Authoritative answer "no data" 50% of the time

Brad Knowles brad.knowles at skynet.be
Thu Jun 7 22:31:58 UTC 2001


At 12:33 PM -0400 6/7/01, Bobby Dimmette wrote:

>  You should only use the advertised servers (ns01,ns02,ns03).   They are
>  the only ones intended to answer queries from outside the army.mil domain.

	He doesn't have a choice what nameserver to query, because he's 
behind a firewall.

>  Use nslookup to look for the SOA...

	Moreover, nslookup is a really bad DNS debugging tool to be 
telling people to use.  It does all sorts of stupid things that it 
should not, and should be avoided unless you're using the 
vendor-provided version of nslookup, which has probably been hacked 
to use /etc/nsswitch.conf, NetInfo, NIS, NIS+, etc... in addition to 
just the pure DNS.

-- 
Brad Knowles, <brad.knowles at skynet.be>

/*        efdtt.c  Author:  Charles M. Hannum <root at ihack.net>          */
/*       Represented as 1045 digit prime number by Phil Carmody         */
/*     Prime as DNS cname chain by Roy Arends and Walter Belgers        */
/*                                                                      */
/*     Usage is:  cat title-key scrambled.vob | efdtt >clear.vob        */
/*   where title-key = "153 2 8 105 225" or other similar 5-byte key    */

dig decss.friet.org|perl -ne'if(/^x/){s/[x.]//g;print pack(H124,$_)}'


More information about the bind-users mailing list