k.gtld-servers.net 0wned?

12 out of 13 gtld servers agree:

[alumange:~] iljitsch% host -v www.imdb.com m.gtld-servers.net
Trying "www.imdb.com"
Using domain server:
Name: m.gtld-servers.net
Address: 192.55.83.30#53
Aliases:

;; ->>HEADER<<- opcode: QUERY, status: NOERROR, id: 60746
;; flags: qr rd; QUERY: 1, ANSWER: 0, AUTHORITY: 2, ADDITIONAL: 2

;; QUESTION SECTION:
;www.imdb.com. IN A

;; AUTHORITY SECTION:
imdb.com. 172800 IN NS udns1.ultradns.net.
imdb.com. 172800 IN NS udns2.ultradns.net.

;; ADDITIONAL SECTION:
udns1.ultradns.net. 172800 IN A 204.69.234.1
udns2.ultradns.net. 172800 IN A 204.74.101.1

But k says something different:

[alumange:~] iljitsch% host -v www.imdb.com k.gtld-servers.net
Trying "www.imdb.com"
Using domain server:
Name: k.gtld-servers.net
Address: 218.234.22.221#53
Aliases:

;; ->>HEADER<<- opcode: QUERY, status: NOERROR, id: 248
;; flags: qr aa rd; QUERY: 1, ANSWER: 2, AUTHORITY: 6, ADDITIONAL: 12

;; QUESTION SECTION:
;www.imdb.com. IN A

;; ANSWER SECTION:
www.imdb.com. 1800 IN A 200.139.105.69
www.imdb.com. 1800 IN A 218.234.22.221

;; AUTHORITY SECTION:
com. 1800 IN NS ns1.thirdfloordoors02.com.
com. 1800 IN NS ns1.thirdfloordoors03.com.
com. 1800 IN NS ns1.thirdfloordoors04.com.
com. 1800 IN NS ns1.thirdfloordoors05.com.
com. 1800 IN NS ns1.thirdfloordoors06.com.
com. 1800 IN NS ns1.thirdfloordoors01.com.

;; ADDITIONAL SECTION:
ns1.thirdfloordoors01.com. 1800 IN A 200.139.105.69
ns1.thirdfloordoors01.com. 1800 IN A 218.234.22.221
ns1.thirdfloordoors02.com. 1800 IN A 218.234.22.221
ns1.thirdfloordoors02.com. 1800 IN A 200.139.105.69
ns1.thirdfloordoors03.com. 1800 IN A 200.139.105.69
ns1.thirdfloordoors03.com. 1800 IN A 218.234.22.221
ns1.thirdfloordoors04.com. 1800 IN A 218.234.22.221
ns1.thirdfloordoors04.com. 1800 IN A 200.139.105.69
ns1.thirdfloordoors05.com. 1800 IN A 200.139.105.69
ns1.thirdfloordoors05.com. 1800 IN A 218.234.22.221
ns1.thirdfloordoors06.com. 1800 IN A 218.234.22.221
ns1.thirdfloordoors06.com. 1800 IN A 200.139.105.69

Received 470 bytes from 218.234.22.221#53 in 1184 ms

Iljitsch van Beijnum wrote:

12 out of 13 gtld servers agree:

<snip>

But k says something different:

[alumange:~] iljitsch% host -v www.imdb.com k.gtld-servers.net
Trying "www.imdb.com"
Using domain server:
Name: k.gtld-servers.net
Address: 218.234.22.221#53
Aliases:

But is k.gtld-servers.net really 218.234.22.221?

> dig @a.root-servers.net k.gtld-servers.net

k.gtld-servers.net. 172800 IN A 192.52.178.30

Mark Radabaugh
Amplex

^^^^^^^^^^^^^^^^^

Apparently not, as this isn't the right address for k.gtld-servers.net.

My apologies.

Well - how / where did you get an IP in Hanaro Telecom, Korea space for k.gtld-servers.net?

DNS cache poisoned or something?

Apparently. I don't manage the box in question so I don't know any details about how it happened.