Hi Kevin,
On Mon, Nov 25, 2024 at 08:09:28PM +0100, Kevin O'Rourke via BitFolk Users wrote:
I finally got round to trying this out, but I'm
obviously doing something wrong:
./ptrcheck -v --server 127.0.0.1 --zone caboose.org.uk
Connecting to 127.0.0.1 port 53 for AXFR of zone caboose.org.uk
Zone contains 1 record
Found 0 unique address (A/AAAA) records
I was not able to replicate this:
$ ptrcheck --server [::1] --zone caboose.org.uk -v
Connecting to ::1 port 53 for AXFR of zone caboose.org.uk
Zone contains 20 records
Found 2 unique address (A/AAAA) records
➡ 85.119.82.49 is pointed to by:
caboose.org.uk., mail.caboose.org.uk., oelph.caboose.org.uk.,
www.caboose.org.uk.
➡ 2001:ba8:1f1:f0e9::2 is pointed to by:
caboose.org.uk., mail.caboose.org.uk., oelph.caboose.org.uk.,
www.caboose.org.uk.
🏆 100.0% good PTRs! Good job!
The fact that it said "contains 1 record" for you leads me to believe
that it got an AXFR with only a SOA record or something.
When I try to do it from a.authns.bitfolk.co.uk against your primary's
IP I get a "NotAuth" response, which is interesting. I did not expect it
to work because the address selection for source address would be an IP
that you probably do not allow AXFR from¹, but I would have expected a
Refused response in that case.
Anyway I'd like to look into it more but not sure how best to proceed.
Was this was done with the head of the main branch? I see it let you just
do "--server 127.0.0.1" with no port.
If you can still replicate it, maybe you could add a github issue?
https://github.com/grifferz/ptrcheck-rs/issues
Or email me privately about it if you'd rather not use github?
Thanks,
Andy
¹ So another option needed for source address?
--
https://bitfolk.com/ -- No-nonsense VPS hosting