[HELP WANTED] Samba DNS Corruption: any examples?

Andrew Bartlett abartlet at samba.org
Tue Nov 1 09:16:12 UTC 2016


G'Day,

I'm chasing down an issue of DNS corruption for a customer, where an A
record coudln't be deleted with Samba's normal tools, and had to be
removed with ldbdel.

Sadly however we no longer have access to the corrupt record (oops),
but there is nothing new under the sun, and if it happening for one
customer it is probably happening elsewhere.  And in any case, the more
examples the better with these things.

I'm aware of the ability of TXT records to be miss-parsed (it even got
as far as a security hole), but if anybody has other records that get
'stuck' in our internal or BIND9 DLZ DNS servers, and can share those
with me (in private is fine), that would be most helpful.

I'm looking for output from commands like:

bin/ldbsearch -H ldap://$SERVER -Uadministrator%$PASSWORD -b
"DC=773eed91-5cc6-4745-94c9-
1c1796e377d0,DC=_msdcs.samba.example.com,CN=MicrosoftDNS,DC=forestDnsZo
nes,DC=samba,DC=example,DC=com" 

and 

bin/ldbsearch -H ldap://$SERVER -Uadministrator%$PASSWORD -b
"DC=773eed91-5cc6-4745-94c9-
1c1796e377d0,DC=_msdcs.samba.example.com,CN=MicrosoftDNS,DC=forestDnsZo
nes,DC=samba,DC=example,DC=com"  --show-binary

Thanks!

Andrew Bartlett
-- 
Andrew Bartlett                       http://samba.org/~abartlet/
Authentication Developer, Samba Team  http://samba.org
Samba Developer, Catalyst IT          http://catalyst.net.nz/services/samba




More information about the samba-technical mailing list