HUSH DNS Seed https://hush.is
You can not select more than 25 topics Topics must start with a letter or number, can include dashes ('-') and can be up to 35 characters long.
 
 
 
 
Madbuda cd47f66c1e initial 7 years ago
.gitignore initial 7 years ago
Makefile initial 7 years ago
README initial 7 years ago
bitcoin.cpp initial 7 years ago
bitcoin.h initial 7 years ago
combine.pl initial 7 years ago
compat.h initial 7 years ago
db.cpp initial 7 years ago
db.h initial 7 years ago
dns.c initial 7 years ago
dns.h initial 7 years ago
main.cpp initial 7 years ago
netbase.cpp initial 7 years ago
netbase.h initial 7 years ago
protocol.cpp initial 7 years ago
protocol.h initial 7 years ago
serialize.h initial 7 years ago
strlcpy.h initial 7 years ago
test.pl initial 7 years ago
uint256.h initial 7 years ago
util.cpp initial 7 years ago
util.h initial 7 years ago

README

hush-seeder
==============

Hush-seeder is a crawler for the Hush network, which exposes a list
of reliable nodes via a built-in DNS server.

Features:
* regularly revisits known nodes to check their availability
* bans nodes after enough failures, or bad behaviour
* keeps statistics over (exponential) windows of 2 hours, 8 hours,
1 day and 1 week, to base decisions on.
* very low memory (a few tens of megabytes) and cpu requirements.
* crawlers run in parallel (by default 24 threads simultaneously).

REQUIREMENTS
------------

$ sudo apt-get install build-essential libboost-all-dev libssl-dev

USAGE
-----

Assuming you want to run a dns seed on dnsseed.example.com, you will
need an authorative NS record in example.com's domain record, pointing
to for example vps.example.com:

$ dig -t NS dnsseed.example.com

;; ANSWER SECTION
dnsseed.example.com. 86400 IN NS vps.example.com.

On the system vps.example.com, you can now run dnsseed:

./dnsseed -h dnsseed.example.com -n vps.example.com

If you want the DNS server to report SOA records, please provide an
e-mail address (with the @ part replaced by .) using -m.

COMPILING
---------
Compiling will require boost and ssl. On debian systems, these are provided
by `libboost-dev` and `libssl-dev` respectively.

$ make

This will produce the `dnsseed` binary.


RUNNING AS NON-ROOT
-------------------

Typically, you'll need root privileges to listen to port 53 (name service).

One solution is using an iptables rule (Linux only) to redirect it to
a non-privileged port:

$ iptables -t nat -A PREROUTING -p udp --dport 53 -j REDIRECT --to-port 5353

If properly configured, this will allow you to run dnsseed in userspace, using
the -p 5353 option.