about the wild record

Chris Thompson cet1 at cam.ac.uk
Mon Oct 15 16:25:37 UTC 2012


On Oct 15 2012, pangj at riseup.net wrote:

>no SOA for test.cloudns.tk IMO. see:
>
>PromatoMacBook-Pro:~ pro$ dig test.cloudns.tk soa
>
>; <<>> DiG 9.7.6-P1 <<>> test.cloudns.tk soa
>;; global options: +cmd
>;; Got answer:
>;; ->>HEADER<<- opcode: QUERY, status: NOERROR, id: 60320
>;; flags: qr rd ra; QUERY: 1, ANSWER: 0, AUTHORITY: 1, ADDITIONAL: 0
>
>;; QUESTION SECTION:
>;test.cloudns.tk.		IN	SOA
>
>;; AUTHORITY SECTION:
>cloudns.tk.		300	IN	SOA	ns0.cloudwebdns.com. support.cloudwebdns.com. 1048
>7200 1800 604800 300
>
>;; Query time: 860 msec
>;; SERVER: 211.136.192.6#53(211.136.192.6)
>;; WHEN: Mon Oct 15 21:13:04 2012
>;; MSG SIZE  rcvd: 96
>
>
>The SOA is presented in AUTHORITY SECTION, not in ANSWER SECTION, so it's
>meaningless.

Indeed, Warren's use of +nostats +ncomments to conceal that was
disingenuous, to say the least.

But you should notice that the above response - rcode NOERROR with
an empty data section - is what RFC 2308 calls "NODATA", and not an
NXDOMAIN. This is because test.cloudns.tk is an "empty non-terminal"
in the name tree within the zone, and it is that which prevents
*.cloudns.tk from applying to anything under it.

-- 
Chris Thompson
Email: cet1 at cam.ac.uk



More information about the bind-users mailing list