[dns-operations] .VA tld has been intermittently wildcarded?

Alarig Le Lay alarig at swordarmor.fr
Sun Dec 1 09:59:33 UTC 2024


Hello,

On Sat 30 Nov 2024 20:16:19 GMT, Mark E. Jeftovic wrote:
> 
> Our domainsure monitors started picking up some weirdness out of .va tld 
> today as it appeared that up to 3 of their 5 nameservers were wildcarded 
> and handing out NS records that seemed autogenerated:

I can reproduce it from different hosts, it seems that the first part of
the hostname is fixed, the second depends on the time and the last
depends on the IP:

10:56 alarig at mbp-scw ~ % dig -4 +nsid -t NS alarig.va @a.nic.va | grep -P 'IN.*NS|WHEN'
;alarig.va.			IN	NS
alarig.va.		0	IN	NS	ck02-3ffdf818f4-59eaba4e.va.
;; WHEN: Sun Dec 01 10:56:23 CET 2024
10:56 alarig at mbp-scw ~ % dig -4 +nsid -t NS alarig.va @a.nic.va | grep -P 'IN.*NS|WHEN'
;alarig.va.			IN	NS
alarig.va.		0	IN	NS	ck02-d7ab603182-59eaba4e.va.
;; WHEN: Sun Dec 01 10:56:24 CET 2024
10:56 alarig at mbp-scw ~ % dig -4 +nsid -t NS alarig.va @b.nic.va | grep -P 'IN.*NS|WHEN'
;alarig.va.			IN	NS
alarig.va.		0	IN	NS	ck02-d7ab603182-59eaba4e.va.
;; WHEN: Sun Dec 01 10:56:26 CET 2024

And from another host:
alarig at regis ~ $ dig -4 +nsid -t NS alarig.va @b.nic.va | grep -P 'IN.*NS'
;alarig.va.			IN	NS
alarig.va.		0	IN	NS	ck02-573203cda5-2d5b7eff.va.
alarig at regis ~ $ dig -4 +nsid -t NS alarig.va @b.nic.va | grep -P 'IN.*NS'
;alarig.va.			IN	NS
alarig.va.		0	IN	NS	ck02-e9a2314bce-2d5b7eff.va.

-- 
Alarig


More information about the dns-operations mailing list