The Wayback Machine - https://web.archive.org/web/20090202125132/http://nlnetlabs.nl:80/projects/drill/
 

DNSSEC Drill: If you need to dig deeper

Merged with ldns

Drill is now bundled with ldns. Please go there to get the newest version. This is the old page and it will no longer be updated.  

Drill

Drill is a tool like dig from BIND. It was designed with DNSSEC in mind and should be a useful debugging/query tool for DNSSEC.

A lot of DNS debugging is done with dig, but as dig is made with the same libraries as BIND8/9 (the most used DNS server out there), what are you actually debugging/testing? Drill has nothing in common with either NSD nor BIND. During the development process we are actually uncovering obscure bugs in NSD and BIND (and in drill itself).

Future versions of drill will be based on the general DNSSEC library we are developing, called ldns. You can download a prerelease of this new version already.

Mailing list

On open.nlnetlabs.nl/mailman/listinfo/drill you can subscribe to the drill mailing list. On this list user and technical discussions will take place. Also announcements of new releases will be communicated via this list.

Documentation

A manual page is included with some examples. Drill acts and looks a lot like dig, so if you know dig, you know drill.

Current status and issues

Everything, except a fully verified top-down trace, works, some highlights:
  • Chasing of signatures (-S)
  • Secure top-down tracing (-TD) (not yet finished)
  • Transport switching (-4: ipv4, -6: ipv6)
  • Print DS records for each DNSKEY (-s)
  • No code sharing with BIND. nor NSD. It's completely stand alone

We are currently building a general dns library in c, and the next major version of drill will be based on this. The current codebase will only see bugfixes. The current code is quite solid, a lot of testing went into this 0.9 release. We consider drill ready for general use.

Usage

Compiling drill is done with:
./configure && make
		
When drill is started with no arguments, it will print out a short usage message:
drill options type name

        @server         use server as nameserver
        -T, --trace     trace from the root down to 'name'
        -S, --sigchase  chase signature from 'name'
        -D, --dnssec    enable dnssec
        -I              reserved for backwards compatibility
        -V, --verbose   Verbose mode (give twice for more verbosity hexdump)
        -4, --ip4       Stay on IPv4
        -6, --ip6       Stay on IPv6

        -p port, --port port     use port as port number
        -b size, --bufsize size  use size is buffer size
        -q file, --dumpquery file       make a hexdump of the query to file
        -f file, --fromfile file        read packet from file and send that
        -i file, --answerinfile file    read packet from file and print it
        -w file, --answertofile file    write (first) answer to file

        -k, --key file  use public key from file file as trusted key
        -x, --reverse   do a reverse (PTR) lookup
        -c, --tcp       only query in tcp mode (connected)
        -u, --udp       only query in udp mode (unconnected)
        -s, --ds        print DS after each DNSKEY
        -v, --version   show version

Download

This release is dated at: 03-02-2005.

You can download the bzip2 tar file here. It was tested on Linux and FreeBSD.  

Contact

Questions about drill should be directed to <drill@nlnetlabs.nl>.  

Changes

0.9.2 (3 Feb 2005)
  • Added two more options (borrowed from dig)
    • --rd, don't set the RD bit in queries
    • --fail, don't query the next nameserver on SERVFAIL
  • Fixed handling of obscure data types
  • Handle classes other the 'IN' when making a query
  • Fixed some small bugs
  • For people using FreeBSD: drill is now in the ports (Thanks to Jaap Akkerhuis)
0.9.1 (6 Jan 2005)
  • Makefile tweaks
  • drill ns . works
  • re-check the root when tracing
  • added handling for some lesser known types (including WKS)
0.9 (6 Dec 2004)
  • big configure.ac and Makefile.in updates (made more general)
  • escapes in names argument and txt and dname data
  • gcc 2(.95) support
  • packet wire data is now checked for dangerous elements (like looping compression etc)
  • (Multiple) Octal char representation
  • Responses can be saved to file
  • 'Answers' can be read from file instead of server
  • Lots and lots of bugfixes and improvements
Fri Dec 12 2008 © NLnet Labs
Science Park 140, 1098 XG Amsterdam, The Netherlands
labs@nlnetlabs.nl , subsidized by NLnet