DNS/毒盛/移転インジェクション/Knot-resolverについて、ここに記述してください。

$ kdig -t a ns5.d.t.e-ontap.com @127.0.0.3
;; ->>HEADER<<- opcode: QUERY; status: NXDOMAIN; id: 11497
;; Flags: qr rd ra; QUERY: 1; ANSWER: 0; AUTHORITY: 1; ADDITIONAL: 0

;; QUESTION SECTION:
;; ns5.d.t.e-ontap.com.         IN      A

;; AUTHORITY SECTION:
d.t.e-ontap.com.        1697    IN      SOA     ns10.d.t.e-ontap.com. hostmaster.d.t.e-ontap.com. 1446179568 16384 2048 1048576 2560

;; Received 89 B
;; Time 2015-11-01 14:29:04 JST
;; From 127.0.0.3@53(UDP) in 0.2 ms
tmaeno@tmaeno:~$ kdig -t ns d.t.e-ontap.com @127.0.0.3
;; ->>HEADER<<- opcode: QUERY; status: NOERROR; id: 42961
;; Flags: qr rd ra; QUERY: 1; ANSWER: 1; AUTHORITY: 0; ADDITIONAL: 0

;; QUESTION SECTION:
;; d.t.e-ontap.com.             IN      NS

;; ANSWER SECTION:
d.t.e-ontap.com.        10      IN      NS      ns10.d.t.e-ontap.com.

;; Received 52 B
;; Time 2015-11-01 14:29:12 JST
;; From 127.0.0.3@53(UDP) in 0.2 ms
tmaeno@tmaeno:~$ kdig -t a www.d.t.e-ontap.com @127.0.0.3
;; ->>HEADER<<- opcode: QUERY; status: NOERROR; id: 62814
;; Flags: qr rd ra; QUERY: 1; ANSWER: 1; AUTHORITY: 0; ADDITIONAL: 0

;; QUESTION SECTION:
;; www.d.t.e-ontap.com.         IN      A

;; ANSWER SECTION:
www.d.t.e-ontap.com.    10      IN      A       192.0.2.10

;; Received 53 B
;; Time 2015-11-01 14:29:19 JST
;; From 127.0.0.3@53(UDP) in 72.4 ms
tmaeno@tmaeno:~$ kdig -t ns d.t.e-ontap.com @127.0.0.3
;; ->>HEADER<<- opcode: QUERY; status: NOERROR; id: 43983
;; Flags: qr rd ra; QUERY: 1; ANSWER: 1; AUTHORITY: 0; ADDITIONAL: 0

;; QUESTION SECTION:
;; d.t.e-ontap.com.             IN      NS

;; ANSWER SECTION:
d.t.e-ontap.com.        0       IN      NS      ns10.d.t.e-ontap.com.

;; Received 52 B
;; Time 2015-11-01 14:29:22 JST
;; From 127.0.0.3@53(UDP) in 0.2 ms
tmaeno@tmaeno:~$ kdig -t ns d.t.e-ontap.com @127.0.0.3
;; ->>HEADER<<- opcode: QUERY; status: NOERROR; id: 38837
;; Flags: qr rd ra; QUERY: 1; ANSWER: 1; AUTHORITY: 0; ADDITIONAL: 0

;; QUESTION SECTION:
;; d.t.e-ontap.com.             IN      NS

;; ANSWER SECTION:
d.t.e-ontap.com.        90      IN      NS      ns5.d.t.e-ontap.com.

;; Received 51 B
;; Time 2015-11-01 14:29:26 JST
;; From 127.0.0.3@53(UDP) in 149.5 ms
tmaeno@tmaeno:~$ kdig -t a ns5.d.t.e-ontap.com @127.0.0.3
;; ->>HEADER<<- opcode: QUERY; status: NOERROR; id: 38723
;; Flags: qr rd ra; QUERY: 1; ANSWER: 1; AUTHORITY: 0; ADDITIONAL: 0

;; QUESTION SECTION:
;; ns5.d.t.e-ontap.com.         IN      A

;; ANSWER SECTION:
ns5.d.t.e-ontap.com.    412     IN      A       150.42.6.5

;; Received 53 B
;; Time 2015-11-01 14:29:34 JST
;; From 127.0.0.3@53(UDP) in 0.2 ms

[plan] plan 'ns5.d.t.e-ontap.com.' type 'A'
[ pc ]   => satisfied from cache
[iter]   <= rcode: NXDOMAIN
[resl] finished: 4, queries: 1, mempool: 16392 B
[plan] plan 'd.t.e-ontap.com.' type 'NS'
[ rc ]   => satisfied from cache
[iter]   <= rcode: NOERROR
[resl] finished: 4, queries: 1, mempool: 16392 B
[plan] plan 'www.d.t.e-ontap.com.' type 'A'
[resl]   => querying: '150.42.6.1' score: 66 zone cut: 'd.t.e-ontap.com.' m12n: 'WWw.D.T.E-Ontap.cOM.' type: 'A'
[iter]   <= rcode: NOERROR
[resl] finished: 4, queries: 1, mempool: 16392 B
[plan] plan 'd.t.e-ontap.com.' type 'NS'
[ rc ]   => satisfied from cache
[iter]   <= rcode: NOERROR
[resl] finished: 4, queries: 1, mempool: 16392 B
[plan] plan 'd.t.e-ontap.com.' type 'NS'
[resl]   => querying: '14.192.44.2' score: 61 zone cut: 't.e-ontap.com.' m12n: 'd.t.E-onTap.COM.' type: 'NS'
[iter]   <= referral response, follow
[resl]   => querying: '150.42.6.5' score: 76 zone cut: 'd.t.e-ontap.com.' m12n: 'D.t.E-ONTAp.COM.' type: 'NS'
[iter]   <= rcode: NOERROR
[resl] finished: 4, queries: 1, mempool: 16392 B
[plan] plan 'ns5.d.t.e-ontap.com.' type 'A'
[ rc ]   => satisfied from cache
[iter]   <= rcode: NOERROR
[resl] finished: 4, queries: 1, mempool: 16392 B

MoinQ: DNS/毒盛/攻撃手法/移転インジェクション/Knot-resolver (last edited 2021-05-02 07:23:02 by ToshinoriMaeno)