mirror of
https://github.com/NLnetLabs/unbound.git
synced 2026-08-17 21:25:50 +02:00
Compare commits
4
Commits
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
f6269baa60 | ||
|
|
19154c6e58 | ||
|
|
a33f0638e1 | ||
|
|
bbeee42e25 |
@@ -1,6 +1,6 @@
|
||||
#! /bin/sh
|
||||
# Guess values for system-dependent variables and create Makefiles.
|
||||
# Generated by GNU Autoconf 2.71 for unbound 1.24.0.
|
||||
# Generated by GNU Autoconf 2.71 for unbound 1.24.2.
|
||||
#
|
||||
# Report bugs to <unbound-bugs@nlnetlabs.nl or https://github.com/NLnetLabs/unbound/issues>.
|
||||
#
|
||||
@@ -622,8 +622,8 @@ MAKEFLAGS=
|
||||
# Identity of this package.
|
||||
PACKAGE_NAME='unbound'
|
||||
PACKAGE_TARNAME='unbound'
|
||||
PACKAGE_VERSION='1.24.0'
|
||||
PACKAGE_STRING='unbound 1.24.0'
|
||||
PACKAGE_VERSION='1.24.2'
|
||||
PACKAGE_STRING='unbound 1.24.2'
|
||||
PACKAGE_BUGREPORT='unbound-bugs@nlnetlabs.nl or https://github.com/NLnetLabs/unbound/issues'
|
||||
PACKAGE_URL=''
|
||||
|
||||
@@ -1513,7 +1513,7 @@ if test "$ac_init_help" = "long"; then
|
||||
# Omit some internal or obsolete options to make the list less imposing.
|
||||
# This message is too long to be a string in the A/UX 3.1 sh.
|
||||
cat <<_ACEOF
|
||||
\`configure' configures unbound 1.24.0 to adapt to many kinds of systems.
|
||||
\`configure' configures unbound 1.24.2 to adapt to many kinds of systems.
|
||||
|
||||
Usage: $0 [OPTION]... [VAR=VALUE]...
|
||||
|
||||
@@ -1579,7 +1579,7 @@ fi
|
||||
|
||||
if test -n "$ac_init_help"; then
|
||||
case $ac_init_help in
|
||||
short | recursive ) echo "Configuration of unbound 1.24.0:";;
|
||||
short | recursive ) echo "Configuration of unbound 1.24.2:";;
|
||||
esac
|
||||
cat <<\_ACEOF
|
||||
|
||||
@@ -1832,7 +1832,7 @@ fi
|
||||
test -n "$ac_init_help" && exit $ac_status
|
||||
if $ac_init_version; then
|
||||
cat <<\_ACEOF
|
||||
unbound configure 1.24.0
|
||||
unbound configure 1.24.2
|
||||
generated by GNU Autoconf 2.71
|
||||
|
||||
Copyright (C) 2021 Free Software Foundation, Inc.
|
||||
@@ -2489,7 +2489,7 @@ cat >config.log <<_ACEOF
|
||||
This file contains any messages produced by compilers while
|
||||
running configure, to aid debugging if configure makes a mistake.
|
||||
|
||||
It was created by unbound $as_me 1.24.0, which was
|
||||
It was created by unbound $as_me 1.24.2, which was
|
||||
generated by GNU Autoconf 2.71. Invocation command line was
|
||||
|
||||
$ $0$ac_configure_args_raw
|
||||
@@ -3253,11 +3253,11 @@ UNBOUND_VERSION_MAJOR=1
|
||||
|
||||
UNBOUND_VERSION_MINOR=24
|
||||
|
||||
UNBOUND_VERSION_MICRO=0
|
||||
UNBOUND_VERSION_MICRO=2
|
||||
|
||||
|
||||
LIBUNBOUND_CURRENT=9
|
||||
LIBUNBOUND_REVISION=33
|
||||
LIBUNBOUND_REVISION=34
|
||||
LIBUNBOUND_AGE=1
|
||||
# 1.0.0 had 0:12:0
|
||||
# 1.0.1 had 0:13:0
|
||||
@@ -3358,6 +3358,8 @@ LIBUNBOUND_AGE=1
|
||||
# 1.23.0 had 9:31:1
|
||||
# 1.23.1 had 9:32:1
|
||||
# 1.24.0 had 9:33:1
|
||||
# 1.24.1 had 9:34:1
|
||||
# 1.24.2 had 9:35:1
|
||||
|
||||
# Current -- the number of the binary API that we're implementing
|
||||
# Revision -- which iteration of the implementation of the binary
|
||||
@@ -25291,7 +25293,7 @@ printf "%s\n" "#define MAXSYSLOGMSGLEN 10240" >>confdefs.h
|
||||
|
||||
|
||||
|
||||
version=1.24.0
|
||||
version=1.24.2
|
||||
|
||||
{ printf "%s\n" "$as_me:${as_lineno-$LINENO}: checking for build time" >&5
|
||||
printf %s "checking for build time... " >&6; }
|
||||
@@ -25821,7 +25823,7 @@ cat >>$CONFIG_STATUS <<\_ACEOF || ac_write_fail=1
|
||||
# report actual input values of CONFIG_FILES etc. instead of their
|
||||
# values after options handling.
|
||||
ac_log="
|
||||
This file was extended by unbound $as_me 1.24.0, which was
|
||||
This file was extended by unbound $as_me 1.24.2, which was
|
||||
generated by GNU Autoconf 2.71. Invocation command line was
|
||||
|
||||
CONFIG_FILES = $CONFIG_FILES
|
||||
@@ -25889,7 +25891,7 @@ ac_cs_config_escaped=`printf "%s\n" "$ac_cs_config" | sed "s/^ //; s/'/'\\\\\\\\
|
||||
cat >>$CONFIG_STATUS <<_ACEOF || ac_write_fail=1
|
||||
ac_cs_config='$ac_cs_config_escaped'
|
||||
ac_cs_version="\\
|
||||
unbound config.status 1.24.0
|
||||
unbound config.status 1.24.2
|
||||
configured by $0, generated by GNU Autoconf 2.71,
|
||||
with options \\"\$ac_cs_config\\"
|
||||
|
||||
|
||||
+4
-2
@@ -12,14 +12,14 @@ sinclude(dnscrypt/dnscrypt.m4)
|
||||
# must be numbers. ac_defun because of later processing
|
||||
m4_define([VERSION_MAJOR],[1])
|
||||
m4_define([VERSION_MINOR],[24])
|
||||
m4_define([VERSION_MICRO],[0])
|
||||
m4_define([VERSION_MICRO],[2])
|
||||
AC_INIT([unbound],m4_defn([VERSION_MAJOR]).m4_defn([VERSION_MINOR]).m4_defn([VERSION_MICRO]),[unbound-bugs@nlnetlabs.nl or https://github.com/NLnetLabs/unbound/issues],[unbound])
|
||||
AC_SUBST(UNBOUND_VERSION_MAJOR, [VERSION_MAJOR])
|
||||
AC_SUBST(UNBOUND_VERSION_MINOR, [VERSION_MINOR])
|
||||
AC_SUBST(UNBOUND_VERSION_MICRO, [VERSION_MICRO])
|
||||
|
||||
LIBUNBOUND_CURRENT=9
|
||||
LIBUNBOUND_REVISION=33
|
||||
LIBUNBOUND_REVISION=34
|
||||
LIBUNBOUND_AGE=1
|
||||
# 1.0.0 had 0:12:0
|
||||
# 1.0.1 had 0:13:0
|
||||
@@ -120,6 +120,8 @@ LIBUNBOUND_AGE=1
|
||||
# 1.23.0 had 9:31:1
|
||||
# 1.23.1 had 9:32:1
|
||||
# 1.24.0 had 9:33:1
|
||||
# 1.24.1 had 9:34:1
|
||||
# 1.24.2 had 9:35:1
|
||||
|
||||
# Current -- the number of the binary API that we're implementing
|
||||
# Revision -- which iteration of the implementation of the binary
|
||||
|
||||
@@ -6176,6 +6176,7 @@ fr_atomic_copy_cfg(struct config_file* oldcfg, struct config_file* cfg,
|
||||
COPY_VAR_ptr(ipset_name_v6);
|
||||
#endif
|
||||
COPY_VAR_int(ede);
|
||||
COPY_VAR_int(iter_scrub_promiscuous);
|
||||
}
|
||||
#endif /* ATOMIC_POINTER_LOCK_FREE && HAVE_LINK_ATOMIC_STORE */
|
||||
|
||||
|
||||
@@ -196,6 +196,10 @@ server:
|
||||
# Limit on upstream queries for an incoming query and its recursion.
|
||||
# max-global-quota: 200
|
||||
|
||||
# Should the scrubber remove promiscuous NS from positive answers,
|
||||
# protects against poison attempts.
|
||||
# iter-scrub-promiscuous: yes
|
||||
|
||||
# msec for waiting for an unknown server to reply. Increase if you
|
||||
# are behind a slow satellite link, to eg. 1128.
|
||||
# unknown-server-time-limit: 376
|
||||
|
||||
@@ -167,6 +167,7 @@ ipset,
|
||||
\fI\%tcp\-reuse\-timeout\fP,
|
||||
\fI\%tcp\-auth\-query\-timeout\fP,
|
||||
\fI\%delay\-close\fP\&.
|
||||
\fI\%iter\-scrub\-promiscuous\fP\&.
|
||||
.sp
|
||||
It does not work with
|
||||
\fI\%interface\fP and
|
||||
|
||||
@@ -169,6 +169,7 @@ There are several commands that the server understands.
|
||||
:ref:`tcp-reuse-timeout<unbound.conf.tcp-reuse-timeout>`,
|
||||
:ref:`tcp-auth-query-timeout<unbound.conf.tcp-auth-query-timeout>`,
|
||||
:ref:`delay-close<unbound.conf.delay-close>`.
|
||||
:ref:`iter-scrub-promiscuous<unbound.conf.iter-scrub-promiscuous>`.
|
||||
|
||||
It does not work with
|
||||
:ref:`interface<unbound.conf.interface>` and
|
||||
|
||||
@@ -3656,6 +3656,15 @@ Default: 200
|
||||
.UNINDENT
|
||||
.INDENT 0.0
|
||||
.TP
|
||||
.B iter\-scrub\-promiscuous: \fI<yes or no>\fP
|
||||
Should the iterator scrubber remove promiscuous NS from positive answers.
|
||||
This protects against poisonous contents, that could affect names in the
|
||||
same zone as a spoofed packet.
|
||||
.sp
|
||||
Default: yes
|
||||
.UNINDENT
|
||||
.INDENT 0.0
|
||||
.TP
|
||||
.B fast\-server\-permil: \fI<number>\fP
|
||||
Specify how many times out of 1000 to pick from the set of fastest servers.
|
||||
0 turns the feature off.
|
||||
|
||||
@@ -3156,6 +3156,14 @@ These options are part of the **server:** clause.
|
||||
Default: 200
|
||||
|
||||
|
||||
@@UAHL@unbound.conf@iter-scrub-promiscuous@@: *<yes or no>*
|
||||
Should the iterator scrubber remove promiscuous NS from positive answers.
|
||||
This protects against poisonous contents, that could affect names in the
|
||||
same zone as a spoofed packet.
|
||||
|
||||
Default: yes
|
||||
|
||||
|
||||
@@UAHL@unbound.conf@fast-server-permil@@: *<number>*
|
||||
Specify how many times out of 1000 to pick from the set of fastest servers.
|
||||
0 turns the feature off.
|
||||
|
||||
+51
-4
@@ -418,12 +418,13 @@ shorten_rrset(sldns_buffer* pkt, struct rrset_parse* rrset, int count)
|
||||
* @param qinfo: original query.
|
||||
* @param region: where to allocate synthesized CNAMEs.
|
||||
* @param env: module env with config options.
|
||||
* @param zonename: name of server zone.
|
||||
* @return 0 on error.
|
||||
*/
|
||||
static int
|
||||
scrub_normalize(sldns_buffer* pkt, struct msg_parse* msg,
|
||||
struct query_info* qinfo, struct regional* region,
|
||||
struct module_env* env)
|
||||
struct module_env* env, uint8_t* zonename)
|
||||
{
|
||||
uint8_t* sname = qinfo->qname;
|
||||
size_t snamelen = qinfo->qname_len;
|
||||
@@ -431,7 +432,8 @@ scrub_normalize(sldns_buffer* pkt, struct msg_parse* msg,
|
||||
int cname_length = 0; /* number of CNAMEs, or DNAMEs */
|
||||
|
||||
if(FLAGS_GET_RCODE(msg->flags) != LDNS_RCODE_NOERROR &&
|
||||
FLAGS_GET_RCODE(msg->flags) != LDNS_RCODE_NXDOMAIN)
|
||||
FLAGS_GET_RCODE(msg->flags) != LDNS_RCODE_NXDOMAIN &&
|
||||
FLAGS_GET_RCODE(msg->flags) != LDNS_RCODE_YXDOMAIN)
|
||||
return 1;
|
||||
|
||||
/* For the ANSWER section, remove all "irrelevant" records and add
|
||||
@@ -470,6 +472,11 @@ scrub_normalize(sldns_buffer* pkt, struct msg_parse* msg,
|
||||
&aliaslen, pkt)) {
|
||||
verbose(VERB_ALGO, "synthesized CNAME "
|
||||
"too long");
|
||||
if(FLAGS_GET_RCODE(msg->flags) == LDNS_RCODE_YXDOMAIN) {
|
||||
prev = rrset;
|
||||
rrset = rrset->rrset_all_next;
|
||||
continue;
|
||||
}
|
||||
return 0;
|
||||
}
|
||||
cname_length++;
|
||||
@@ -634,6 +641,45 @@ scrub_normalize(sldns_buffer* pkt, struct msg_parse* msg,
|
||||
"RRset:", pkt, msg, prev, &rrset);
|
||||
continue;
|
||||
}
|
||||
/* If the NS set is a promiscuous NS set, scrub that
|
||||
* to remove potential for poisonous contents that
|
||||
* affects other names in the same zone. Remove
|
||||
* promiscuous NS sets in positive answers, that
|
||||
* thus have records in the answer section. Nodata
|
||||
* and nxdomain promiscuous NS sets have been removed
|
||||
* already. Since the NS rrset is scrubbed, its
|
||||
* address records are also not marked to be allowed
|
||||
* and are removed later. */
|
||||
if(FLAGS_GET_RCODE(msg->flags) == LDNS_RCODE_NOERROR &&
|
||||
msg->an_rrsets != 0 &&
|
||||
env->cfg->iter_scrub_promiscuous) {
|
||||
remove_rrset("normalize: removing promiscuous "
|
||||
"RRset:", pkt, msg, prev, &rrset);
|
||||
continue;
|
||||
}
|
||||
/* Also delete promiscuous NS for other RCODEs */
|
||||
if(FLAGS_GET_RCODE(msg->flags) != LDNS_RCODE_NOERROR
|
||||
&& env->cfg->iter_scrub_promiscuous) {
|
||||
remove_rrset("normalize: removing promiscuous "
|
||||
"RRset:", pkt, msg, prev, &rrset);
|
||||
continue;
|
||||
}
|
||||
/* Also delete promiscuous NS for NOERROR with nodata
|
||||
* for authoritative answers, not for delegations.
|
||||
* NOERROR with an_rrsets!=0 already handled.
|
||||
* Also NOERROR and soa_in_auth already handled.
|
||||
* NOERROR with an_rrsets==0, and not a referral.
|
||||
* referral is (NS not the zonename, noSOA).
|
||||
*/
|
||||
if(FLAGS_GET_RCODE(msg->flags) == LDNS_RCODE_NOERROR
|
||||
&& msg->an_rrsets == 0
|
||||
&& !(dname_pkt_compare(pkt, rrset->dname,
|
||||
zonename) != 0 && !soa_in_auth(msg))
|
||||
&& env->cfg->iter_scrub_promiscuous) {
|
||||
remove_rrset("normalize: removing promiscuous "
|
||||
"RRset:", pkt, msg, prev, &rrset);
|
||||
continue;
|
||||
}
|
||||
if(nsset == NULL) {
|
||||
nsset = rrset;
|
||||
} else {
|
||||
@@ -1044,7 +1090,8 @@ scrub_message(sldns_buffer* pkt, struct msg_parse* msg,
|
||||
/* this is not required for basic operation but is a forgery
|
||||
* resistance (security) feature */
|
||||
if((FLAGS_GET_RCODE(msg->flags) == LDNS_RCODE_NOERROR ||
|
||||
FLAGS_GET_RCODE(msg->flags) == LDNS_RCODE_NXDOMAIN) &&
|
||||
FLAGS_GET_RCODE(msg->flags) == LDNS_RCODE_NXDOMAIN ||
|
||||
FLAGS_GET_RCODE(msg->flags) == LDNS_RCODE_YXDOMAIN) &&
|
||||
msg->qdcount == 0)
|
||||
return 0;
|
||||
|
||||
@@ -1058,7 +1105,7 @@ scrub_message(sldns_buffer* pkt, struct msg_parse* msg,
|
||||
}
|
||||
|
||||
/* normalize the response, this cleans up the additional. */
|
||||
if(!scrub_normalize(pkt, msg, qinfo, region, env))
|
||||
if(!scrub_normalize(pkt, msg, qinfo, region, env, zonename))
|
||||
return 0;
|
||||
/* delete all out-of-zone information */
|
||||
if(!scrub_sanitize(pkt, msg, qinfo, zonename, env, ie, qstate))
|
||||
|
||||
Vendored
+1
@@ -5,6 +5,7 @@ server:
|
||||
fake-sha1: yes
|
||||
trust-anchor-signaling: no
|
||||
minimal-responses: no
|
||||
iter-scrub-promiscuous: no
|
||||
stub-zone:
|
||||
name: "."
|
||||
stub-addr: 193.0.14.129 # K.ROOT-SERVERS.NET.
|
||||
|
||||
Vendored
+1
@@ -5,6 +5,7 @@ server:
|
||||
fake-sha1: yes
|
||||
trust-anchor-signaling: no
|
||||
minimal-responses: no
|
||||
iter-scrub-promiscuous: no
|
||||
stub-zone:
|
||||
name: "."
|
||||
stub-addr: 193.0.14.129 # K.ROOT-SERVERS.NET.
|
||||
|
||||
Vendored
+1
@@ -5,6 +5,7 @@ server:
|
||||
fake-sha1: yes
|
||||
trust-anchor-signaling: no
|
||||
minimal-responses: no
|
||||
iter-scrub-promiscuous: no
|
||||
stub-zone:
|
||||
name: "."
|
||||
stub-addr: 193.0.14.129 # K.ROOT-SERVERS.NET.
|
||||
|
||||
Vendored
+1
@@ -5,6 +5,7 @@ server:
|
||||
fake-sha1: yes
|
||||
trust-anchor-signaling: no
|
||||
minimal-responses: no
|
||||
iter-scrub-promiscuous: no
|
||||
stub-zone:
|
||||
name: "."
|
||||
stub-addr: 193.0.14.129 # K.ROOT-SERVERS.NET.
|
||||
|
||||
Vendored
+1
@@ -8,6 +8,7 @@ server:
|
||||
fake-sha1: yes
|
||||
trust-anchor-signaling: no
|
||||
minimal-responses: no
|
||||
iter-scrub-promiscuous: no
|
||||
rrset-roundrobin: no
|
||||
|
||||
stub-zone:
|
||||
|
||||
Vendored
+1
@@ -8,6 +8,7 @@ server:
|
||||
fake-sha1: yes
|
||||
trust-anchor-signaling: no
|
||||
minimal-responses: no
|
||||
iter-scrub-promiscuous: no
|
||||
rrset-roundrobin: no
|
||||
|
||||
stub-zone:
|
||||
|
||||
Vendored
+1
@@ -5,6 +5,7 @@ server:
|
||||
qname-minimisation: "no"
|
||||
trust-anchor-signaling: no
|
||||
minimal-responses: no
|
||||
iter-scrub-promiscuous: no
|
||||
disable-edns-do: yes
|
||||
|
||||
stub-zone:
|
||||
|
||||
Vendored
+1
@@ -7,6 +7,7 @@ server:
|
||||
dns64-ignore-aaaa: ip6ignore.example.com
|
||||
dns64-ignore-aaaa: ip6only.example.com
|
||||
minimal-responses: no
|
||||
iter-scrub-promiscuous: no
|
||||
|
||||
stub-zone:
|
||||
name: "."
|
||||
|
||||
Vendored
+1
@@ -5,6 +5,7 @@ server:
|
||||
module-config: "dns64 iterator"
|
||||
dns64-prefix: 64:ff9b::0/96
|
||||
minimal-responses: no
|
||||
iter-scrub-promiscuous: no
|
||||
prefetch: yes
|
||||
|
||||
stub-zone:
|
||||
|
||||
Vendored
+1
@@ -3,6 +3,7 @@ server:
|
||||
target-fetch-policy: "0 0 0 0 0"
|
||||
qname-minimisation: "no"
|
||||
minimal-responses: no
|
||||
iter-scrub-promiscuous: no
|
||||
|
||||
stub-zone:
|
||||
name: "."
|
||||
|
||||
Vendored
+1
@@ -3,6 +3,7 @@ server:
|
||||
target-fetch-policy: "0 0 0 0 0"
|
||||
qname-minimisation: "no"
|
||||
minimal-responses: no
|
||||
iter-scrub-promiscuous: no
|
||||
|
||||
stub-zone:
|
||||
name: "."
|
||||
|
||||
Vendored
+1
@@ -2,6 +2,7 @@
|
||||
; config options go here.
|
||||
server:
|
||||
minimal-responses: no
|
||||
iter-scrub-promiscuous: no
|
||||
forward-zone: name: "." forward-addr: 216.0.0.1
|
||||
CONFIG_END
|
||||
|
||||
|
||||
@@ -10,6 +10,7 @@ server:
|
||||
username: ""
|
||||
do-not-query-localhost: no
|
||||
minimal-responses: no
|
||||
iter-scrub-promiscuous: no
|
||||
rrset-roundrobin: no
|
||||
forward-zone:
|
||||
name: "."
|
||||
|
||||
Vendored
+1
@@ -5,6 +5,7 @@ server:
|
||||
; is fine for that, not removed by minimal-responses.
|
||||
access-control: 127.0.0.1 allow_snoop
|
||||
minimal-responses: yes
|
||||
iter-scrub-promiscuous: no
|
||||
forward-zone: name: "." forward-addr: 216.0.0.1
|
||||
CONFIG_END
|
||||
|
||||
|
||||
+1
@@ -9,6 +9,7 @@ server:
|
||||
qname-minimisation: "no"
|
||||
# test that default value of harden-dnssec-stripped is still yes.
|
||||
fake-sha1: yes
|
||||
iter-scrub-promiscuous: no
|
||||
trust-anchor-signaling: no
|
||||
access-control: 127.0.0.1 allow_snoop
|
||||
module-config: "ipsecmod validator iterator"
|
||||
|
||||
Vendored
+1
@@ -11,6 +11,7 @@ server:
|
||||
ipsecmod-enabled: no
|
||||
qname-minimisation: "no"
|
||||
minimal-responses: no
|
||||
iter-scrub-promiscuous: no
|
||||
|
||||
stub-zone:
|
||||
name: "."
|
||||
|
||||
@@ -18,6 +18,7 @@ server:
|
||||
ipsecmod-ignore-bogus: yes
|
||||
qname-minimisation: "no"
|
||||
minimal-responses: no
|
||||
iter-scrub-promiscuous: no
|
||||
|
||||
stub-zone:
|
||||
name: "."
|
||||
|
||||
Vendored
+1
@@ -10,6 +10,7 @@ server:
|
||||
ipsecmod-max-ttl: 200
|
||||
qname-minimisation: "no"
|
||||
minimal-responses: no
|
||||
iter-scrub-promiscuous: no
|
||||
|
||||
stub-zone:
|
||||
name: "."
|
||||
|
||||
Vendored
+1
@@ -10,6 +10,7 @@ server:
|
||||
ipsecmod-max-ttl: 200
|
||||
qname-minimisation: "no"
|
||||
minimal-responses: no
|
||||
iter-scrub-promiscuous: no
|
||||
|
||||
stub-zone:
|
||||
name: "."
|
||||
|
||||
Vendored
+1
@@ -11,6 +11,7 @@ server:
|
||||
ipsecmod-whitelist: white.example.com
|
||||
qname-minimisation: "no"
|
||||
minimal-responses: no
|
||||
iter-scrub-promiscuous: no
|
||||
|
||||
stub-zone:
|
||||
name: "."
|
||||
|
||||
Vendored
+1
@@ -8,6 +8,7 @@ server:
|
||||
fake-sha1: yes
|
||||
trust-anchor-signaling: no
|
||||
minimal-responses: no
|
||||
iter-scrub-promiscuous: no
|
||||
|
||||
stub-zone:
|
||||
name: "."
|
||||
|
||||
Vendored
+1
@@ -4,6 +4,7 @@ server:
|
||||
target-fetch-policy: "0 0 0 0 0"
|
||||
qname-minimisation: "no"
|
||||
minimal-responses: no
|
||||
iter-scrub-promiscuous: no
|
||||
|
||||
stub-zone:
|
||||
name: "."
|
||||
|
||||
Vendored
+1
@@ -2,6 +2,7 @@
|
||||
server:
|
||||
target-fetch-policy: "0 0 0 0 0"
|
||||
minimal-responses: no
|
||||
iter-scrub-promiscuous: no
|
||||
|
||||
stub-zone:
|
||||
name: "."
|
||||
|
||||
+1
@@ -2,6 +2,7 @@
|
||||
server:
|
||||
target-fetch-policy: "0 0 0 0 0"
|
||||
minimal-responses: no
|
||||
iter-scrub-promiscuous: no
|
||||
|
||||
stub-zone:
|
||||
name: "."
|
||||
|
||||
Vendored
+1
@@ -8,6 +8,7 @@ server:
|
||||
fake-sha1: yes
|
||||
trust-anchor-signaling: no
|
||||
minimal-responses: no
|
||||
iter-scrub-promiscuous: no
|
||||
|
||||
stub-zone:
|
||||
name: "."
|
||||
|
||||
Vendored
+1
@@ -8,6 +8,7 @@ server:
|
||||
fake-sha1: yes
|
||||
trust-anchor-signaling: no
|
||||
minimal-responses: no
|
||||
iter-scrub-promiscuous: no
|
||||
|
||||
stub-zone:
|
||||
name: "."
|
||||
|
||||
Vendored
+1
@@ -2,6 +2,7 @@
|
||||
server:
|
||||
target-fetch-policy: "0 0 0 0 0"
|
||||
minimal-responses: no
|
||||
iter-scrub-promiscuous: no
|
||||
|
||||
stub-zone:
|
||||
name: "."
|
||||
|
||||
Vendored
+1
@@ -2,6 +2,7 @@
|
||||
server:
|
||||
target-fetch-policy: "0 0 0 0 0"
|
||||
minimal-responses: no
|
||||
iter-scrub-promiscuous: no
|
||||
|
||||
stub-zone:
|
||||
name: "."
|
||||
|
||||
Vendored
+1
@@ -2,6 +2,7 @@
|
||||
server:
|
||||
target-fetch-policy: "0 0 0 0 0"
|
||||
minimal-responses: no
|
||||
iter-scrub-promiscuous: no
|
||||
tcp-upstream: no
|
||||
#tls-upstream:no # same case but not testable in rpl.
|
||||
|
||||
|
||||
Vendored
+1
@@ -2,6 +2,7 @@
|
||||
server:
|
||||
target-fetch-policy: "0 0 0 0 0"
|
||||
minimal-responses: no
|
||||
iter-scrub-promiscuous: no
|
||||
|
||||
stub-zone:
|
||||
name: "."
|
||||
|
||||
Vendored
+1
@@ -2,6 +2,7 @@
|
||||
server:
|
||||
target-fetch-policy: "0 0 0 0 0"
|
||||
minimal-responses: no
|
||||
iter-scrub-promiscuous: no
|
||||
|
||||
stub-zone:
|
||||
name: "."
|
||||
|
||||
@@ -3,6 +3,7 @@ server:
|
||||
target-fetch-policy: "0 0 0 0 0"
|
||||
qname-minimisation: "no"
|
||||
minimal-responses: no
|
||||
iter-scrub-promiscuous: no
|
||||
|
||||
stub-zone:
|
||||
name: "."
|
||||
|
||||
Vendored
+1
@@ -3,6 +3,7 @@ server:
|
||||
target-fetch-policy: "0 0 0 0 0"
|
||||
qname-minimisation: "no"
|
||||
minimal-responses: no
|
||||
iter-scrub-promiscuous: no
|
||||
|
||||
stub-zone:
|
||||
name: "."
|
||||
|
||||
Vendored
+1
@@ -3,6 +3,7 @@ server:
|
||||
target-fetch-policy: "0 0 0 0 0"
|
||||
qname-minimisation: "no"
|
||||
minimal-responses: no
|
||||
iter-scrub-promiscuous: no
|
||||
discard-timeout: 86400
|
||||
|
||||
stub-zone:
|
||||
|
||||
Vendored
+1
@@ -4,6 +4,7 @@ server:
|
||||
target-fetch-policy: "0 0 0 0 0 "
|
||||
qname-minimisation: "no"
|
||||
minimal-responses: no
|
||||
iter-scrub-promiscuous: no
|
||||
stub-zone:
|
||||
name: "."
|
||||
stub-addr: 193.0.14.129 # K.ROOT-SERVERS.NET.
|
||||
|
||||
Vendored
+1
@@ -3,6 +3,7 @@ server:
|
||||
target-fetch-policy: "0 0 0 0 0"
|
||||
qname-minimisation: "no"
|
||||
minimal-responses: no
|
||||
iter-scrub-promiscuous: no
|
||||
|
||||
stub-zone:
|
||||
name: "."
|
||||
|
||||
Vendored
+1
@@ -4,6 +4,7 @@ server:
|
||||
target-fetch-policy: "0 0 0 0 0"
|
||||
qname-minimisation: "no"
|
||||
minimal-responses: no
|
||||
iter-scrub-promiscuous: no
|
||||
rrset-roundrobin: no
|
||||
|
||||
stub-zone:
|
||||
|
||||
Vendored
+1
@@ -2,6 +2,7 @@
|
||||
server:
|
||||
target-fetch-policy: "0 0 0 0 0"
|
||||
minimal-responses: no
|
||||
iter-scrub-promiscuous: no
|
||||
rrset-roundrobin: no
|
||||
|
||||
stub-zone:
|
||||
|
||||
Vendored
+1
@@ -4,6 +4,7 @@ server:
|
||||
qname-minimisation: "no"
|
||||
module-config: "iterator"
|
||||
minimal-responses: no
|
||||
iter-scrub-promiscuous: no
|
||||
|
||||
stub-zone:
|
||||
name: "."
|
||||
|
||||
Vendored
+1
@@ -3,6 +3,7 @@ server:
|
||||
target-fetch-policy: "3 2 1 0 0"
|
||||
qname-minimisation: "no"
|
||||
minimal-responses: no
|
||||
iter-scrub-promiscuous: no
|
||||
rrset-roundrobin: no
|
||||
|
||||
stub-zone:
|
||||
|
||||
Vendored
+1
@@ -4,6 +4,7 @@ server:
|
||||
target-fetch-policy: "0 0 0 0 0"
|
||||
qname-minimisation: "no"
|
||||
minimal-responses: no
|
||||
iter-scrub-promiscuous: no
|
||||
stub-zone:
|
||||
name: "."
|
||||
stub-addr: 193.0.14.129 # K.ROOT-SERVERS.NET.
|
||||
|
||||
Vendored
+1
@@ -8,6 +8,7 @@ server:
|
||||
access-control: 127.0.0.1 allow_snoop
|
||||
qname-minimisation: no
|
||||
minimal-responses: no
|
||||
iter-scrub-promiscuous: no
|
||||
rrset-roundrobin: no
|
||||
|
||||
stub-zone:
|
||||
|
||||
Vendored
+1
@@ -2,6 +2,7 @@
|
||||
server:
|
||||
target-fetch-policy: "0 0 0 0 0"
|
||||
minimal-responses: no
|
||||
iter-scrub-promiscuous: no
|
||||
|
||||
stub-zone:
|
||||
name: "."
|
||||
|
||||
Vendored
+1
@@ -2,6 +2,7 @@
|
||||
server:
|
||||
target-fetch-policy: "0 0 0 0 0"
|
||||
minimal-responses: no
|
||||
iter-scrub-promiscuous: no
|
||||
|
||||
stub-zone:
|
||||
name: "."
|
||||
|
||||
Vendored
+1
@@ -2,6 +2,7 @@
|
||||
server:
|
||||
target-fetch-policy: "0 0 0 0 0"
|
||||
minimal-responses: no
|
||||
iter-scrub-promiscuous: no
|
||||
|
||||
stub-zone:
|
||||
name: "."
|
||||
|
||||
Vendored
+1
@@ -3,6 +3,7 @@ server:
|
||||
target-fetch-policy: "0 0 0 0 0"
|
||||
qname-minimisation: "no"
|
||||
minimal-responses: no
|
||||
iter-scrub-promiscuous: no
|
||||
|
||||
stub-zone:
|
||||
name: "."
|
||||
|
||||
Vendored
+1
@@ -2,6 +2,7 @@
|
||||
server:
|
||||
target-fetch-policy: "0 0 0 0 0"
|
||||
minimal-responses: no
|
||||
iter-scrub-promiscuous: no
|
||||
|
||||
stub-zone:
|
||||
name: "."
|
||||
|
||||
Vendored
+1
@@ -2,6 +2,7 @@
|
||||
server:
|
||||
target-fetch-policy: "0 0 0 0 0"
|
||||
minimal-responses: no
|
||||
iter-scrub-promiscuous: no
|
||||
rrset-roundrobin: no
|
||||
|
||||
stub-zone:
|
||||
|
||||
Vendored
+1
@@ -2,6 +2,7 @@
|
||||
server:
|
||||
target-fetch-policy: "0 0 0 0 0"
|
||||
minimal-responses: no
|
||||
iter-scrub-promiscuous: no
|
||||
rrset-roundrobin: no
|
||||
|
||||
stub-zone:
|
||||
|
||||
Vendored
+1
@@ -2,6 +2,7 @@
|
||||
server:
|
||||
target-fetch-policy: "0 0 0 0 0"
|
||||
minimal-responses: no
|
||||
iter-scrub-promiscuous: no
|
||||
|
||||
stub-zone:
|
||||
name: "."
|
||||
|
||||
Vendored
+1
@@ -3,6 +3,7 @@ server:
|
||||
target-fetch-policy: "0 0 0 0 0"
|
||||
do-ip6: no
|
||||
minimal-responses: no
|
||||
iter-scrub-promiscuous: no
|
||||
|
||||
stub-zone:
|
||||
name: "."
|
||||
|
||||
Vendored
+1
@@ -4,6 +4,7 @@ server:
|
||||
qname-minimisation: "no"
|
||||
prefetch: "yes"
|
||||
minimal-responses: no
|
||||
iter-scrub-promiscuous: no
|
||||
|
||||
stub-zone:
|
||||
name: "."
|
||||
|
||||
Vendored
+1
@@ -3,6 +3,7 @@ server:
|
||||
target-fetch-policy: "0 0 0 0 0"
|
||||
prefetch: "yes"
|
||||
minimal-responses: no
|
||||
iter-scrub-promiscuous: no
|
||||
|
||||
stub-zone:
|
||||
name: "."
|
||||
|
||||
Vendored
+1
@@ -3,6 +3,7 @@ server:
|
||||
target-fetch-policy: "0 0 0 0 0"
|
||||
prefetch: "yes"
|
||||
minimal-responses: no
|
||||
iter-scrub-promiscuous: no
|
||||
|
||||
stub-zone:
|
||||
name: "."
|
||||
|
||||
Vendored
+1
@@ -4,6 +4,7 @@ server:
|
||||
qname-minimisation: "no"
|
||||
prefetch: "yes"
|
||||
minimal-responses: no
|
||||
iter-scrub-promiscuous: no
|
||||
|
||||
stub-zone:
|
||||
name: "."
|
||||
|
||||
Vendored
+1
@@ -3,6 +3,7 @@ server:
|
||||
target-fetch-policy: "0 0 0 0 0"
|
||||
prefetch: "yes"
|
||||
minimal-responses: no
|
||||
iter-scrub-promiscuous: no
|
||||
|
||||
stub-zone:
|
||||
name: "."
|
||||
|
||||
Vendored
+1
@@ -4,6 +4,7 @@ server:
|
||||
qname-minimisation: "no"
|
||||
prefetch: "yes"
|
||||
minimal-responses: no
|
||||
iter-scrub-promiscuous: no
|
||||
|
||||
stub-zone:
|
||||
name: "."
|
||||
|
||||
Vendored
+1
@@ -8,6 +8,7 @@ server:
|
||||
fake-sha1: yes
|
||||
trust-anchor-signaling: no
|
||||
minimal-responses: no
|
||||
iter-scrub-promiscuous: no
|
||||
|
||||
stub-zone:
|
||||
name: "."
|
||||
|
||||
Vendored
+1
@@ -3,6 +3,7 @@ server:
|
||||
target-fetch-policy: "0 0 0 0 0"
|
||||
qname-minimisation: "no"
|
||||
minimal-responses: no
|
||||
iter-scrub-promiscuous: no
|
||||
|
||||
private-address: 10.0.0.0/8
|
||||
private-address: 172.16.0.0/12
|
||||
|
||||
Vendored
+1
@@ -2,6 +2,7 @@
|
||||
server:
|
||||
target-fetch-policy: "0 0 0 0 0"
|
||||
minimal-responses: no
|
||||
iter-scrub-promiscuous: no
|
||||
rrset-roundrobin: no
|
||||
|
||||
stub-zone:
|
||||
|
||||
Vendored
+1
@@ -3,6 +3,7 @@ server:
|
||||
target-fetch-policy: "0 0 0 0 0"
|
||||
qname-minimisation: "no"
|
||||
minimal-responses: no
|
||||
iter-scrub-promiscuous: no
|
||||
rrset-roundrobin: no
|
||||
|
||||
stub-zone:
|
||||
|
||||
Vendored
+1
@@ -2,6 +2,7 @@
|
||||
server:
|
||||
target-fetch-policy: "0 0 0 0 0"
|
||||
minimal-responses: no
|
||||
iter-scrub-promiscuous: no
|
||||
rrset-roundrobin: no
|
||||
|
||||
stub-zone:
|
||||
|
||||
Vendored
+1
@@ -3,6 +3,7 @@ server:
|
||||
target-fetch-policy: "0 0 0 0 0"
|
||||
qname-minimisation: "no"
|
||||
minimal-responses: no
|
||||
iter-scrub-promiscuous: no
|
||||
|
||||
stub-zone:
|
||||
name: "."
|
||||
|
||||
Vendored
+1
@@ -3,6 +3,7 @@ server:
|
||||
target-fetch-policy: "0 0 0 0 0"
|
||||
qname-minimisation: "no"
|
||||
minimal-responses: no
|
||||
iter-scrub-promiscuous: no
|
||||
|
||||
stub-zone:
|
||||
name: "."
|
||||
|
||||
Vendored
+1
@@ -2,6 +2,7 @@
|
||||
server:
|
||||
target-fetch-policy: "0 0 0 0 0"
|
||||
minimal-responses: no
|
||||
iter-scrub-promiscuous: no
|
||||
|
||||
stub-zone:
|
||||
name: "."
|
||||
|
||||
+1
@@ -3,6 +3,7 @@ server:
|
||||
target-fetch-policy: "0 0 0 0 0"
|
||||
qname-minimisation: yes
|
||||
minimal-responses: no
|
||||
iter-scrub-promiscuous: no
|
||||
|
||||
stub-zone:
|
||||
name: "."
|
||||
|
||||
+1
@@ -3,6 +3,7 @@ server:
|
||||
target-fetch-policy: "0 0 0 0 0"
|
||||
qname-minimisation: yes
|
||||
minimal-responses: no
|
||||
iter-scrub-promiscuous: no
|
||||
|
||||
stub-zone:
|
||||
name: "."
|
||||
|
||||
+1
@@ -3,6 +3,7 @@ server:
|
||||
target-fetch-policy: "0 0 0 0 0"
|
||||
qname-minimisation: yes
|
||||
minimal-responses: no
|
||||
iter-scrub-promiscuous: no
|
||||
|
||||
stub-zone:
|
||||
name: "."
|
||||
|
||||
Vendored
+1
@@ -4,6 +4,7 @@ server:
|
||||
target-fetch-policy: "0 0 0 0 0"
|
||||
qname-minimisation: "no"
|
||||
minimal-responses: no
|
||||
iter-scrub-promiscuous: no
|
||||
|
||||
stub-zone:
|
||||
name: "."
|
||||
|
||||
Vendored
+1
@@ -4,6 +4,7 @@ server:
|
||||
target-fetch-policy: "0 0 0 0 0"
|
||||
qname-minimisation: "no"
|
||||
minimal-responses: no
|
||||
iter-scrub-promiscuous: no
|
||||
|
||||
stub-zone:
|
||||
name: "."
|
||||
|
||||
Vendored
+1
@@ -8,6 +8,7 @@ server:
|
||||
fake-sha1: yes
|
||||
trust-anchor-signaling: no
|
||||
minimal-responses: no
|
||||
iter-scrub-promiscuous: no
|
||||
|
||||
stub-zone:
|
||||
name: "."
|
||||
|
||||
Vendored
+1
@@ -8,6 +8,7 @@ server:
|
||||
fake-sha1: yes
|
||||
trust-anchor-signaling: no
|
||||
minimal-responses: no
|
||||
iter-scrub-promiscuous: no
|
||||
|
||||
stub-zone:
|
||||
name: "."
|
||||
|
||||
Vendored
+457
@@ -0,0 +1,457 @@
|
||||
; config options
|
||||
server:
|
||||
target-fetch-policy: "0 0 0 0 0"
|
||||
qname-minimisation: no
|
||||
iter-scrub-promiscuous: yes
|
||||
|
||||
stub-zone:
|
||||
name: "."
|
||||
stub-addr: 1.2.3.0 # ns.root
|
||||
CONFIG_END
|
||||
|
||||
SCENARIO_BEGIN Test iterator with scrub of promiscuous records
|
||||
; The test queries receive spoofed answers. The check queries see if
|
||||
; the record is returned by the original server or by a spoofed source.
|
||||
; The test domains are pollute1.mesa, pollute2.mesa and pollute3.mesa.
|
||||
; The spoofed contents are ns.attacker.mesa and its IPs 5.6.7.8 and 5.6.7.9.
|
||||
; The pollute1.mesa NS, ns.pollute2.mesa A, and test3.atkr.pollute3.mesa NS
|
||||
; with ns.pollute3.mesa A records are tested for cache placement.
|
||||
; pollute4.mesa uses YXDOMAIN.
|
||||
|
||||
; ns.root
|
||||
RANGE_BEGIN 0 400
|
||||
ADDRESS 1.2.3.0
|
||||
ENTRY_BEGIN
|
||||
MATCH opcode qtype qname
|
||||
ADJUST copy_id
|
||||
REPLY QR AA NOERROR
|
||||
SECTION QUESTION
|
||||
. IN NS
|
||||
SECTION ANSWER
|
||||
. IN NS NS.ROOT.
|
||||
SECTION ADDITIONAL
|
||||
NS.ROOT. IN A 1.2.3.0
|
||||
ENTRY_END
|
||||
|
||||
ENTRY_BEGIN
|
||||
MATCH opcode subdomain
|
||||
ADJUST copy_id copy_query
|
||||
REPLY QR NOERROR
|
||||
SECTION QUESTION
|
||||
mesa. IN NS
|
||||
SECTION AUTHORITY
|
||||
mesa. IN NS ns.mesa.
|
||||
SECTION ADDITIONAL
|
||||
ns.mesa. IN A 1.2.7.7
|
||||
ENTRY_END
|
||||
RANGE_END
|
||||
|
||||
; ns.mesa
|
||||
RANGE_BEGIN 0 400
|
||||
ADDRESS 1.2.7.7
|
||||
ENTRY_BEGIN
|
||||
MATCH opcode subdomain
|
||||
ADJUST copy_id copy_query
|
||||
REPLY QR NOERROR
|
||||
SECTION QUESTION
|
||||
pollute1.mesa. IN NS
|
||||
SECTION AUTHORITY
|
||||
pollute1.mesa. IN NS ns.pollute1.mesa.
|
||||
SECTION ADDITIONAL
|
||||
ns.pollute1.mesa. IN A 1.2.4.1
|
||||
ENTRY_END
|
||||
|
||||
ENTRY_BEGIN
|
||||
MATCH opcode subdomain
|
||||
ADJUST copy_id copy_query
|
||||
REPLY QR NOERROR
|
||||
SECTION QUESTION
|
||||
pollute2.mesa. IN NS
|
||||
SECTION AUTHORITY
|
||||
pollute2.mesa. IN NS ns.pollute2.mesa.
|
||||
SECTION ADDITIONAL
|
||||
ns.pollute2.mesa. IN A 1.2.4.2
|
||||
ENTRY_END
|
||||
|
||||
ENTRY_BEGIN
|
||||
MATCH opcode subdomain
|
||||
ADJUST copy_id copy_query
|
||||
REPLY QR NOERROR
|
||||
SECTION QUESTION
|
||||
pollute3.mesa. IN NS
|
||||
SECTION AUTHORITY
|
||||
pollute3.mesa. IN NS ns.pollute3.mesa.
|
||||
SECTION ADDITIONAL
|
||||
ns.pollute3.mesa. IN A 1.2.4.3
|
||||
ENTRY_END
|
||||
|
||||
ENTRY_BEGIN
|
||||
MATCH opcode subdomain
|
||||
ADJUST copy_id copy_query
|
||||
REPLY QR NOERROR
|
||||
SECTION QUESTION
|
||||
pollute4.mesa. IN NS
|
||||
SECTION AUTHORITY
|
||||
pollute4.mesa. IN NS ns.pollute4.mesa.
|
||||
SECTION ADDITIONAL
|
||||
ns.pollute4.mesa. IN A 1.2.4.4
|
||||
ENTRY_END
|
||||
|
||||
ENTRY_BEGIN
|
||||
MATCH opcode subdomain
|
||||
ADJUST copy_id copy_query
|
||||
REPLY QR NOERROR
|
||||
SECTION QUESTION
|
||||
attacker.mesa. IN NS
|
||||
SECTION AUTHORITY
|
||||
attacker.mesa. IN NS ns.attacker.mesa.
|
||||
SECTION ADDITIONAL
|
||||
ns.attacker.mesa. IN A 5.6.7.8
|
||||
ENTRY_END
|
||||
RANGE_END
|
||||
|
||||
; ns.pollute1.mesa
|
||||
RANGE_BEGIN 0 400
|
||||
ADDRESS 1.2.4.1
|
||||
|
||||
; This is the spoofed answer that is returned.
|
||||
ENTRY_BEGIN
|
||||
MATCH opcode qtype qname
|
||||
ADJUST copy_id
|
||||
REPLY QR AA NOERROR
|
||||
SECTION QUESTION
|
||||
test1.atkr.pollute1.mesa. IN A
|
||||
SECTION ANSWER
|
||||
test1.atkr.pollute1.mesa. 86400 IN A 1.2.3.4
|
||||
SECTION AUTHORITY
|
||||
pollute1.mesa. 86400 IN NS ns.attacker.mesa.
|
||||
ENTRY_END
|
||||
|
||||
; correct answer for the check query.
|
||||
ENTRY_BEGIN
|
||||
MATCH opcode qtype qname
|
||||
ADJUST copy_id
|
||||
REPLY QR AA NOERROR
|
||||
SECTION QUESTION
|
||||
check.pollute1.mesa. IN A
|
||||
SECTION ANSWER
|
||||
check.pollute1.mesa. IN A 1.8.9.1
|
||||
ENTRY_END
|
||||
RANGE_END
|
||||
|
||||
; ns.pollute2.mesa
|
||||
RANGE_BEGIN 0 400
|
||||
ADDRESS 1.2.4.2
|
||||
|
||||
; This is the spoofed answer that is returned.
|
||||
ENTRY_BEGIN
|
||||
MATCH opcode qtype qname
|
||||
ADJUST copy_id
|
||||
REPLY QR AA NOERROR
|
||||
SECTION QUESTION
|
||||
test2.atkr.pollute2.mesa. IN A
|
||||
SECTION ANSWER
|
||||
test2.atkr.pollute2.mesa. 86400 IN A 1.2.3.4
|
||||
SECTION AUTHORITY
|
||||
pollute2.mesa. 86400 IN NS ns.pollute2.mesa.
|
||||
SECTION ADDITIONAL
|
||||
ns.pollute2.mesa. 86400 IN A 5.6.7.8
|
||||
ENTRY_END
|
||||
|
||||
; correct answer for the check query.
|
||||
ENTRY_BEGIN
|
||||
MATCH opcode qtype qname
|
||||
ADJUST copy_id
|
||||
REPLY QR AA NOERROR
|
||||
SECTION QUESTION
|
||||
check.pollute2.mesa. IN A
|
||||
SECTION ANSWER
|
||||
check.pollute2.mesa. IN A 1.8.9.2
|
||||
ENTRY_END
|
||||
RANGE_END
|
||||
|
||||
; ns.pollute3.mesa
|
||||
RANGE_BEGIN 0 400
|
||||
ADDRESS 1.2.4.3
|
||||
|
||||
; This is the spoofed answer that is returned.
|
||||
ENTRY_BEGIN
|
||||
MATCH opcode qtype qname
|
||||
ADJUST copy_id
|
||||
REPLY QR AA NOERROR
|
||||
SECTION QUESTION
|
||||
test3.atkr.pollute3.mesa. IN A
|
||||
SECTION ANSWER
|
||||
test3.atkr.pollute3.mesa. 86400 IN A 1.2.3.4
|
||||
SECTION AUTHORITY
|
||||
test3.atkr.pollute3.mesa. 86400 IN NS ns.pollute3.mesa.
|
||||
SECTION ADDITIONAL
|
||||
ns.pollute3.mesa. 86400 IN A 5.6.7.8
|
||||
ENTRY_END
|
||||
|
||||
; correct answer for the check query.
|
||||
ENTRY_BEGIN
|
||||
MATCH opcode qtype qname
|
||||
ADJUST copy_id
|
||||
REPLY QR AA NOERROR
|
||||
SECTION QUESTION
|
||||
check.pollute3.mesa. IN A
|
||||
SECTION ANSWER
|
||||
check.pollute3.mesa. IN A 1.8.9.3
|
||||
ENTRY_END
|
||||
RANGE_END
|
||||
|
||||
; ns.pollute4.mesa
|
||||
RANGE_BEGIN 0 400
|
||||
ADDRESS 1.2.4.4
|
||||
|
||||
; This is the spoofed answer that is returned.
|
||||
ENTRY_BEGIN
|
||||
MATCH opcode qtype qname
|
||||
ADJUST copy_id
|
||||
REPLY QR AA YXDOMAIN
|
||||
SECTION QUESTION
|
||||
test4.atkr.pollute4.mesa. IN A
|
||||
SECTION ANSWER
|
||||
test4.atkr.pollute4.mesa. 86400 IN A 1.2.3.4
|
||||
SECTION AUTHORITY
|
||||
pollute4.mesa. 86400 IN NS ns.attacker.mesa.
|
||||
ENTRY_END
|
||||
|
||||
; correct answer for the check query.
|
||||
ENTRY_BEGIN
|
||||
MATCH opcode qtype qname
|
||||
ADJUST copy_id
|
||||
REPLY QR AA NOERROR
|
||||
SECTION QUESTION
|
||||
check.pollute4.mesa. IN A
|
||||
SECTION ANSWER
|
||||
check.pollute4.mesa. IN A 1.8.9.4
|
||||
ENTRY_END
|
||||
RANGE_END
|
||||
|
||||
; ns.attacker.mesa
|
||||
RANGE_BEGIN 0 400
|
||||
ADDRESS 5.6.7.8
|
||||
|
||||
ENTRY_BEGIN
|
||||
MATCH opcode qtype qname
|
||||
ADJUST copy_id
|
||||
REPLY QR AA NOERROR
|
||||
SECTION QUESTION
|
||||
ns.attacker.mesa. IN A
|
||||
SECTION ANSWER
|
||||
ns.attacker.mesa. 86400 IN A 5.6.7.8
|
||||
ENTRY_END
|
||||
|
||||
ENTRY_BEGIN
|
||||
MATCH opcode qtype qname
|
||||
ADJUST copy_id
|
||||
REPLY QR AA NOERROR
|
||||
SECTION QUESTION
|
||||
ns.attacker.mesa. IN AAAA
|
||||
SECTION AUTHORITY
|
||||
attacker.mesa. 3600 IN SOA ns.attacker.mesa. root.attacker.mesa. 4 7200 3600 604800 3600
|
||||
ENTRY_END
|
||||
|
||||
ENTRY_BEGIN
|
||||
MATCH opcode qtype qname
|
||||
ADJUST copy_id
|
||||
REPLY QR AA NOERROR
|
||||
SECTION QUESTION
|
||||
ns.attacker.mesa. IN A
|
||||
SECTION ANSWER
|
||||
ns.attacker.mesa. 86400 IN A 5.6.7.8
|
||||
ENTRY_END
|
||||
|
||||
ENTRY_BEGIN
|
||||
MATCH opcode qtype qname
|
||||
ADJUST copy_id
|
||||
REPLY QR AA NOERROR
|
||||
SECTION QUESTION
|
||||
check.pollute1.mesa. IN A
|
||||
SECTION ANSWER
|
||||
check.pollute1.mesa. 86400 IN A 5.6.7.9
|
||||
ENTRY_END
|
||||
|
||||
ENTRY_BEGIN
|
||||
MATCH opcode qtype qname
|
||||
ADJUST copy_id
|
||||
REPLY QR AA NOERROR
|
||||
SECTION QUESTION
|
||||
check.pollute2.mesa. IN A
|
||||
SECTION ANSWER
|
||||
check.pollute2.mesa. 86400 IN A 5.6.7.9
|
||||
ENTRY_END
|
||||
|
||||
ENTRY_BEGIN
|
||||
MATCH opcode qtype qname
|
||||
ADJUST copy_id
|
||||
REPLY QR AA NOERROR
|
||||
SECTION QUESTION
|
||||
check.pollute3.mesa. IN A
|
||||
SECTION ANSWER
|
||||
check.pollute3.mesa. 86400 IN A 5.6.7.9
|
||||
ENTRY_END
|
||||
RANGE_END
|
||||
|
||||
; Test query 1
|
||||
STEP 1 QUERY
|
||||
ENTRY_BEGIN
|
||||
REPLY RD
|
||||
SECTION QUESTION
|
||||
test1.atkr.pollute1.mesa. IN A
|
||||
ENTRY_END
|
||||
|
||||
STEP 10 CHECK_ANSWER
|
||||
ENTRY_BEGIN
|
||||
MATCH all
|
||||
REPLY QR RD RA NOERROR
|
||||
SECTION QUESTION
|
||||
test1.atkr.pollute1.mesa. IN A
|
||||
SECTION ANSWER
|
||||
test1.atkr.pollute1.mesa. 86400 IN A 1.2.3.4
|
||||
ENTRY_END
|
||||
|
||||
; Test query 2
|
||||
STEP 20 QUERY
|
||||
ENTRY_BEGIN
|
||||
REPLY RD
|
||||
SECTION QUESTION
|
||||
test2.atkr.pollute2.mesa. IN A
|
||||
ENTRY_END
|
||||
|
||||
STEP 30 CHECK_ANSWER
|
||||
ENTRY_BEGIN
|
||||
MATCH all
|
||||
REPLY QR RD RA NOERROR
|
||||
SECTION QUESTION
|
||||
test2.atkr.pollute2.mesa. IN A
|
||||
SECTION ANSWER
|
||||
test2.atkr.pollute2.mesa. 86400 IN A 1.2.3.4
|
||||
ENTRY_END
|
||||
|
||||
; Test query 3
|
||||
STEP 40 QUERY
|
||||
ENTRY_BEGIN
|
||||
REPLY RD
|
||||
SECTION QUESTION
|
||||
test3.atkr.pollute3.mesa. IN A
|
||||
ENTRY_END
|
||||
|
||||
STEP 50 CHECK_ANSWER
|
||||
ENTRY_BEGIN
|
||||
MATCH all
|
||||
REPLY QR RD RA NOERROR
|
||||
SECTION QUESTION
|
||||
test3.atkr.pollute3.mesa. IN A
|
||||
SECTION ANSWER
|
||||
test3.atkr.pollute3.mesa. 86400 IN A 1.2.3.4
|
||||
ENTRY_END
|
||||
|
||||
; Check the cache contents, for query 1.
|
||||
STEP 60 QUERY
|
||||
ENTRY_BEGIN
|
||||
REPLY RD
|
||||
SECTION QUESTION
|
||||
check.pollute1.mesa. IN A
|
||||
ENTRY_END
|
||||
|
||||
STEP 70 CHECK_ANSWER
|
||||
ENTRY_BEGIN
|
||||
MATCH all
|
||||
REPLY QR RD RA NOERROR
|
||||
SECTION QUESTION
|
||||
check.pollute1.mesa. IN A
|
||||
SECTION ANSWER
|
||||
; good answer
|
||||
check.pollute1.mesa. IN A 1.8.9.1
|
||||
; bad answer
|
||||
;check.pollute1.mesa. IN A 5.6.7.9
|
||||
ENTRY_END
|
||||
|
||||
; Check the cache contents, for query 2.
|
||||
STEP 80 QUERY
|
||||
ENTRY_BEGIN
|
||||
REPLY RD
|
||||
SECTION QUESTION
|
||||
check.pollute2.mesa. IN A
|
||||
ENTRY_END
|
||||
|
||||
STEP 90 CHECK_ANSWER
|
||||
ENTRY_BEGIN
|
||||
MATCH all
|
||||
REPLY QR RD RA NOERROR
|
||||
SECTION QUESTION
|
||||
check.pollute2.mesa. IN A
|
||||
SECTION ANSWER
|
||||
; good answer
|
||||
check.pollute2.mesa. IN A 1.8.9.2
|
||||
; bad answer
|
||||
;check.pollute2.mesa. IN A 5.6.7.9
|
||||
ENTRY_END
|
||||
|
||||
; Check the cache contents, for query 3.
|
||||
STEP 100 QUERY
|
||||
ENTRY_BEGIN
|
||||
REPLY RD
|
||||
SECTION QUESTION
|
||||
check.pollute3.mesa. IN A
|
||||
ENTRY_END
|
||||
|
||||
STEP 110 CHECK_ANSWER
|
||||
ENTRY_BEGIN
|
||||
MATCH all
|
||||
REPLY QR RD RA NOERROR
|
||||
SECTION QUESTION
|
||||
check.pollute3.mesa. IN A
|
||||
SECTION ANSWER
|
||||
; good answer
|
||||
check.pollute3.mesa. IN A 1.8.9.3
|
||||
; bad answer
|
||||
;check.pollute3.mesa. IN A 5.6.7.9
|
||||
ENTRY_END
|
||||
|
||||
; Test query 4
|
||||
STEP 120 QUERY
|
||||
ENTRY_BEGIN
|
||||
REPLY RD
|
||||
SECTION QUESTION
|
||||
test4.atkr.pollute4.mesa. IN A
|
||||
ENTRY_END
|
||||
|
||||
STEP 130 CHECK_ANSWER
|
||||
ENTRY_BEGIN
|
||||
MATCH all
|
||||
REPLY QR RD RA YXDOMAIN
|
||||
SECTION QUESTION
|
||||
test4.atkr.pollute4.mesa. IN A
|
||||
SECTION ANSWER
|
||||
test4.atkr.pollute4.mesa. 86400 IN A 1.2.3.4
|
||||
SECTION AUTHORITY
|
||||
; removed record
|
||||
;pollute4.mesa. 0 IN NS ns.attacker.mesa.
|
||||
ENTRY_END
|
||||
|
||||
; Check the cache contents, for query 4.
|
||||
STEP 140 QUERY
|
||||
ENTRY_BEGIN
|
||||
REPLY RD
|
||||
SECTION QUESTION
|
||||
check.pollute4.mesa. IN A
|
||||
ENTRY_END
|
||||
|
||||
STEP 150 CHECK_ANSWER
|
||||
ENTRY_BEGIN
|
||||
MATCH all
|
||||
REPLY QR RD RA NOERROR
|
||||
SECTION QUESTION
|
||||
check.pollute4.mesa. IN A
|
||||
SECTION ANSWER
|
||||
; good answer
|
||||
check.pollute4.mesa. IN A 1.8.9.4
|
||||
; bad answer
|
||||
;check.pollute4.mesa. IN A 5.6.7.9
|
||||
ENTRY_END
|
||||
|
||||
SCENARIO_END
|
||||
Vendored
+1
@@ -3,6 +3,7 @@ server:
|
||||
target-fetch-policy: "0 0 0 0 0"
|
||||
qname-minimisation: "no"
|
||||
minimal-responses: no
|
||||
iter-scrub-promiscuous: no
|
||||
rrset-roundrobin: no
|
||||
ede: yes
|
||||
|
||||
|
||||
Vendored
+1
@@ -2,6 +2,7 @@
|
||||
server:
|
||||
target-fetch-policy: "0 0 0 0 0"
|
||||
minimal-responses: no
|
||||
iter-scrub-promiscuous: no
|
||||
|
||||
stub-zone:
|
||||
name: "."
|
||||
|
||||
Vendored
+1
@@ -2,6 +2,7 @@
|
||||
server:
|
||||
target-fetch-policy: "0 0 0 0 0"
|
||||
minimal-responses: no
|
||||
iter-scrub-promiscuous: no
|
||||
|
||||
stub-zone:
|
||||
name: "."
|
||||
|
||||
Vendored
+1
@@ -2,6 +2,7 @@
|
||||
server:
|
||||
target-fetch-policy: "0 0 0 0 0"
|
||||
minimal-responses: no
|
||||
iter-scrub-promiscuous: no
|
||||
|
||||
stub-zone:
|
||||
name: "."
|
||||
|
||||
Vendored
+1
@@ -3,6 +3,7 @@ server:
|
||||
target-fetch-policy: "0 0 0 0 0"
|
||||
qname-minimisation: "no"
|
||||
minimal-responses: no
|
||||
iter-scrub-promiscuous: no
|
||||
|
||||
stub-zone:
|
||||
name: "."
|
||||
|
||||
Vendored
+1
@@ -3,6 +3,7 @@ server:
|
||||
target-fetch-policy: "0 0 0 0 0"
|
||||
qname-minimisation: no
|
||||
minimal-responses: no
|
||||
iter-scrub-promiscuous: no
|
||||
do-ip6: no
|
||||
harden-unverified-glue: yes
|
||||
stub-zone:
|
||||
|
||||
+24
-6
@@ -3,13 +3,31 @@ $ORIGIN example.com.
|
||||
$TTL 3600
|
||||
|
||||
ENTRY_BEGIN
|
||||
MATCH opcode qtype
|
||||
MATCH opcode qname qtype
|
||||
REPLY QR AA NOERROR
|
||||
ADJUST copy_id copy_query
|
||||
ADJUST copy_id
|
||||
SECTION QUESTION
|
||||
wild IN A
|
||||
www1 IN A
|
||||
SECTION ANSWER
|
||||
wild IN A 10.20.30.40
|
||||
SECTION AUTHORITY
|
||||
example.com. IN NS ns.example.com.
|
||||
www1 IN A 1.1.1.1
|
||||
ENTRY_END
|
||||
|
||||
ENTRY_BEGIN
|
||||
MATCH opcode qname qtype
|
||||
REPLY QR AA NOERROR
|
||||
ADJUST copy_id
|
||||
SECTION QUESTION
|
||||
www2 IN A
|
||||
SECTION ANSWER
|
||||
www2 IN A 2.2.2.2
|
||||
ENTRY_END
|
||||
|
||||
ENTRY_BEGIN
|
||||
MATCH opcode qname qtype
|
||||
REPLY QR AA NOERROR
|
||||
ADJUST copy_id
|
||||
SECTION QUESTION
|
||||
www3 IN A
|
||||
SECTION ANSWER
|
||||
www3 IN A 3.3.3.3
|
||||
ENTRY_END
|
||||
|
||||
Vendored
+1
@@ -2,6 +2,7 @@
|
||||
; config options go here.
|
||||
server:
|
||||
minimal-responses: no
|
||||
iter-scrub-promiscuous: no
|
||||
forward-zone: name: "." forward-addr: 216.0.0.1
|
||||
CONFIG_END
|
||||
|
||||
|
||||
Vendored
+1
@@ -2,6 +2,7 @@
|
||||
; config options go here.
|
||||
server:
|
||||
minimal-responses: no
|
||||
iter-scrub-promiscuous: no
|
||||
forward-zone: name: "." forward-addr: 216.0.0.1
|
||||
CONFIG_END
|
||||
|
||||
|
||||
Vendored
+1
@@ -2,6 +2,7 @@
|
||||
; config options go here.
|
||||
server:
|
||||
minimal-responses: no
|
||||
iter-scrub-promiscuous: no
|
||||
rrset-roundrobin: no
|
||||
forward-zone: name: "." forward-addr: 216.0.0.1
|
||||
CONFIG_END
|
||||
|
||||
Vendored
+1
@@ -1,5 +1,6 @@
|
||||
server:
|
||||
minimal-responses: no
|
||||
iter-scrub-promiscuous: no
|
||||
serve-expired: yes
|
||||
# The value does not matter, we will not simulate delay.
|
||||
# We do not want only serve-expired because fetches from that
|
||||
|
||||
Vendored
+1
@@ -3,6 +3,7 @@ server:
|
||||
module-config: "validator iterator"
|
||||
qname-minimisation: "no"
|
||||
minimal-responses: no
|
||||
iter-scrub-promiscuous: no
|
||||
serve-expired: yes
|
||||
serve-expired-client-timeout: 0
|
||||
access-control: 127.0.0.1/32 allow_snoop
|
||||
|
||||
+1
@@ -3,6 +3,7 @@ server:
|
||||
module-config: "validator iterator"
|
||||
qname-minimisation: "no"
|
||||
minimal-responses: no
|
||||
iter-scrub-promiscuous: no
|
||||
serve-expired: yes
|
||||
serve-expired-client-timeout: 0
|
||||
ede: yes
|
||||
|
||||
+1
@@ -3,6 +3,7 @@ server:
|
||||
module-config: "validator iterator"
|
||||
qname-minimisation: "no"
|
||||
minimal-responses: no
|
||||
iter-scrub-promiscuous: no
|
||||
serve-expired: yes
|
||||
serve-expired-client-timeout: 0
|
||||
ede: yes
|
||||
|
||||
+1
@@ -3,6 +3,7 @@ server:
|
||||
module-config: "validator iterator"
|
||||
qname-minimisation: "no"
|
||||
minimal-responses: no
|
||||
iter-scrub-promiscuous: no
|
||||
serve-expired: yes
|
||||
serve-expired-client-timeout: 0
|
||||
ede: yes
|
||||
|
||||
+1
@@ -3,6 +3,7 @@ server:
|
||||
module-config: "validator iterator"
|
||||
qname-minimisation: "no"
|
||||
minimal-responses: no
|
||||
iter-scrub-promiscuous: no
|
||||
serve-expired: yes
|
||||
serve-expired-client-timeout: 0
|
||||
serve-expired-reply-ttl: 123
|
||||
|
||||
+1
@@ -3,6 +3,7 @@ server:
|
||||
module-config: "validator iterator"
|
||||
qname-minimisation: "no"
|
||||
minimal-responses: no
|
||||
iter-scrub-promiscuous: no
|
||||
serve-expired: yes
|
||||
serve-expired-client-timeout: 1
|
||||
serve-expired-reply-ttl: 123
|
||||
|
||||
@@ -3,6 +3,7 @@ server:
|
||||
module-config: "validator iterator"
|
||||
qname-minimisation: "no"
|
||||
minimal-responses: no
|
||||
iter-scrub-promiscuous: no
|
||||
serve-expired: yes
|
||||
serve-expired-client-timeout: 1
|
||||
serve-expired-reply-ttl: 123
|
||||
|
||||
Some files were not shown because too many files have changed in this diff Show More
Reference in New Issue
Block a user