in case you missed it on the bird website. I've written a funky little chrome plugin (other browsers coming soon) that will harvest your DNS requests out of your browser and fire them to an API which in turn will log them in Elasticsearch all local, but could be turned into something much much better.

I'm looking to go down the road of a crowd pDNS collection platform that respects privacy by doing as much as possible to separate you from your data, no email/phone based accounts, submissions over a baked in Tor client and the ability to filter hosts out by keywords before anything is pushed to the API (this already exists, right click > options)

There is scope to write a couple of binary clients to pop a collector on your egress firewalls or even your Android device

https://github.com/olihough86/pdnscollect

tags

#infosec #threatintel #github #help #dns #pdns #cybersecurity

GitHub - olihough86/pdnscollect: Browser extension and local listener PoC for collecting your own DNS data while browsing

Browser extension and local listener PoC for collecting your own DNS data while browsing - GitHub - olihough86/pdnscollect: Browser extension and local listener PoC for collecting your own DNS data...

GitHub

What's in it for you?

Well top contributors will get access to all the data for free for life (who is a top contributor? I'll decide that based on the value you added to the project.)

Quality submissions will be rewarded with coins which can be spent on queries/downloads from the dataset. Your submissions will be tied to a arbitrary token (think like a bitcoin address) generated on install, you keep hold of it and pop it in all your collectors

As the set grows I'll add the ability to purchase coin packs (that is how costs will be recovered) but the focus will ALWAYS be on you put data in you can pull data out

Why bother?

LOL I wanna make DomainTools cry and laugh bitterly as we collectively destroy a monopoly. Also pDNS is fucking expensive and I'm tired of begging for it because I don't have budget of a multi million $ company.

Privacy though?

Yes there will always be a hurdle here, after all I'm asking you to fire off your browsing history to me, kind of.

I don't care who you are, I don't want to collect identifying data or any local (RFC1918) resolutions. Rather than "i promise not to identify you" I want to go down the route of just collecting the minimum

- drop anything that resolves to a bogon range
- keywords to drop ANYTHING containing that keyword, this should be expended on more, go crazy!
- everything is open source, hell want to go set up your own private swam, go ahead compete with me, the license is The Unlicense, do it. (don't be surprised if your mega corp using my stuff for free gets some uninvited packets when I find out you flipped my work for greed)
- use of Tor or any better anonymous routing to break the tie of your IP to a submission
- ability to retroactively purge your data in full or by host or token, self service no need to fill a form (you will of course loose your coins tied to that data)

I already have a fuck ton of pDNS data?

That's great, can I have it please? In return you will get the aforementioned access for life and I'll love you, you will be helping to seed a project that has the potential to change things, allowing small time analysts access to very valuable real time data, also I promise not to tell anyone your nabbed it from elsewhere, ssshhhh!

I am someone who contributes a lot of cutting edge intel on the bird site etc off my own back?

Yes. I probably already know who you are, once we get to close to rolling version 0.0000000000000001 I'll be contacting you, I would be honored to know you gave it a go, you're the good people this is for you.

no one will use it and your data will be stale?

This is well yes, this is an issue. I'm open to ideas on how to get it on more devices (with big fat consent, not some hidden t&c) There is the potential to bundle it into other projects (think like how ad providers do it but without dodgyness)

As it's all open source, it could be abused, people bundling it into stuff and earning coins... there isn't much I can do about that but I'd have no issue purging data on request to combat that.

and finally for this wall of text mega thread.

YOU ARE DOING SOMETHING I DON'T LIKE AND OR I HAVE A PATENT AND OR YOU USED DATA TAKE FROM ME RARARARARAAR

lawyer up motherfucker, I have way too much free time. There is nothing more dangerous than a person who has decided that society just isn't for them, I'll be happy to waste your time and money by simply not answering.