From owner-freebsd-security@FreeBSD.ORG Tue Mar 24 08:52:16 2009 Return-Path: Delivered-To: freebsd-security@freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2001:4f8:fff6::34]) by hub.freebsd.org (Postfix) with ESMTP id 5B1BE1065679 for ; Tue, 24 Mar 2009 08:52:16 +0000 (UTC) (envelope-from bc@default.rs) Received: from smtp2.default.rs (anarki.default.rs [87.237.201.134]) by mx1.freebsd.org (Postfix) with ESMTP id 9337C8FC1E for ; Tue, 24 Mar 2009 08:52:15 +0000 (UTC) (envelope-from bc@default.rs) Received: (qmail 76232 invoked by uid 89); 24 Mar 2009 08:25:31 -0000 Received: from goldfish.yubc.net (HELO ?212.124.160.35?) (bc@default.rs@212.124.160.35) by smtp2.default.rs with AES256-SHA encrypted SMTP; 24 Mar 2009 08:25:31 -0000 Message-ID: <49C898FC.3010107@default.rs> Date: Tue, 24 Mar 2009 09:25:32 +0100 From: =?UTF-8?B?Qm9nZGFuIMSGdWxpYnJr?= User-Agent: Thunderbird 2.0.0.21 (Windows/20090302) MIME-Version: 1.0 To: freebsd-security@freebsd.org References: <20090324164644.A697.5F3C430A@netforest.ad.jp> In-Reply-To: <20090324164644.A697.5F3C430A@netforest.ad.jp> Content-Type: text/plain; charset=UTF-8; format=flowed Content-Transfer-Encoding: 7bit X-Mailman-Approved-At: Tue, 24 Mar 2009 11:27:26 +0000 Subject: Re: DNS of FreeBSD.org been Attacked!? X-BeenThere: freebsd-security@freebsd.org X-Mailman-Version: 2.1.5 Precedence: list List-Id: "Security issues \[members-only posting\]" List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Tue, 24 Mar 2009 08:52:16 -0000 UEDA Hiroyuki wrote: > Hello, > > >> C:\Documents and Settings\Administrator>nslookup ftp11.tw.freebsd.org 168.95.1.1 >> >> Server: dns.hinet.net >> Address: 168.95.1.1 >> >> Name: ftp11.tw.freebsd.org.com.tw > ^^^^^^^^ > You seem to nslookup "ftp11.tw.freebsd.org.COM.TW". If it's right, > >> Address: 82.98.86.170 > > is correct as follows: > > $ dig A ftp11.tw.freebsd.org.com.tw > > ; <<>> DiG 9.2.4 <<>> A ftp11.tw.freebsd.org.com.tw > ;; global options: printcmd > ;; Got answer: > ;; ->>HEADER<<- opcode: QUERY, status: NOERROR, id: 53400 > ;; flags: qr rd ra; QUERY: 1, ANSWER: 1, AUTHORITY: 0, ADDITIONAL: 0 > > ;; QUESTION SECTION: > ;ftp11.tw.freebsd.org.com.tw. IN A > > ;; ANSWER SECTION: > ftp11.tw.freebsd.org.com.tw. 600 IN A 82.98.86.170 > > So you had better check your PC's settings. > > > BTW, a wild card record(*.org.com.tw) is probably used. For example, I > got same results with following queries: > > $ dig A foo.bar.freebsd.org.com.tw > $ dig A foo.bar.org.com.tw > $ dig A foo.org.com.tw > An epic fail guy ;>