testing vulnerability against secondary NS

Chris Henderson henders254 at gmail.com
Mon Aug 11 23:24:21 UTC 2008


I am testing the recent DNS vulnerability against my secondary name server
from my local machine
("dig @<ip_of_nameserver> +short porttest.dns-oarc.net TXT" and also
"nslookup -querytype=TXT -timeout=10 porttest.dns-oarc.net.")

But strangely it is giving me the result of my primary name server! Every time
I try to query, it gives me back my primary name server's result. I also tried
doxpara.com and https://www.dns-oarc.net/oarc/services/dnsentropy

My local machine's /etc/resolv.conf has only one nameserver entry - my
secondary name server.

Also, if I try to resolve a hostname I can query my secondary name server and
get the answer back. So I know my secondary name server is working.

Does anyone know how can I test the vuln. against my secondary name server?

Thanks.


More information about the bind-users mailing list