1. watchNS/000.co.jp
Knot resolver だと委譲情報が使われる。(BIND, Unboundとは異なる)
- Answerありの返答でAuthority Section以降を捨てる実装なら、似た状況になる。
$ dig -t ns 000.co.jp @127.0.0.3
; <<>> DiG 9.11.1 <<>> -t ns 000.co.jp @127.0.0.3 ;; global options: +cmd ;; Got answer: ;; ->>HEADER<<- opcode: QUERY, status: NOERROR, id: 8385 ;; flags: qr rd ra; QUERY: 1, ANSWER: 2, AUTHORITY: 0, ADDITIONAL: 1 ;; OPT PSEUDOSECTION: ; EDNS: version: 0, flags:; udp: 4096 ; COOKIE: 25d2e0dbaf719e7b3de6ec2958ff240559a88f8f60b9aed6 (good) ;; QUESTION SECTION: ;000.co.jp. IN NS ;; ANSWER SECTION: 000.co.jp. 86400 IN NS ns1.dnsserver-jp.net. 000.co.jp. 86400 IN NS ns2.dnsserver-jp.net. ;; Query time: 295 msec ;; SERVER: 127.0.0.3#53(127.0.0.3) ;; WHEN: Tue Apr 25 19:25:09 JST 2017 ;; MSG SIZE rcvd: 118
tmaeno@tm:~$ dig 000.co.jp @127.0.0.3
; <<>> DiG 9.11.1 <<>> 000.co.jp @127.0.0.3 ;; global options: +cmd ;; Got answer: ;; ->>HEADER<<- opcode: QUERY, status: NOERROR, id: 33551 ;; flags: qr rd ra; QUERY: 1, ANSWER: 1, AUTHORITY: 0, ADDITIONAL: 1 ;; OPT PSEUDOSECTION: ; EDNS: version: 0, flags:; udp: 4096 ; COOKIE: 85b66c737d28a41f1794732758ff241c0360fb96477dd28b (good) ;; QUESTION SECTION: ;000.co.jp. IN A ;; ANSWER SECTION: 000.co.jp. 300 IN A 110.34.58.136 ;; Query time: 8 msec ;; SERVER: 127.0.0.3#53(127.0.0.3) ;; WHEN: Tue Apr 25 19:25:32 JST 2017 ;; MSG SIZE rcvd: 82
$ dig 000.co.jp @127.0.0.3
; <<>> DiG 9.11.1 <<>> 000.co.jp @127.0.0.3 ;; global options: +cmd ;; Got answer: ;; ->>HEADER<<- opcode: QUERY, status: NOERROR, id: 16211 ;; flags: qr rd ra; QUERY: 1, ANSWER: 1, AUTHORITY: 0, ADDITIONAL: 1 ;; OPT PSEUDOSECTION: ; EDNS: version: 0, flags:; udp: 4096 ; COOKIE: c3fb499c2fa6ad8772a4879d58ff243a4d8aaf7a9bed79aa (good) ;; QUESTION SECTION: ;000.co.jp. IN A ;; ANSWER SECTION: 000.co.jp. 270 IN A 110.34.58.136 ;; Query time: 0 msec ;; SERVER: 127.0.0.3#53(127.0.0.3) ;; WHEN: Tue Apr 25 19:26:02 JST 2017 ;; MSG SIZE rcvd: 82
$ dig -t ns 000.co.jp @127.0.0.3
; <<>> DiG 9.11.1 <<>> -t ns 000.co.jp @127.0.0.3 ;; global options: +cmd ;; Got answer: ;; ->>HEADER<<- opcode: QUERY, status: NOERROR, id: 29807 ;; flags: qr rd ra; QUERY: 1, ANSWER: 2, AUTHORITY: 0, ADDITIONAL: 1 ;; OPT PSEUDOSECTION: ; EDNS: version: 0, flags:; udp: 4096 ; COOKIE: eb9e8e95a4fca1426a8853d958ff24409315b30345710dd1 (good) ;; QUESTION SECTION: ;000.co.jp. IN NS ;; ANSWER SECTION: 000.co.jp. 86341 IN NS ns1.dnsserver-jp.net. 000.co.jp. 86341 IN NS ns2.dnsserver-jp.net. ;; Query time: 0 msec ;; SERVER: 127.0.0.3#53(127.0.0.3) ;; WHEN: Tue Apr 25 19:26:08 JST 2017 ;; MSG SIZE rcvd: 118
2. www.000.co.jp A query
返答を確認しておいて:
$ dnsq a www.000.co.jp ns1.dnsserver-jp.net.
1 www.000.co.jp: 126 bytes, 1+1+2+2 records, response, authoritative, noerror query: 1 www.000.co.jp answer: www.000.co.jp 300 A 110.34.58.136 authority: 000.co.jp 300 NS ns1.willnet.ne.jp authority: 000.co.jp 300 NS ns2.willnet.ne.jp additional: ns1.willnet.ne.jp 86400 A 123.108.1.106 additional: ns2.willnet.ne.jp 3600 A 123.108.2.218
$ dig www.000.co.jp @127.0.0.3
; <<>> DiG 9.11.1 <<>> www.000.co.jp @127.0.0.3 ;; global options: +cmd ;; Got answer: ;; ->>HEADER<<- opcode: QUERY, status: NOERROR, id: 36649 ;; flags: qr rd ra; QUERY: 1, ANSWER: 1, AUTHORITY: 0, ADDITIONAL: 1 ;; OPT PSEUDOSECTION: ; EDNS: version: 0, flags:; udp: 4096 ; COOKIE: affa4b9c4f0cbb043a559b2358ff246449cf7b8a260b6045 (good) ;; QUESTION SECTION: ;www.000.co.jp. IN A ;; ANSWER SECTION: www.000.co.jp. 300 IN A 110.34.58.136 ;; Query time: 8 msec ;; SERVER: 127.0.0.3#53(127.0.0.3) ;; WHEN: Tue Apr 25 19:26:44 JST 2017 ;; MSG SIZE rcvd: 86
$ dig -t ns 000.co.jp @127.0.0.3
; <<>> DiG 9.11.1 <<>> -t ns 000.co.jp @127.0.0.3 ;; global options: +cmd ;; Got answer: ;; ->>HEADER<<- opcode: QUERY, status: NOERROR, id: 51929 ;; flags: qr rd ra; QUERY: 1, ANSWER: 2, AUTHORITY: 0, ADDITIONAL: 1 ;; OPT PSEUDOSECTION: ; EDNS: version: 0, flags:; udp: 4096 ; COOKIE: 5e8215b19f4068087c95792858ff2483ca6984c4dfeb07f2 (good) ;; QUESTION SECTION: ;000.co.jp. IN NS ;; ANSWER SECTION: 000.co.jp. 86274 IN NS ns1.dnsserver-jp.net. 000.co.jp. 86274 IN NS ns2.dnsserver-jp.net. ;; Query time: 0 msec ;; SERVER: 127.0.0.3#53(127.0.0.3) ;; WHEN: Tue Apr 25 19:27:15 JST 2017 ;; MSG SIZE rcvd: 118
UnboundはNSにns1.willnet.ne.jpなどを返してきますが、 これがどうやって入手したものかは未確認です。
- harden-referral-pathの効果であることを期待しています。
-- ToshinoriMaeno 2017-04-25 12:00:19