further information. it appears that plan 9 dns is vulnerable to
cache poisoning. i just caught a second machine with these entries
ns localhost UN 1269483730/1269483730
ns B.ROOT-SERVERS.NET UN 1273157904/1273157904
ns C.ROOT-SERVERS.NET UN 1273157904/1273157904
ns D.ROOT-SERVERS.NET UN 1273157904/1273157904
ns E.ROOT-SERVERS.NET UN 1273157904/1273157904
ns F.ROOT-SERVERS.NET UN 1273157904/1273157904
ns G.ROOT-SERVERS.NET UN 1273157904/1273157904
ns H.ROOT-SERVERS.NET UN 1273157904/1273157904
ns I.ROOT-SERVERS.NET UN 1273157904/1273157904
ns J.ROOT-SERVERS.NET UN 1273157904/1273157904
ns K.ROOT-SERVERS.NET UN 1273157904/1273157904
ns L.ROOT-SERVERS.NET UN 1273157904/1273157904
ns M.ROOT-SERVERS.NET UN 1273157904/1273157904
ns A.ROOT-SERVERS.NET UN 1273157904/1273157904
>> ns ns1.parked.com UN 1269855557/1269855557
>> ns ns2.parked.com UN 1269855557/1269855557
ns A.ROOT-SERVERS.NET UD 1303335771/0
ns B.ROOT-SERVERS.NET UD 1303335771/0
ns C.ROOT-SERVERS.NET UD 1303335771/0
ns D.ROOT-SERVERS.NET UD 1303335771/0
ns E.ROOT-SERVERS.NET UD 1303335771/0
ns F.ROOT-SERVERS.NET UD 1303335771/0
ns G.ROOT-SERVERS.NET UD 1303335771/0
ns H.ROOT-SERVERS.NET UD 1303335771/0
ns I.ROOT-SERVERS.NET UD 1303335771/0
ns J.ROOT-SERVERS.NET UD 1303335771/0
ns K.ROOT-SERVERS.NET UD 1303335771/0
ns L.ROOT-SERVERS.NET UD 1303335771/0
ns M.ROOT-SERVERS.NET UD 1303335771/0
>> ns ns1.trafficz.com UN 1272210527/1272210527
>> ns ns2.trafficz.com UN 1272210527/1272210527
soa ns1.parked.com admin.parked.com 2006032101 7200 1800 1209600
10800 AN 1269743556/1269743556
soa ns01.cashparking.com dns.jomax.net 2010021700 28800 7200 604800
86400 AN 1271491124/1271491124
soa ns1.gunas.net hostmaster 2008092011 3600 900 604800 14400 AN
1271839986/1271839986
soa A.ROOT-SERVERS.NET nstld.verisign-grs.com 2010042200 1800 900
604800 86400 AN 1272015686/1272015686
soa ns1.trafficz.com hostmaster 1271791802 16384 2048 1048576 2560
AN 1271945458/1271945458
[etc]
- erik