Digging Into DNS With dig
Goal
You do lookups by record type with dig, read the TTL and the negative cache, and build for yourself the point where the answers of getent and dig diverge.
Why it matters
You must read dig output starting from status and flags. NXDOMAIN (the name itself does not exist) and NOERROR + ANSWER 0 (the name exists but only that type does not) are completely different situations and call for different responses. Without the aa flag, the answer came from a cache, which is why the TTL decreases. And because dig does not look at /etc/hosts, it can give an answer different from getent for the same name — that difference is the location of the cause.
Steps
- Create the
/root/dnsdirectory and save only the lines starting withnameserverin/etc/resolv.confto/root/dns/nameserver.txt. - Save only the A record value of
example.comto/root/dns/a.txt. The file must have at least one IPv4 address line. - Save the
MX,NS, andTXTofgoogle.comto/root/dns/mx.txt,/root/dns/ns.txt, and/root/dns/txt.txtrespectively. None of the three files may be empty. - Print only the answer section of
example.comand save it to/root/dns/ttl1.txt, and after waiting 5 seconds or more, make/root/dns/ttl2.txtthe same way. The second TTL must not be larger than the first. - Save the reverse lookup result of
8.8.8.8to/root/dns/ptr.txt. - Look up
labhub-does-not-exist-9137.example.comand save the full output to/root/dns/nxdomain.txt. The file must contain bothstatus: NXDOMAINand an SOA record. - After adding
10.77.0.1 www.example.comto/etc/hosts, save thegetent hosts www.example.comresult to/root/dns/getent-www.txtand thedig +short www.example.comresult to/root/dns/dig-www.txt. The two results must differ. - Make
/root/dns/report.txtwith the following 5 lines.NAMESERVERS=<1번 파일의 줄 수>/A_COUNT=<2번 파일의 줄 수>/PTR=<5번에서 얻은 이름, 끝의 점 제외>/HOSTS_WINS=<7번 getent 결과의 IP>/DNS_SAYS=<7번 dig 결과의 첫 번째 IP>(that is, the number of lines in the step 1 file, the number of lines in the step 2 file, the name obtained in step 5 without the trailing dot, the IP of the step 7 getent result, and the first IP of the step 7 dig result)
Notes
- Combining
dig +short,dig +noall +answer,dig -x <IP>, anddig -t MX <이름>finishes most of this lab (the last placeholder is the name). - In step 4, the TTL is the second column of the
+noall +answeroutput. - In step 6, the SOA appears in the AUTHORITY section. You can also look at it separately with
+noall +authority. - Common mistake 1: if the IP you put in hosts in step 7 is the same as the actual DNS response, this step is meaningless. Use a private-range address.
- Common mistake 2: if the
digresult is empty, there is no record of that type. Checkstatusto tell whether it is NXDOMAIN or NOERROR.
Reading the resolver configuration
Create the /root/dns directory and save only the lines starting with nameserver in /etc/resolv.conf to /root/dns/nameserver.txt.
You need only the lines in resolv.conf that start with nameserver. There may be several.
Forward lookup
Save only the A record value of example.com to /root/dns/a.txt. The file must have at least one IPv4 address line.
If you need only the value, there is a short output option. An A record must be in IPv4 address format.
Lookups by record type
Save the MX, NS, and TXT of google.com to /root/dns/mx.txt, /root/dns/ns.txt, and /root/dns/txt.txt respectively. None of the three files may be empty.
With dig you can specify the type with -t, or simply attach the type after the name. An MX value is a pair of a priority number and a host name.
Observing the TTL decrease
Print only the answer section of example.com and save it to /root/dns/ttl1.txt, and after waiting 5 seconds or more, make /root/dns/ttl2.txt the same way. The second TTL must not be larger than the first.
If you print only the answer section, the TTL comes out in the second column. Run the same query twice with a short interval in between.
Reverse lookup
Save the reverse lookup result of 8.8.8.8 to /root/dns/ptr.txt.
dig has a dedicated option that finds the PTR when you put in an IP. The result is a name ending in a dot.
A nonexistent name and the negative cache
Look up labhub-does-not-exist-9137.example.com and save the full output to /root/dns/nxdomain.txt. The file must contain both status: NXDOMAIN and an SOA record.
The status is on the header line. The SOA comes in the AUTHORITY section, and the last number is the MINIMUM.
The point where getent and dig diverge
After adding 10.77.0.1 www.example.com to /etc/hosts, save the getent hosts www.example.com result to /root/dns/getent-www.txt and the dig +short www.example.com result to /root/dns/dig-www.txt. The two results must differ.
This step has meaning only if the IP you put in hosts differs from the IP DNS gives. Save the two results separately.
There is one trap. getent hosts <이름> asks first for IPv6 and asks for IPv4 again only when there is no answer (the placeholder is the name). But the line you put in hosts is IPv4 only, so if that name has an AAAA record, the v6 lookup passes over hosts and goes out to DNS, and the IPv6 address comes out first. It looks as if hosts were ignored, but that is not so — if you ask only the v4 family with getent ahostsv4 <이름>, the hosts value comes out as it is. Use that in this step.
Lookup summary report
Make /root/dns/report.txt with the following 5 lines.
NAMESERVERS=<1번 파일의 줄 수> / A_COUNT=<2번 파일의 줄 수> / PTR=<5번에서 얻은 이름, 끝의 점 제외> / HOSTS_WINS=<7번 getent 결과의 IP> / DNS_SAYS=<7번 dig 결과의 첫 번째 IP> (that is, the number of lines in the step 1 file, the number of lines in the step 2 file, the name obtained in step 5 without the trailing dot, the IP of the step 7 getent result, and the first IP of the step 7 dig result)
Just gather the earlier results as key=value. For the items that count, counting by number of lines is enough.