[dnsdist] SpoofRawAction - DNS Wire format?

Bit World Computing e.K. - Michael Mertel michael.mertel at bwc.de
Fri Jul 17 12:20:03 UTC 2020


Hi,

I solved it, it’s actually much easier than I thought:

IN MX	100	mail.test.de.
		looks like this
SpoofRawAction("\000\100\004mail\004test\002de\000“)

Maybe it helps if someone else struggles with it like me before :)

Stay safe.

—Michael

> Am 17.07.2020 um 12:24 schrieb Bit World Computing e.K. - Michael Mertel via dnsdist <dnsdist at mailman.powerdns.com>:
> 
> Hi,
> 
> I would like to redo a MX spoofing project from recursor over to dnsdist, thanks to the new SpoofRawAction function.
> 
> Is there a tool that shows me the wire format for a specific response which I can adept? Or do I need to know the structure of the DNS packet and get it out of a tcpdump?
> 
> A hint into the right direction would be highly appreciated.
> 
> -Michael
> 



More information about the dnsdist mailing list