| 122 | |
| 123 | |
| 124 | def _get_question_section(query): |
| 125 | # Query format is as follows: 12 byte header, question section (comprised |
| 126 | # of arbitrary-length name, 2 byte type, 2 byte class), followed by an |
| 127 | # additional section sometimes. (e.g. OPT record for DNSSEC) |
| 128 | start_idx = 12 |
| 129 | end_idx = start_idx |
| 130 | |
| 131 | num_questions = (query.data[4] << 8) | query.data[5] |
| 132 | |
| 133 | while num_questions > 0: |
| 134 | while query.data[end_idx] != 0: |
| 135 | end_idx += query.data[end_idx] + 1 |
| 136 | # Include the null byte, type, and class |
| 137 | end_idx += 5 |
| 138 | num_questions -= 1 |
| 139 | |
| 140 | return query.data[start_idx:end_idx] |
| 141 | |
| 142 | |
| 143 | class DNSFlag: |