wok-6.x view dnstop/description.txt @ rev 25395
updated vde2 and vde2-dev (2.3.1 -> 2.3.3)
author | Hans-G?nter Theisgen |
---|---|
date | Mon Aug 01 17:34:00 2022 +0100 (2022-08-01) |
parents | |
children |
line source
1 Dnstop is a libpcap application (like tcpdump) that displays
2 various tables of DNS traffic on your network.
3 Currently dnstop displays tables of:
5 * Source IP addresses
6 * Destination IP addresses
7 * Query types
8 * Response codes
9 * Opcodes
10 * Top level domains
11 * Second level domains
12 * Third level domains
14 Dnstop supports both IPv4 and IPv6 addresses.
16 To help find especially undesirable DNS queries, dnstop provides
17 a number of filters. The filters tell dnstop to display only the
18 following types of queries:
20 * For unknown or invalid TLDs
21 * A queries where the query name is already an IP address
22 * PTR queries for RFC1918 address space
23 * Responses with code REFUSED
25 Dnstop can either read packets from the live capture device,
26 or from a tcpdump savefile.