SunQuest
           Linux Help
 
Forums: » Register « |  User CP |  Games |  Calendar |  Members |  FAQs |  Sitemap |  Support | 
User Name:
Password:
Remember me
Go Back   Dev Shed ForumsOperating SystemsLinux Help

Reply
Add This Thread To:
  Del.icio.us   Digg   Google   Spurl   Blink   Furl   Simpy   Y! MyWeb 
Thread Tools Search this Thread Rate Thread Display Modes
 
Unread Dev Shed Forums Sponsor:
Stop making mediocre tutorials.The best tutorials are video! Camtasia Studio makes it easy to create engaging, buzz-building screen videos at any size, in any popular format. Download the free trial!
  #1  
Old June 1st, 2002, 09:52 AM
Hero Zzyzzx's Avatar
Hero Zzyzzx Hero Zzyzzx is offline
11
Dev Shed Demi-God (4500 - 4999 posts)
 
Join Date: Jul 2001
Location: Lynn, MA
Posts: 4,632 Hero Zzyzzx User rank is Second Lieutenant (5000 - 10000 Reputation Level)Hero Zzyzzx User rank is Second Lieutenant (5000 - 10000 Reputation Level)Hero Zzyzzx User rank is Second Lieutenant (5000 - 10000 Reputation Level)Hero Zzyzzx User rank is Second Lieutenant (5000 - 10000 Reputation Level)Hero Zzyzzx User rank is Second Lieutenant (5000 - 10000 Reputation Level)Hero Zzyzzx User rank is Second Lieutenant (5000 - 10000 Reputation Level)Hero Zzyzzx User rank is Second Lieutenant (5000 - 10000 Reputation Level) 
Time spent in forums: 4 Days 23 h 12 m 33 sec
Reputation Power: 77
Send a message via AIM to Hero Zzyzzx
Strange DNS Issue- Advice Sought

Here's the thing-

I think that a DNS server/set of DNS servers in China are misconfigured, and hitting one of my IP addresses. . .

Looking at my logs, I'm repeatedly getting requests to one of my servers for pages in the domains "www.nudecards.com", "www.leadhound.com", "www.linksynergy.com", "cash.whitestockings.com" and others, and the requests ALWAYS come from IPS in China. Looking up the ip addresses in APNIC says that they are all owned by CHINANET, which must be the state ISP or something.

I wrote a perl script to parse my logs and pull out all the IPS of requests for these pages, which I am getting a lot of, from only 317 unique IP addresses.

This has been going on as long as I have had this IP address. I have all the bandwidth I want, so it's not the use of resources that bugs me, it's just that it's clogging up my log files and ruining the usage reports.

What I'm thinking of doing is just blocking these 317 ips with ipchains. For one thing, all the sites at this IP are english, specific to Massachusetts and for non-profit legal aid agencies. For another, none of the requests from these IPS are for pages I host. . .

Do folks think this is a good/bad idea, and what are your thoughts?

Example log entries from these requests are attached.

I had no idea where to post this, and linux seemed the best place.
Attached Files
File Type: gz log.txt.gz (1.3 KB, 281 views)

Reply With Quote
  #2  
Old June 13th, 2002, 07:36 PM
gogoadmin gogoadmin is offline
Junior Member
Dev Shed Newbie (0 - 499 posts)
 
Join Date: Jun 2002
Location: Los Angeles, CA
Posts: 1 gogoadmin User rank is Just a Lowly Private (1 - 20 Reputation Level) 
Time spent in forums: < 1 sec
Reputation Power: 0
Thumbs up naughty nameservers

Wow, that's definately a screwed up nameserver, but I don't think it's China's fault... check it out...

The host their trying to reach is nudecards.com right?

If you do a whois lookup on nudecards.com you find out it belongs to some guy in palo alto, ca. and what the screwed up name servers are...

Technical Contact:
Conru, Andrew URL
Friendfinder Inc.
445 Sherman Ave., Suite T
Palo Alto, Ca 946306
US
650 324-4867
650 324-99379


Domain servers in listed order:
CASTOR.CONRU.COM
POLLUX.CONRU.COM

I'm assuming if you let him know about the problem, this guy will fix it, cause it means people are going to your site and not his.

Good luck...

Reply With Quote
  #3  
Old June 14th, 2002, 09:05 AM
Hero Zzyzzx's Avatar
Hero Zzyzzx Hero Zzyzzx is offline
11
Dev Shed Demi-God (4500 - 4999 posts)
 
Join Date: Jul 2001
Location: Lynn, MA
Posts: 4,632 Hero Zzyzzx User rank is Second Lieutenant (5000 - 10000 Reputation Level)Hero Zzyzzx User rank is Second Lieutenant (5000 - 10000 Reputation Level)Hero Zzyzzx User rank is Second Lieutenant (5000 - 10000 Reputation Level)Hero Zzyzzx User rank is Second Lieutenant (5000 - 10000 Reputation Level)Hero Zzyzzx User rank is Second Lieutenant (5000 - 10000 Reputation Level)Hero Zzyzzx User rank is Second Lieutenant (5000 - 10000 Reputation Level)Hero Zzyzzx User rank is Second Lieutenant (5000 - 10000 Reputation Level) 
Time spent in forums: 4 Days 23 h 12 m 33 sec
Reputation Power: 77
Send a message via AIM to Hero Zzyzzx
Thanks for the feedback.

All the requesting IPs are from China, though. As we all know, DNS entries propagate around the world and each ISP usually provides DNS services to it's own users.

Therefore, when these folks in China try to get "nudecards.com", it goes to their local DNS server, does a lookup, and then sends them to my boxen.

I don't think it's an error in California, I can get nudecards from my terminal, and again all the screwed up requests come from China, which leads me to believe the Chinese DNS servers are wacked.

Reply With Quote
  #4  
Old June 14th, 2002, 09:16 AM
Onslaught's Avatar
Onslaught Onslaught is offline
/(bb|[^b]{2})/
Dev Shed Demi-God (4500 - 4999 posts)
 
Join Date: Nov 2001
Location: Somewhere in the great unknown
Posts: 4,834 Onslaught User rank is Second Lieutenant (5000 - 10000 Reputation Level)Onslaught User rank is Second Lieutenant (5000 - 10000 Reputation Level)Onslaught User rank is Second Lieutenant (5000 - 10000 Reputation Level)Onslaught User rank is Second Lieutenant (5000 - 10000 Reputation Level)Onslaught User rank is Second Lieutenant (5000 - 10000 Reputation Level)Onslaught User rank is Second Lieutenant (5000 - 10000 Reputation Level)Onslaught User rank is Second Lieutenant (5000 - 10000 Reputation Level) 
Time spent in forums: 1 Day 23 h 30 m 30 sec
Reputation Power: 88
Send a message via ICQ to Onslaught
Honestly, I would send an email to chinanet and/or the guy in california and then block the ip addresses. No matter who's falt it is, it is comming from one area that, in all likelyhood, will never need/want access to your site.
Even though it may not be the site owners fault, he may want to take action to remedy this so that he can get more traffic.

Reply With Quote
Reply

Viewing: Dev Shed ForumsOperating SystemsLinux Help > Strange DNS Issue- Advice Sought


Thread Tools  Search this Thread 
Search this Thread:

Advanced Search
Display Modes  Rate This Thread 
Rate This Thread:


Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
View Your Warnings | New Posts | Latest News | Latest Threads | Shoutbox
Forum Jump


Forums: » Register « |  User CP |  Games |  Calendar |  Members |  FAQs |  Sitemap |  Support | 
  
 





© 2003-2008 by Developer Shed. All rights reserved. DS Cluster 3 hosted by Hostway