今天发现我校 DNS 递归服务器出现大量解析异常, 分析发现是从 v6 解析时 NS 记录被污染了
从国际线路解析出现了污染
$ dig AAAA @2001:4860:4860::8888 n3390.ns.yunjiasu.com
; <<>> DiG 9.9.4-RedHat-9.9.4-51.el7 <<>> AAAA @2001:4860:4860::8888 n3390.ns.yunjiasu.com
; (1 server found)
;; global options: +cmd
;; Got answer:
;; ->>HEADER<<- opcode: QUERY, status: NOERROR, id: 56553
;; flags: qr rd ra; QUERY: 1, ANSWER: 1, AUTHORITY: 0, ADDITIONAL: 0
;; QUESTION SECTION:
;n3390.ns.yunjiasu.com. IN AAAA
;; ANSWER SECTION:
n3390.ns.yunjiasu.com. 892 IN AAAA 2001::212
;; Query time: 2 msec
;; SERVER: 2001:4860:4860::8888#53(2001:4860:4860::8888)
;; WHEN: Sun Jul 22 22:47:43 EDT 2018
;; MSG SIZE rcvd: 67
$ dig AAAA @2001:4860:4860::8888 n307.ns.yunjiasu.com
; <<>> DiG 9.9.4-RedHat-9.9.4-51.el7 <<>> AAAA @2001:4860:4860::8888 n307.ns.yunjiasu.com
; (1 server found)
;; global options: +cmd
;; Got answer:
;; ->>HEADER<<- opcode: QUERY, status: NOERROR, id: 23466
;; flags: qr rd ra; QUERY: 1, ANSWER: 1, AUTHORITY: 0, ADDITIONAL: 0
;; QUESTION SECTION:
;n307.ns.yunjiasu.com. IN AAAA
;; ANSWER SECTION:
n307.ns.yunjiasu.com. 892 IN AAAA 101::1234
;; Query time: 2 msec
;; SERVER: 2001:4860:4860::8888#53(2001:4860:4860::8888)
;; WHEN: Sun Jul 22 22:51:03 EDT 2018
;; MSG SIZE rcvd: 66
从国内解析没有问题
$ dig AAAA @240c::6666 n307.ns.yunjiasu.com
; <<>> DiG 9.9.4-RedHat-9.9.4-51.el7 <<>> AAAA @240c::6666 n307.ns.yunjiasu.com
; (1 server found)
;; global options: +cmd
;; Got answer:
;; ->>HEADER<<- opcode: QUERY, status: NOERROR, id: 49599
;; flags: qr rd ra; QUERY: 1, ANSWER: 1, AUTHORITY: 0, ADDITIONAL: 1
;; OPT PSEUDOSECTION:
; EDNS: version: 0, flags:; udp: 4096
;; QUESTION SECTION:
;n307.ns.yunjiasu.com. IN AAAA
;; ANSWER SECTION:
n307.ns.yunjiasu.com. 299 IN AAAA 2400:cb00:2049:1::a29f:1c6e
;; Query time: 1 msec
;; SERVER: 240c::6666#53(240c::6666)
;; WHEN: Sun Jul 22 22:54:16 EDT 2018
;; MSG SIZE rcvd: 77