DragonFly BSD
DragonFly users List (threaded) for 2005-03
OT DNS/routing question

From: walt <wa1ter@xxxxxxxxxxxxx>
Date: Sat, 12 Mar 2005 07:23:52 -0800

Like my last DNS question, this one was raised by a phishing
email asking me to click on this URL:

Now, this is my puzzle:

#host wamu.securesite.cn
wamu.securesite.cn has address

My first thought was that my local DNS server is misconfigured, so I
tried using the nameserver for securesite.cn and got the same answer.

#dig @ns2.afraid.org wamu.securesite.cn

; <<>> DiG 9.2.3 <<>> @ns2.afraid.org wamu.securesite.cn
;; global options:  printcmd
;; Got answer:
;; ->>HEADER<<- opcode: QUERY, status: NOERROR, id: 12484
;; flags: qr aa rd; QUERY: 1, ANSWER: 1, AUTHORITY: 5, ADDITIONAL: 4

;wamu.securesite.cn.            IN      A

wamu.securesite.cn.     43200   IN      A

Do you see why I'm confused?  Are they doing something *really*
sneaky here, or am I using the DNS tools incorrectly?

