nbsp;will be available in the Simple DNS Plus Options dialog / Plug-Ins section.&lt;/p&gt;

&lt;p&gt;Note that this plug-in works with Simple DNS Plus v. 5.2 and later only.&lt;br /&gt;
	&lt;/p&gt;</description><pubDate>Mon, 22 Jun 2009 08:30:00 GMT</pubDate><guid isPermaLink="false">jhsoft.com-news-2405</guid><link>http://www.simpledns.com/newsitem.aspx?id=2405</link><comments>http://www.simpledns.com/newsitem.aspx?id=2405#comments</comments><category>Front Page</category><category>JHMAIN</category><category>Simple DNS Plus</category></item><item><title>Simple DNS Plus v. 5.2.105 / 5.1.136 / 5.0.125 released</title><description>&lt;p&gt;Simple DNS Plus v. 5.2 build 105 is now available at &lt;a href="http://www.simpledns.com/download.aspx"&gt;http://www.simpledns.com/download.aspx&lt;/a&gt;&lt;br&gt;For details on the updates and changes in this build, please see &lt;a href="http://www.simpledns.com/relnotes-5-2.aspx"&gt;release notes&lt;/a&gt;.&lt;/p&gt;

&lt;p&gt;Simple DNS Plus v. 5.1 build 136 is now available at &lt;a href="http://www.simpledns.com/download-oldver.aspx"&gt;http://www.simpledns.com/download-oldver.aspx&lt;/a&gt;&lt;br&gt;For details on the updates and changes in this build, please see &lt;a href="http://www.simpledns.com/relnotes-5-1.aspx"&gt;release notes&lt;/a&gt;.&lt;/p&gt;

&lt;p&gt;Simple DNS Plus v. 5.0 build 125 is now available at &lt;a href="http://www.simpledns.com/download-oldver.aspx"&gt;http://www.simpledns.com/download-oldver.aspx&lt;/a&gt;&lt;br&gt;For details on the updates and changes in this build, please see &lt;a href="http://www.simpledns.com/relnotes-5-0.aspx"&gt;release notes&lt;/a&gt;.&lt;/p&gt;


&lt;p&gt;These are NOT a critical updates. We do recommend that all users update to these builds, but there is no urgency unless you are directly affected by the issues addressed by the updates.&lt;/p&gt;</description><pubDate>Thu, 21 May 2009 10:56:00 GMT</pubDate><guid isPermaLink="false">jhsoft.com-news-2403</guid><link>http://www.simpledns.com/newsitem.aspx?id=2403</link><comments>http://www.simpledns.com/newsitem.aspx?id=2403#comments</comments><category>JHMAIN</category><category>Simple DNS Plus</category></item><item><title>DNS Blacklist Editor v. 1.0 build 4 released</title><description>When compiling lists for the Simple DNS Plus &lt;a href="http://www.simpledns.com/kb.aspx?kbid=1241"&gt;DNSBL plug-in&lt;/a&gt;, a bug related to exclusions 
caused some IP address ranges to be listed which should not be. &lt;br&gt;&lt;br&gt;The new build of the editor is now available from &lt;a href="http://www.simpledns.com/dnsbl-editor.aspx"&gt;http://www.simpledns.com/dnsbl-editor.aspx&lt;/a&gt; &lt;br&gt;This build is now also included with the DNSBL plug-in download.&lt;br&gt;&lt;br&gt;</description><pubDate>Mon, 18 May 2009 11:16:00 GMT</pubDate><guid isPermaLink="false">jhsoft.com-news-2402</guid><link>http://www.simpledns.com/newsitem.aspx?id=2402</link><comments>http://www.simpledns.com/newsitem.aspx?id=2402#comments</comments><category>JHMAIN</category><category>Simple DNS Plus</category></item><item><title>Simple DNS Plus logs in W3C Extended format</title><description>A new command line tool which converts Simple DNS Plus raw request log
files (.sdraw files) into the standard W3C Extended log file format (as
typically produced by IIS, Apache, and other web-servers) is now
available.&lt;br&gt;&lt;br&gt;Note that DNS request (and the .sdraw log files) do not contain HTTP header information such as referrers, browser info, full URLs, etc. So while you can process the resulting W3C log files with various web-log analyzer programs, this does not replace web-logs.&lt;br&gt;Rather it provides a different perspective on traffic data.&lt;br&gt;Data columns shared with web-server logs are "date", "time", "c-ip" and "cs-host". Additional "x-" columns contain more details about individual DNS requests. &lt;br&gt;

&lt;br&gt;&lt;a href="http://www.simpledns.com/outbox/sdraw-w3c.zip"&gt;Click here to download "sdraw-w3c.zip" (35 KB)&lt;/a&gt;&lt;br&gt;&lt;br&gt;The zip file above contains both the compiled "sdraw-w3c.exe" file as well as the C# source code (VS2008).&lt;br&gt;
This is a very small and simple program so if you want to add some type of
filtering (only output some requests) or build on this functionality,
it is easy to do so.&lt;br&gt;

&lt;br&gt;The command line syntax is:&lt;br&gt;

&lt;code&gt;sdraw-w3c.exe &amp;lt;log-date&amp;gt; &amp;lt;raw-log-file&amp;gt; &amp;lt;w3c-log-file&amp;gt;&lt;/code&gt;&lt;br&gt;
&lt;br&gt;Raw request log files are enabled in the Simple DNS Plus Options dialog / Logging / Log Files section.&lt;br&gt;

&lt;br&gt;Thanks to "Fulgan" for &lt;a href="http://www.simpledns.com/forums.aspx?g=posts&amp;amp;t=174"&gt;suggesting this in our community forum&lt;/a&gt;.&lt;br&gt;</description><pubDate>Mon, 04 May 2009 13:49:00 GMT</pubDate><guid isPermaLink="false">jhsoft.com-news-2399</guid><link>http://www.simpledns.com/newsitem.aspx?id=2399</link><comments>http://www.simpledns.com/newsitem.aspx?id=2399#comments</comments><category>JHMAIN</category><category>Simple DNS Plus</category></item><item><title>Simple DNS Plus v. 5.2 released</title><description>Some of the new features in Simple DNS Plus v. 5.2 are:&lt;br&gt;&lt;br&gt;- Remote Management&lt;br&gt;- Runs on Windows "Server Core"&lt;br&gt;- DNSSEC&lt;br&gt;- Secure Zone Transfers&lt;br&gt;- Check Internet Delegations wizard &lt;br&gt;- Windows Performance Counters&lt;br&gt;- And much more...&lt;br&gt;&lt;br&gt;See all the details at &lt;a href="http://www.simpledns.com/kb.aspx?kbid=1265"&gt;http://www.simpledns.com/kb.aspx?kbid=1265&lt;/a&gt;&lt;br&gt;&lt;br&gt;IMPORTANT: Version 5.2 may or may not be a free upgrade depending on when you purchased your license or last purchased an upgrade.&lt;br&gt;If you purchased your license or your 
last upgrade on or after April 23rd 2008, then the upgrade to v. 5.2 is free.&lt;br&gt;Otherwise you will need to purchase 
an upgrade - see &lt;a href="http://www.simpledns.com/upgrade.aspx"&gt;http://www.simpledns.com/upgrade.aspx&lt;/a&gt; &lt;br&gt;&lt;br&gt;V. 5.2 is now available for download at &lt;a href="http://www.simpledns.com/download.aspx"&gt;http://www.simpledns.com/download.aspx&lt;/a&gt;&lt;br&gt;Please read the important upgrade instructions on the same page.&lt;br&gt;&lt;br&gt;&lt;br&gt;</description><pubDate>Thu, 23 Apr 2009 13:18:00 GMT</pubDate><guid isPermaLink="false">jhsoft.com-news-2396</guid><link>http://www.simpledns.com/newsitem.aspx?id=2396</link><comments>http://www.simpledns.com/newsitem.aspx?id=2396#comments</comments><category>Front Page</category><category>JHMAIN</category><category>SDNSBETA</category><category>Simple DNS Plus</category></item><item><title>Simple DNS Plus v. 5.1 build 135 released</title><description>&lt;p&gt;Simple DNS Plus v. 5.1 build 135 is now available at &lt;a href="http://www.simpledns.com/download.aspx"&gt;http://www.simpledns.com/download.aspx&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;For details on the updates and changes in this build, please see &lt;a href="http://www.simpledns.com/relnotes-5-1.aspx"&gt;release notes&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;This is NOT a critical update. We do recommend that all users update to this build, but there is no urgency unless you are directly affected by the issues addressed by this update.&lt;/p&gt;</description><pubDate>Wed, 22 Apr 2009 09:57:00 GMT</pubDate><guid isPermaLink="false">jhsoft.com-news-2395</guid><link>http://www.simpledns.com/newsitem.aspx?id=2395</link><comments>http://www.simpledns.com/newsitem.aspx?id=2395#comments</comments><category>JHMAIN</category><category>Simple DNS Plus</category></item><item><title>Secure zone transfers in Simple DNS Plus v. 5.2</title><description>&lt;P&gt;The upcoming Simple DNS Plus v. 5.2 supports secure zone transfer (TSIG authenticated).&lt;BR&gt;Both zone transfer requests and responses are authenticated, so this provides protection in two ways;&amp;nbsp;it prevents unauthorized transfers (only&amp;nbsp;people / servers with the correct key can transfer), and&amp;nbsp;it ensures data integrity on secondary servers (not possible to spoof / inject false data during transfers).&lt;/P&gt;
&lt;P&gt;In the Zone Properties dialog, you can now specify the TSIG key(s) which are allowed to transfer the zone:&lt;/P&gt;
&lt;P&gt;&lt;IMG height=467 alt=Image1.png src="http://www.jhsoft.com/news/images/2387/Image1.png" width=426 border=0&gt;&lt;/P&gt;
&lt;P&gt;For each key, you specify a key name, signing algorithm, and a secret:&lt;/P&gt;
&lt;P&gt;&lt;IMG height=290 alt=Image2.png src="http://www.jhsoft.com/news/images/2387/Image2.png" width=450 border=0&gt;&lt;/P&gt;
&lt;P&gt;For secondary zones, you can now specify the key to sign zone transfer requests with:&lt;/P&gt;
&lt;P&gt;&lt;IMG height=467 alt=Image3.png src="http://www.jhsoft.com/news/images/2387/Image3.png" width=426 border=0&gt;&lt;/P&gt;
&lt;P&gt;In the Options dialog / DNS / Local Zones / Zone Transfers section, it is now also possible to specify keys which are allowed to transfer all zones:&lt;/P&gt;
&lt;P&gt;&lt;IMG height=425 alt=Image4.png src="http://www.jhsoft.com/news/images/2387/Image4.png" width=651 border=0&gt;&lt;/P&gt;
&lt;P&gt;And in the Options dialog / DNS / Local Zones / Super Master/Slave section, it is now possible to allow / disallow un-signed zone transfer requests from slave server - and to specify keys for master servers:&lt;/P&gt;
&lt;P&gt;&lt;IMG height=425 alt=Image5.png src="http://www.jhsoft.com/news/images/2387/Image5.png" width=651 border=0&gt;&lt;/P&gt;
&lt;P&gt;Adding / editing a master server:&lt;/P&gt;
&lt;P&gt;&lt;IMG height=266 alt=Image6.png src="http://www.jhsoft.com/news/images/2387/Image6.png" width=439 border=0&gt; &lt;/P&gt;
&lt;P&gt;This new feature is available in Simple DNS Plus v. 5.2 BETA build 25 and later - now available at &lt;A href="http://www.simpledns.com/beta.aspx"&gt;http://www.simpledns.com/beta.aspx&lt;/A&gt; &lt;/P&gt;
&lt;P&gt;For other updates in this BETA&amp;nbsp;build, please see the &lt;A href="http://www.simpledns.com/beta-relnotes.aspx"&gt;beta release notes&lt;/A&gt;&lt;/P&gt;</description><pubDate>Tue, 17 Mar 2009 20:38:00 GMT</pubDate><guid isPermaLink="false">jhsoft.com-news-2387</guid><link>http://www.simpledns.com/newsitem.aspx?id=2387</link><comments>http://www.simpledns.com/newsitem.aspx?id=2387#comments</comments><category>JHMAIN</category><category>SDNSBETA</category><category>Simple DNS Plus</category></item><item><title>New build of the Simple DNS Plus API for .NET and COM</title><description>&lt;P&gt;The Simple DNS Plus API for .NET and COM version 1.1 build 3 is now available for download from &lt;A href="http://www.simpledns.com/addons.aspx"&gt;http://www.simpledns.com/addons.aspx&lt;/A&gt; &lt;/P&gt;
&lt;P&gt;The purpose of this&amp;nbsp;build is to fix some .NET compatibility issues on computers with .NET Framework 3.5 installed.&lt;BR&gt;This build does not contain any changes to the API functions.&lt;/P&gt;</description><pubDate>Wed, 04 Mar 2009 12:45:00 GMT</pubDate><guid isPermaLink="false">jhsoft.com-news-2381</guid><link>http://www.simpledns.com/newsitem.aspx?id=2381</link><comments>http://www.simpledns.com/newsitem.aspx?id=2381#comments</comments><category>JHMAIN</category><category>Simple DNS Plus</category></item><item><title>Simple DNS Plus on Windows "Server Core"</title><description>&lt;P&gt;The upcoming Simple DNS Plus v. 5.2&amp;nbsp;also runs on Windows "Server Core".&lt;BR&gt;For details see &lt;A href="http://www.simpledns.com/kb.aspx?kbid=1278"&gt;KB1278&lt;/A&gt;.&lt;/P&gt;
&lt;P&gt;To download the current beta&amp;nbsp;and for more information about beta testing see &lt;A href="http://www.simpledns.com/beta.aspx"&gt;http://www.simpledns.com/beta.aspx&lt;/A&gt; &lt;/P&gt;</description><pubDate>Tue, 17 Feb 2009 18:12:00 GMT</pubDate><guid isPermaLink="false">jhsoft.com-news-2373</guid><link>http://www.simpledns.com/newsitem.aspx?id=2373</link><comments>http://www.simpledns.com/newsitem.aspx?id=2373#comments</comments><category>Front Page</category><category>JHMAIN</category><category>SDNSBETA</category><category>Simple DNS Plus</category></item><item><title>Remote manage Simple DNS Plus</title><description>&lt;p&gt;The upcoming Simple DNS Plus v. 5.2&amp;nbsp;supports remote management, so that you can use the normal Simple DNS Plus user interface on a remote computer. This is much faster and uses much less bandwidth compared to&amp;nbsp;accessing a remote server via Remote Desktop, VNC, or similar.&lt;br&gt;Traffic between the server and the remote GUI is&amp;nbsp;highly optimized and secure.&amp;nbsp;Authentication uses&amp;nbsp;SHA-1 challenge/response to prevent password sniffing,&amp;nbsp;all data transferred is encrypted, and larger data chunks (such as zone files)&amp;nbsp;are compressed.&lt;/p&gt;
&lt;p&gt;A new "Remote Management" section has been added to the Options dialog where you can enable/disable remote management, and specify IP address, port, and password:&lt;/p&gt;
&lt;p&gt;&lt;img alt="Image1.png" src="http://www.jhsoft.com/news/images/2372/Image1.png" border="0" width="513" height="340"&gt;&lt;/p&gt;
&lt;p&gt;A new "Remote Management" shortcut is added to the Windows Start menu - used to manage remote servers:&lt;/p&gt;
&lt;p&gt;&lt;img alt="Image2.png" src="http://www.jhsoft.com/news/images/2372/Image2.png" border="0" width="329" height="292"&gt;&lt;/p&gt;
&lt;p&gt;- which opens a "Connect to..." dialog:&lt;/p&gt;
&lt;p&gt;&lt;img src="http://www.jhsoft.com/news/images/2372/rc27.png" alt="rc27.png" border="0" width="392" height="234"&gt;&lt;br&gt;&lt;/p&gt;
&lt;p&gt;It is&amp;nbsp;possible to create desktop shortcuts pre-filled with the remote computer and password - &lt;a href="http://www.simpledns.com/kb.aspx?kbid=1275"&gt;details&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;When connected to a remote Simple DNS Plus server, the window title (main&amp;nbsp;and "DNS Records" windows) will indicate that this is a remote session:&lt;/p&gt;
&lt;p&gt;&lt;img alt="Image4.png" src="http://www.jhsoft.com/news/images/2372/Image4.png" border="0" width="284" height="99"&gt;&lt;/p&gt;
&lt;p&gt;During program installation (custom)&amp;nbsp;it is&amp;nbsp;now possible to exclude the service module (Core Service) for installations on remote desktops:&lt;/p&gt;
&lt;p&gt;&lt;img alt="Image5.png" src="http://www.jhsoft.com/news/images/2372/Image5.png" border="0" width="499" height="386"&gt;&lt;/p&gt;
&lt;p&gt;The remote management feature is available in Simple DNS Plus v. 5.2 BETA build 10 and later.&lt;br&gt;To download and for more information about beta testing see &lt;a href="http://www.simpledns.com/beta.aspx"&gt;http://www.simpledns.com/beta.aspx&lt;/a&gt; &lt;/p&gt;
&lt;p&gt;For other updates in v. 5.2 BETA build 10, please see the&amp;nbsp;&lt;a href="http://www.simpledns.com/beta-relnotes.aspx"&gt;BETA release notes&lt;/a&gt;.&lt;/p&gt;</description><pubDate>Sun, 15 Feb 2009 18:07:00 GMT</pubDate><guid isPermaLink="false">jhsoft.com-news-2372</guid><link>http://www.simpledns.com/newsitem.aspx?id=2372</link><comments>http://www.simpledns.com/newsitem.aspx?id=2372#comments</comments><category>SDNSBETA</category><category>Simple DNS Plus</category></item><item><title>DNSSEC signed .gov</title><description>&lt;P&gt;Today the .gov&amp;nbsp;top level domain (U.S. government) was DNSSEC signed.&lt;BR&gt;As per &lt;A href="http://www.whitehouse.gov/omb/memoranda/fy2008/m08-23.pdf" target=_blank&gt;OMB Memo 08-23&lt;/A&gt;, all U.S.&amp;nbsp;government agencies must&amp;nbsp;DNSSEC sign their DNS zones (ending with&amp;nbsp;.gov) before the end of 2009.&lt;/P&gt;
&lt;P&gt;Federal agencies using Simple DNS Plus will be able to DNSSEC sign their zones in the upcoming Simple DNS Plus v. 5.2 (beta version &lt;A href="http://www.simpledns.com/beta.aspx"&gt;available now&lt;/A&gt;). For details see:&lt;BR&gt;- &lt;A href="http://www.simpledns.com/kb.aspx?kbid=1273"&gt;How to DNSSEC sign a zone with Simple DNS Plus&lt;/A&gt;&lt;BR&gt;- &lt;A href="http://www.simpledns.com/kb.aspx?kbid=1274"&gt;Managing DNSSEC keys with Simple DNS Plus&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;Using the DNS Look Up tool in Simple DNS Plus 5.2, we can&amp;nbsp;see that the ".gov" zone was indeed signed on February 5th 2009 at 12:01:02 PM (UTC):&lt;/P&gt;
&lt;P&gt;&lt;IMG height=460 alt=Image1.png src="http://www.jhsoft.com/news/images/2370/Image1.png" width=592 border=0&gt;&lt;/P&gt;
&lt;P&gt;And using the Check DNSSEC Signatures tool (&lt;A href="http://www.simpledns.com/kb.aspx?kbid=1272"&gt;free download&lt;/A&gt;), we can verify that the .gov&amp;nbsp;zone's records are signed correctly:&lt;/P&gt;
&lt;P&gt;&lt;IMG height=547 alt=Image2.png src="http://www.jhsoft.com/news/images/2370/Image2.png" width=531 border=0&gt;&lt;/P&gt;</description><pubDate>Thu, 05 Feb 2009 13:28:00 GMT</pubDate><guid isPermaLink="false">jhsoft.com-news-2370</guid><link>http://www.simpledns.com/newsitem.aspx?id=2370</link><comments>http://www.simpledns.com/newsitem.aspx?id=2370#comments</comments><category>Front Page</category><category>JHMAIN</category><category>Simple DNS Plus</category></item><item><title>Option in Simple DNS Plus to ignore root requests</title><description>&lt;P&gt;Because of continued reports about&amp;nbsp;DNS amplification&amp;nbsp;/ DDoS attacks (DNS requests for NS-records for &amp;lt;root&amp;gt; from spoofed IP addresses), we have&amp;nbsp;added a new option in Simple DNS Plus to make it easy to deal with these requests and keep them out of the log.&lt;/P&gt;
&lt;P&gt;In the Simple DNS Plus Options dialog / DNS / Miscellanuous section, there is now a new "Ignore all DNS requests for &amp;lt;root&amp;gt;" option:&lt;/P&gt;
&lt;P&gt;&lt;IMG height=424 alt=Image1.png src="http://www.jhsoft.com/news/images/2368/Image1.png" width=641 border=0&gt;&lt;/P&gt;
&lt;P&gt;And the statistics (available through the HTTP API) has a new counter for this:&lt;/P&gt;
&lt;P&gt;&lt;IMG height=327 alt=Image2.png src="http://www.jhsoft.com/news/images/2368/Image2.png" width=359 border=0&gt;&lt;/P&gt;
&lt;P&gt;This new option is in Simple DNS Plus v. 5.1 build 128&amp;nbsp;now available at &lt;A href="http://www.simpledns.com/download.aspx"&gt;&lt;FONT color=#800080&gt;http://www.simpledns.com/download.aspx&lt;/FONT&gt;&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;Please note that this&amp;nbsp;only works against a&amp;nbsp;very specific type of attack - which has been rampant for the last two weeks or so. It may&amp;nbsp;become useless very quickly if the&amp;nbsp;attackers change their tatics, but at least it should help right now.&lt;/P&gt;
&lt;P&gt;IMPORTANT: When registering new domain names, some registrars require that your DNS server responds with a correct list of DNS root servers as part of their tests, so you may need to temporarily switch this option off when doing this.&lt;/P&gt;</description><pubDate>Sat, 31 Jan 2009 13:48:00 GMT</pubDate><guid isPermaLink="false">jhsoft.com-news-2368</guid><link>http://www.simpledns.com/newsitem.aspx?id=2368</link><comments>http://www.simpledns.com/newsitem.aspx?id=2368#comments</comments><category>Front Page</category><category>JHMAIN</category><category>Simple DNS Plus</category></item><item><title>DNSSEC in Simple DNS Plus v. 5.2</title><description>&lt;P&gt;The upcoming Simple DNS Plus v. 5.2 supports hosting DNSSEC signed zones and has built-in functions for managing DNSSEC keys and for signing zones - all in a user friendly GUI of course.&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;What is DNSSEC?&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;Similar to digital signatures for e-mails, DNSSEC authenticates that a set of DNS records originate from an authorized sender (DNS server) using private/public key cryptography.&lt;BR&gt;The main purpose of this is to protect DNS against falsified information (a.k.a. DNS spoofing).&lt;BR&gt;DNSSEC does NOT encrypt or hide anything - all data is still in "clear text". Its only purpose is verification of data authenticity.&lt;BR&gt;Learn more at &lt;A href="http://www.dnssec.net/" target=_blank&gt;http://www.dnssec.net/&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Why now?&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;DNSSEC has been under way for more than a decade, and has been the subject of many changes and much controversy over the years. We have resisted implementing it in Simple DNS Plus until now for a number of reasons, but decided that it is finally time because:&lt;BR&gt;1) Increased user demand - no doubt due to the &lt;A href="http://www.simpledns.com/kb.aspx?kbid=1251"&gt;Kaminsky bug&lt;/A&gt; with media coverage pointing mainly to DNSSEC as the long term solution. &lt;BR&gt;2) DNSSEC protocol standards are finally in place and appear stable (RFC4033/4/5 and 5155).&lt;BR&gt;3) The U.S. government recently mandated that all federal agencies must implement DNSSEC by the end of 2009 (&lt;A href="http://www.whitehouse.gov/omb/memoranda/fy2008/m08-23.pdf" target=_blank&gt;OMB Memo 08-23&lt;/A&gt;). &lt;BR&gt;4) Several countries have DNSSEC signed their TLDs including Brazil (.br), Bulgaria (.bg), Czech Republic (.cz), Puerto Rico (.pr) and Sweden (.se). &lt;A href="http://www.xelerance.com/dnssec/" target=_blank&gt;World DNSSEC deployment map&lt;/A&gt;&lt;BR&gt;5) Efforts to "sign the root" seem to be &lt;A href="http://www.ntia.doc.gov/dns/dnssec.html" target=_blank&gt;gaining some momentum&lt;/A&gt;.&lt;BR&gt;6) Microsoft has &lt;A href="http://blogs.technet.com/sseshad/archive/2008/11/11/dnssec-on-windows-7-dns-client.aspx" target=_blank&gt;announced&lt;/A&gt; that "Windows 7" will support DNSSEC, meaning that DNSSEC will be broadly available on client systems in a not so distant future.&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Can DNSSEC be used today?&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;A significant obstacle for DNSSEC is that the Internet DNS root is not signed yet. This is stuck in international politics (has been for years), because this is ultimately about who gets to hold the "master key" to the entire Internet.&lt;BR&gt;Until this happens, clients need to maintain a list of "trust anchors" for domains they want to verify.&lt;BR&gt;But yes, DNSSEC can be used today within organizations (local "trust anchors") and for domains under the signed country TLDs mentioned above.&lt;BR&gt;Practical uses are however still few because of limited client software support. Of course "Windows 7" may change this.&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Who issues DNSSEC "certificates"? &lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;You do!&lt;BR&gt;While based on the same cryptography standards as SSL and e-mail signatures (RSA / DSA / SHA1), there is no 3rd party certification authorities involved with DNSSEC.&lt;BR&gt;A new function in Simple DNS Plus v. 5.2 lets you create your own private/public key sets and sign your zones with these.&lt;BR&gt;In order to establish a "link of trust" so that other Internet users can verify your keys and signatures, you create a delegation signature record (DS) which needs to be included and "counter signed" in the parent zone. For example if your domain name is "example.se", this DS-record needs to be added to the ".se" zone. The exact procedure for "uploading" this DS-record depends on your parent zone / TLD operator, and/or your domain name registrar.&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;What will DNSSEC look like in my DNS zones?&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;DNSSEC signing a zone adds the following records to the zone (may increase zone size by 4-5 times):&lt;BR&gt;- DNSKEY-records: public keys.&lt;BR&gt;- RRSIG-records: record set signatures.&lt;BR&gt;- NSEC/NSEC3/NSEC3PARAM-records: denial-of-existence "fillers" for non-existing record names/types.&lt;BR&gt;- DS-records: delegation signatures for secure sub-delegations.&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Availability&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;The new DNSSEC functionality is part of the upcoming Simple DNS Plus v. 5.2.&lt;BR&gt;For more information about Simple DNS Plus v. 5.2 and to&amp;nbsp;download&amp;nbsp;the current beta version, click &lt;A href="http://www.simpledns.com/beta.aspx"&gt;here&lt;/A&gt;.&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;See also&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;- &lt;A href="http://www.simpledns.com/kb.aspx?kbid=1273"&gt;How to DNSSEC sign a zone with Simple DNS Plus&lt;/A&gt;&lt;BR&gt;- &lt;A href="http://www.simpledns.com/kb.aspx?kbid=1274"&gt;Managing DNSSEC keys with Simple DNS Plus&lt;/A&gt;&lt;BR&gt;- &lt;A href="http://www.simpledns.com/kb.aspx?kbid=1272"&gt;Check DNSSEC Signatures tool&lt;/A&gt;&lt;BR&gt;&lt;/P&gt;</description><pubDate>Sun, 25 Jan 2009 19:36:00 GMT</pubDate><guid isPermaLink="false">jhsoft.com-news-2364</guid><link>http://www.simpledns.com/newsitem.aspx?id=2364</link><comments>http://www.simpledns.com/newsitem.aspx?id=2364#comments</comments><category>Front Page</category><category>JHMAIN</category><category>SDNSBETA</category><category>Simple DNS Plus</category></item><item><title>Root query DNS amplification / DDoS attack</title><description>&lt;DIV style="BORDER-RIGHT: black 1px solid; PADDING-RIGHT: 5px; BORDER-TOP: black 1px solid; PADDING-LEFT: 5px; PADDING-BOTTOM: 5px; BORDER-LEFT: black 1px solid; PADDING-TOP: 5px; BORDER-BOTTOM: black 1px solid; BACKGROUND-COLOR: #ffff80"&gt;Added January 31th 2009:&lt;BR&gt;We have just added a new option in Simple DNS Plus to ignore root requests (and not log them) - &lt;A href="http://www.simpledns.com/newsitem.aspx?id=2368"&gt;click here for details&lt;/A&gt;.&lt;BR&gt;Hopefully this will make it&amp;nbsp;easier to deal with this attack. &lt;/DIV&gt;&lt;BR&gt;&lt;BR&gt;
&lt;DIV style="BORDER-RIGHT: black 1px solid; PADDING-RIGHT: 5px; BORDER-TOP: black 1px solid; PADDING-LEFT: 5px; PADDING-BOTTOM: 5px; BORDER-LEFT: black 1px solid; PADDING-TOP: 5px; BORDER-BOTTOM: black 1px solid; BACKGROUND-COLOR: #ffff80"&gt;Added January 30th 2009: &lt;BR&gt;We do &lt;STRONG&gt;&lt;U&gt;NOT&lt;/U&gt;&lt;/STRONG&gt; recommend blocking the sender's IP address on your firewall, with IPSec, or anything else at the IP address level - that is exactly what the attacker wants you to do (we are seeing an alarming number of suggestion on how to do that).&lt;BR&gt;By blocking the apparent sender IP addresses, you are really blocking the victim rather than the attacker - because the sender IP address is spoofed as the victim's. &lt;BR&gt;The aim of the attack is twofold: (1) overload the victim's Internet connection with large DNS responses , and (2) make everybody firewall the victim, so he can't use his connection even after the attack. &lt;BR&gt;The best way to counter this attack is by refusing or ignoring lame DNS requests as described below. &lt;/DIV&gt;
&lt;P&gt;Over the past few days several users have reported receiving a slow stream of DNS requests for the DNS root (.) from unknown IP addresses.&lt;BR&gt;One alert user pointed out that this is also being reported at &lt;A href="http://isc.sans.org/diary.html?storyid=5713"&gt;http://isc.sans.org/diary.html?storyid=5713&lt;/A&gt; &lt;/P&gt;
&lt;P&gt;Other than taking up some extra log space, this is not really a problem for the local Simple DNS Plus server or site.&lt;BR&gt;It may however be an indication that someone is using your DNS server as part of a so-called DNS amplification attack against a third party - the owner of the IP address that the DNS requests appear to originate from.&lt;BR&gt;By sending a DNS request from a spoofed IP address, an attacker can trick your DNS server into sending a relatively large response (all the root records) to the victim.&lt;/P&gt;
&lt;P&gt;We recommend that you prevent this by limiting recursion to your own IP addresses, and refuse or ignore lame requests:&lt;/P&gt;
&lt;P&gt;In the Options dialog / DNS / Recursion section, either turn off recursion completely if you don't need it, or limit it. Do not use the "For everyone" option:&lt;/P&gt;
&lt;P&gt;&lt;IMG height=425 alt=rootdos1.png src="http://www.jhsoft.com/news/images/2362/rootdos1.png" width=641 border=0&gt;&lt;/P&gt;
&lt;P&gt;And in the Lame Requests section, select either "Respond with a Refused error message" or "Do not respond":&lt;/P&gt;
&lt;P&gt;&lt;IMG height=425 alt=rootdos3.png src="http://www.jhsoft.com/news/images/2362/rootdos3.png" width=641 border=0&gt;&lt;/P&gt;
&lt;P&gt;IMPORTANT: When registering new domain names, some registrars require that your DNS server responds with a correct list of DNS root servers as part of their tests (thus the default setting), so you may need to temporarily switch back when doing this.&lt;/P&gt;
&lt;P&gt;As described above, we recommend using the Lame Requests options to counter this type of attack in general.&lt;BR&gt;If this particular attack is continuously hitting your server, you will do the victim a favor using the "Do not respond" option. When no longer under attack, you can switch to the "Respond with Refused error message" option which still ensures that your server is not "interesting" as a waypoint for this type of attack - since it won't amplify traffic.&lt;/P&gt;</description><pubDate>Tue, 20 Jan 2009 12:57:00 GMT</pubDate><guid isPermaLink="false">jhsoft.com-news-2362</guid><link>http://www.simpledns.com/newsitem.aspx?id=2362</link><comments>http://www.simpledns.com/newsitem.aspx?id=2362#comments</comments><category>Front Page</category><category>JHMAIN</category><category>Simple DNS Plus</category></item><item><title>Remote zone/record editor from HostsTools.com</title><description>&lt;P&gt;Hosts Tools have just published a remote zone/record editor for Simple DNS Plus.&lt;/P&gt;
&lt;P&gt;For details see &lt;A href="http://www.hoststools.com/index.php/other-software/simpledns-client/"&gt;http://www.hoststools.com/index.php/other-software/simpledns-client/&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;Make sure to also check out the rest of their &lt;A href="http://www.hoststools.com"&gt;web-site&lt;/A&gt; for many other useful hosting tools.&lt;/P&gt;</description><pubDate>Mon, 29 Dec 2008 15:10:00 GMT</pubDate><guid isPermaLink="false">jhsoft.com-news-2354</guid><link>http://www.simpledns.com/newsitem.aspx?id=2354</link><comments>http://www.simpledns.com/newsitem.aspx?id=2354#comments</comments><category>JHMAIN</category><category>Simple DNS Plus</category></item></channel></rss>