Re: Reverse look-up returns root servers?

2013-10-28 Thread Matus UHLAR - fantomas
com. -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto adresu chcem NEDOSTAVAT akukolvek reklamnu postu. If Barbie is so popular, why do you have to buy her frie

Re: Refreshing cache in other DNS servers

2013-10-15 Thread Matus UHLAR - fantomas
On 15.10.13 22:53, babu dheen wrote: To: Matus UHLAR - fantomas , "bind-users@lists.isc.org" Hi Matus, you don't need to send me private copies - we are using a mailing list for a purpose... thank you.  If I change the TTL value on the particular zone after modifying a

Re: Refreshing cache in other DNS servers

2013-10-15 Thread Matus UHLAR - fantomas
to sane standard value (e.g. 43200). You may ask for access to win2003 servers to manipulate their caches, or configure your zone as slave on them and send notifies to them, so they notice as soon as possible. -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish

Re: NS record TTL versus nameserver's A record TTL

2013-10-08 Thread Matus UHLAR - fantomas
makes me wonder: -Is this addressed by a standard? E.g., the nameserver's A record have the same TTL as NS records pointing at it. It should be the same, when the server is in the domain. I met exactly those issues when NS record had longer ttl then the A record in the same domain.

Re: weird perfmonce BIND version 9.6

2013-10-04 Thread Matus UHLAR - fantomas
includes (I recommend you not goind more than one level of inclusion) were are the view definitions. you said Check their match-* directives, post them here if possible. check all used files and view definitions for "match-" directives. -- Matus UHLAR - fantomas, uh...@fantomas

Re: weird perfmonce BIND version 9.6

2013-09-26 Thread Matus UHLAR - fantomas
should NOT mention both IPs in any view. hosts from internal view should get internal IP and hosts from external view should get external IP. -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto ad

Re: weird perfmonce BIND version 9.6

2013-09-26 Thread Matus UHLAR - fantomas
issue. you apparently have not configured views properly. only clients that are supposed to get internal private addresses should be in internal view. -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address

Re: weird perfmonce BIND version 9.6

2013-09-25 Thread Matus UHLAR - fantomas
ws machines (I still feel it's better to install bind9 with "tools only" on windows than using nslookup). using ping is not a good idea for DNS testing. -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this addres

Re: Weird dig behavior when querying ANY

2013-09-10 Thread Matus UHLAR - fantomas
simply provides you the remaining TTL. If you do it again, you will see TTL has either decreased in the time difference, or the records were fetched again. the discussion a few days ago has revealed that BIND does not recursively fetch records when you send ANY query. -- Matus UHLAR - fantomas, uh..

Re: nxdomain

2013-08-28 Thread Matus UHLAR - fantomas
? -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto adresu chcem NEDOSTAVAT akukolvek reklamnu postu. I'm not interested in your website anymore. If you need cookies, bake them you

Re: nxdomain not caching for configured reverse lookup

2013-08-20 Thread Matus UHLAR - fantomas
to forward 7.7.7.in-addr.arpa, 7.7.in-addr.arpa or 7.in-addr.arpa, depending on what is configured on 10.212.24.11. BTW, are you aware that 7.7.7.7 is used by DoD and 9.9.9.9 by IBM? -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail adverti

Re: nxdomain not caching for configured reverse lookup

2013-08-20 Thread Matus UHLAR - fantomas
do dig -x 7.7.7.7, which is in the configured zone for DNS 10.212.24.11, i am not able to get the responses cached. what is the TTL of those NXDOMAIN answers? -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address.

Re: bind not getting out of my LAN?

2013-08-18 Thread Matus UHLAR - fantomas
t blocks DNS? -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto adresu chcem NEDOSTAVAT akukolvek reklamnu postu. I just got lost in thought. It was unfamili

Re: Can't make my bind service for zone authoritative

2013-08-17 Thread Matus UHLAR - fantomas
On 17.08.13 10:36, Mimiko wrote: I created a zone with the following: [...] But the answer is always un-authoritative. Why is this? did you also configure the server to be master forthe zone? -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to

Re: Reverse Records on a leash?

2013-08-11 Thread Matus UHLAR - fantomas
On 8/10/13 3:37 AM, Matus UHLAR - fantomas wrote: however, reverse DNS records must not be zero-filled (those won't be taken into account) On 10.08.13 10:26, Eduardo Bonsi wrote: I put zeros just as an example. it can be 111.111.111.111 where 1= (any ipv4 number) or 000.000.000.000. wh

Re: Reverse Records on a leash?

2013-08-10 Thread Matus UHLAR - fantomas
nd charge you for it. ... and please, do not tell me that is to keep the spammers out because that so far has not proven to be true. The bad guys have an unlimited number of domains to do their dirt work everyday. -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish N

Re: New warning message...

2013-07-23 Thread Matus UHLAR - fantomas
In article , Matus UHLAR - fantomas wrote: No, it does not. If a mail gets delivered to address, which is sending it further ("forwarding it"), the envelope sender has to be changed, because it's not the original sender who sends the another mail. Forwarding without changing e

Re: IPv4 not working reverse on > /24 cidr

2013-07-22 Thread Matus UHLAR - fantomas
-addr.arpa maintained by the client. -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto adresu chcem NEDOSTAVAT akukolvek reklamnu postu. BSE = Mad Cow Desease ... BS

Re: New warning message...

2013-07-22 Thread Matus UHLAR - fantomas
g without changing envelope address is already broken, it's just people don't care without SPF. I have a case I am researching right now where forwarded mail is undeliverable due to SPF checking at the new destination. Rewrite the sender's address. You have more choices,

Re: New warning message...

2013-07-22 Thread Matus UHLAR - fantomas
ragraph 6.2; and Appendix A point 4. This was discussed here already, and imho this is anti-spf bullshit like all those "spf breaks forwarding" FUD. The SPF RR is already here and is preferred over TXT that is generik RR type, unlike SPF. -- Matus UHLAR - fantomas, uh...@fantomas.sk ;

Re: resolving-problem

2013-07-21 Thread Matus UHLAR - fantomas
; QUERY: 1, ANSWER: 0, AUTHORITY: 0, ADDITIONAL: 0 ;; QUESTION SECTION: ;ns1.alfransi.com.sa. IN ANY -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto adresu chcem NEDOSTAVAT aku

Re: Slave not creating/updating zones

2013-07-15 Thread Matus UHLAR - fantomas
ts.isc.org/mailman/listinfo/bind-users ___ Please visit https://lists.isc.org/mailman/listinfo/bind-users to unsubscribe from this list bind-users mailing list bind-users@lists.isc.org https://lists.isc.org/mailman/listinfo/bind-users -- Matus

Re: Reverse Lookups with Forwarders

2013-07-09 Thread Matus UHLAR - fantomas
changed to zone "110.252.173.in-addr.arpa" IN { All the requests for 173.252.110.0-173.252.110.255 is forwarded to 10.10.96.1. Use 110.252.173.in-addr.arpa then. You should be aware that the IP range belongs to facebook, as already noted. -- Matus UHLAR - fantoma

Re: Bind unable to get MX reocrd from Parrent name server

2013-07-05 Thread Matus UHLAR - fantomas
o.za. ; <<>> DiG 9.8.4-rpz2+rl005.12-P1 <<>> +norec any rbcaa.co.za. ; @babylon.mitsol.co.za. ;; global options: +cmd ;; Got answer: ;; ->>HEADER<<- opcode: QUERY, status: REFUSED, id: 52980 ;; flags: qr; QUERY: 1, ANSWER: 0, AUTHORITY: 0, ADDITIONAL: 0 -- M

Re: BIND Service Hung

2013-07-03 Thread Matus UHLAR - fantomas
UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto adresu chcem NEDOSTAVAT akukolvek reklamnu postu. "They say when you play that M$ CD backward you can hear satanic messages." "That's

Re: configure syslog prefix

2013-07-03 Thread Matus UHLAR - fantomas
/ftp.isc.org/isc/bind9/cur/9.9/doc/arm/Bv9ARM.ch06.html#id2576269 -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto adresu chcem NEDOSTAVAT akukolvek reklamnu pos

Re: Reverse address entries

2013-07-03 Thread Matus UHLAR - fantomas
tware should get NXDOMAIN answer. in such case there's nothing to wait for any longer. Are you sure that was not a case of unreachable servers? -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovani

Re: How to suppress ADDITIONAL SECTION per zone

2013-07-01 Thread Matus UHLAR - fantomas
to implement packet rate limiting - a patch was discussed here a few days/weeks ago. -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto adresu chcem NEDOSTAVAT akukolvek reklamnu postu. (R)etr

Re: Reverse address entries

2013-07-01 Thread Matus UHLAR - fantomas
>In article , > Charles Swiger wrote: >> Certainly. Various software performs what's called a double-reverse >> lookup >> to confirm that the A and PTR records match. In article , Matus UHLAR - fantomas wrote: He apparently meant exactly the same. Also calle

Re: Reverse address entries

2013-07-01 Thread Matus UHLAR - fantomas
pen. I don't know of anything to be gained by requiring a reverse lookup after a forward lookup. He apparently meant exactly the same. Also calles FcRDNS - "forward confirmed" or "full circle" reverse DNS. -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantoma

Re: servfail response message question

2013-06-27 Thread Matus UHLAR - fantomas
. If they are accessible from us, of course. We could check it ourselves and see how it behaves from the net. -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto adresu chcem NEDOSTAVAT

Re: Secondary DNS question...

2013-06-27 Thread Matus UHLAR - fantomas
ssues and overall my DNS was just erratic. I have now moved all of my secondary to BuddyNS with much better redundancy, and I figured out what was causing my ns1 to be glitchy. Can you tell us what, just for evidence? Thank you. -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantom

Re: Secondary DNS question...

2013-06-27 Thread Matus UHLAR - fantomas
alling software from scratch. -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto adresu chcem NEDOSTAVAT akukolvek reklamnu postu. Linux IS user friendly, it's just selective

Re: servfail response message question

2013-06-27 Thread Matus UHLAR - fantomas
f DNS load balancers... -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto adresu chcem NEDOSTAVAT akukolvek reklamnu postu. The 3 biggets disasters: Hiroshima 45, Tschernobyl 86, Windo

Re: Secondary DNS question...

2013-06-26 Thread Matus UHLAR - fantomas
mail/bind-users/2013-June/090970.html or pcap format at http://test.fantomas.sk/74.87.108.83.dns.pcap -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto adresu chcem NEDOSTAVAT akukolvek reklamnu

Re: Answers from cache or authority section?

2013-06-25 Thread Matus UHLAR - fantomas
r the zone, the given NS records prevail over delegation from parent zone. -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto adresu chcem NEDOSTAVAT akukolvek reklamnu postu. - Holmes, wh

Re: Secondary DNS question...

2013-06-25 Thread Matus UHLAR - fantomas
On 24.06.13 07:41, Frank Bulk wrote: Interesting to note that querying for ANY does return an SOA. I can't explain that behavior. On 24.06.13 14:54, Matus UHLAR - fantomas wrote: I can guess a kind of DNS filter/firewall. Some l3 switches or load balancers tend to produce strange result

Re: Secondary DNS question...

2013-06-24 Thread Matus UHLAR - fantomas
you have no SOA set for for ns1.starionhost.net: -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto adresu chcem NEDOSTAVAT akukolvek reklamnu postu. Support bacteria - they're the only

Re: How to suppress ADDITIONAL SECTION per zone

2013-06-24 Thread Matus UHLAR - fantomas
ional records being sent from a selected list of zone in our configuration.. You still have not answered my question, so I repeat it: > What is the point of your question? -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising

Re: bind 2.1a3 on centos 6.4

2013-06-21 Thread Matus UHLAR - fantomas
as it is. However if you want to have clean shield, there's one thing abovbe to fix (PTR to nonexistent name). -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto adresu chcem NEDOSTAVAT

Re: Secondary DNS question...

2013-06-21 Thread Matus UHLAR - fantomas
message, it can mean anything. Which MX server started bouncing meil? Is ns1.starionhost.net reachable from that server? -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto adresu chcem NEDOSTAVAT

Re: Secondary DNS question...

2013-06-21 Thread Matus UHLAR - fantomas
I would be interested to hear about any red flags you may see. I don't see any ... since the problems reported were not true, we may assume there was no problem causer by one of your servers' outage. -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I w

Re: How to suppress ADDITIONAL SECTION per zone

2013-06-21 Thread Matus UHLAR - fantomas
On 21.06.13 02:00, blrmaani wrote: The additional-from-auth yes_or_no ; option is a global option. I would like to know if there is a per-zone configuration to do the same in BIND9 configuration? I couldn't find it in BIND9 ARM. What is the point of your question? -- Matus UHLAR - fan

Re: What happens when one out of three NSs are down?

2013-06-12 Thread Matus UHLAR - fantomas
above, authoritative and glue NS records should be the same). But don't tell me that you use TTL so small that someone would notice. -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto ad

Re: [Off-Topic] RE: This list's prefix

2013-06-06 Thread Matus UHLAR - fantomas
. -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto adresu chcem NEDOSTAVAT akukolvek reklamnu postu. - Holmes, what kind of school did you study to be a detective? - Elementary, Watson. --

Re: does zone trump forward?

2013-06-04 Thread Matus UHLAR - fantomas
resubmitting a query after NXDOMAIN is received is an ugly hack and violates the DNS principles. The problem must be solved by DNS tools. -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tu

Re: Bind 9.9.3 configuration message: missing 'file' entry

2013-06-02 Thread Matus UHLAR - fantomas
ers { stealthMasters; }; notify explicit; also-notify { publicSlaves; }; allow-transfer { localhost; transferees; }; }; Have you looked carefuly enough, and to the correct file if there is no missed character that makes the configuration invalid? Have you run named-checkconf w

Re: does zone trump forward?

2013-06-02 Thread Matus UHLAR - fantomas
ould a loop not occur if the forwarder matches this view? local domains are served locally. Only recursive queries are being forwarded. To ask the question another way, does the zone statement take precedence on matching queries over any forwarding? yes. -- Matus UHLAR - fantomas, uh...@fanto

Re: any requests

2013-06-02 Thread Matus UHLAR - fantomas
;t do that. -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto adresu chcem NEDOSTAVAT akukolvek reklamnu postu. Nothing is fool-proof to a tal

Re: Help on NXDOMAIN to try next forwarder in the list

2013-05-31 Thread Matus UHLAR - fantomas
logical to ask again if someone replies THERE IS NO SUCH RECORD. You need to fix your DNS infrastructure, not try to circumvent it's issues. -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie:

Re: Help on NXDOMAIN to try next forwarder in the list

2013-05-31 Thread Matus UHLAR - fantomas
m which are specific authoritative DNS servers to mycompany.com But administrator does not know which one has it So, is that mytestdomain101.com or mycompany.com or mygeo1.mycompany.com? It would be easier to look at the problem if you provided us correct data. -- Matus UHLAR - fantomas, uh..

Re: Negative zones; NXDOMAIN responses

2013-05-21 Thread Matus UHLAR - fantomas
On 21.05.13 11:03, Mark Andrews wrote: >The simplest solution is to slave the root zone and >turn off notify to so you don't spam the official >root servers. 192.5.5.241 is f.root-servers.net. In message <20130521072352.ga17...@fantomas.sk>, Matus UHLAR -

Re: Negative zones; NXDOMAIN responses

2013-05-21 Thread Matus UHLAR - fantomas
oot"; masters { 192.5.5.241; }; notify no; }; I thought this is not oficially recommended for ordinary users to prevent root servers from being overloaded (transfers use much more resources than ordinary lookups). Has this changed? -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http:/

Re: Negative zones; NXDOMAIN responses

2013-05-20 Thread Matus UHLAR - fantomas
e services broken like this of any ISP. I'd even recommend not to use ANY services of such ISPs. -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto adresu chcem NEDOSTAVAT akukolvek reklamnu pos

Re: architecture question

2013-05-09 Thread Matus UHLAR - fantomas
On 09.05.13 10:21, Tony Finch wrote: > Right. Give each student a subdomain of some existing domain, even if the > subdomains aren't publicly delegated. Matus UHLAR - fantomas wrote: yes, so they will start using it in their job and home. On 09.05.13 16:01, Tony Finch w

Re: architecture question

2013-05-09 Thread Matus UHLAR - fantomas
heir job and home. ...I still think it would be better to have reserved private TLD for intranets as we have IP's in rfc1918 (plus rfc6598 for ISPs) -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Va

Re: Mailing list "reply-to" setting

2013-05-08 Thread Matus UHLAR - fantomas
don't like to see. The filtering or diferentiating messages can be done on better way than modifying subject. -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto adresu chcem NEDOSTAVAT

Re: Classless PTR query issue

2013-05-07 Thread Matus UHLAR - fantomas
t way. -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto adresu chcem NEDOSTAVAT akukolvek reklamnu postu. Saving Private Ryan... Private Ryan exists. Overwrite?

Re: How does bind select what master to use?

2013-04-27 Thread Matus UHLAR - fantomas
accessible and their RTT. It tends to prefer theone with shoertet RTT but ocasionally re-tries (RTT can change over time. If notice comes, BIND tends to prefer server that has sent it. -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising

Re: BIND 9.4.x and check-names

2013-04-19 Thread Matus UHLAR - fantomas
bind 9.4 has also "check-names response"; Ok, I'm reading up on that now. Should I be able to suppress the logging using: "check-names response ignore;" ? This should be the default. Also, current version could have better handling of this issue... -- Matus UH

Re: BIND 9.4.x and check-names

2013-04-17 Thread Matus UHLAR - fantomas
13 00:45:37.447 general: warning: zone /IN: gc._msdcs./A: bad owner name (check-names) default.log:12-Apr-2013 00:45:37.447 general: warning: zone /IN: gc._msdcs./A: bad owner name (check-names) Hmm, aren't those supposed to be SRV reco

Re: I'm having thousands of queries a domain isc.org and this increases my cpu percentage to 100%. That may be happening and how I can control this? is an attack? attachment of the log I made an updat

2013-04-16 Thread Matus UHLAR - fantomas
also complain if the service does not work properly if you want to be really a bitch, you can set up recursive view with "." domain providing * records. -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this

Re: I'm having thousands of queries a domain isc.org and this increases my cpu percentage to 100%. That may be happening and how I can control this? is an attack? attachment of the log I made an updat

2013-04-16 Thread Matus UHLAR - fantomas
52538: view external: query (cache) 'hao.360.cn/A/IN' denied Aren't thosedomains pointing their NS onto your nameserver? What's your IP, if it's not secret? -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-ma

Re: Understanding Kaminsky exploit w/bind

2013-04-16 Thread Matus UHLAR - fantomas
why securedns is the only way to avoid this attack. Once the spoofed answer with guessed ID and containing NS records of attacker's servers is accepted, the attacker owns the domain at least within your nameserver. -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning

Re: reverse resolution failing

2013-04-10 Thread Matus UHLAR - fantomas
s to three servers, of which one returns positive answer and two reply NXDOMAIN (no such host). seems someone configured invalid serial to reverse zone and now slaves don't fetch updates... -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-m

Re: clients-per-query increased to 15

2013-04-10 Thread Matus UHLAR - fantomas
ND servers, although you may want to have at least two of them, to have backup if one fails. imho you should first answer my first question and then you see if you need to increase clients-per-query or not. -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT

Re: Simple question about zone and CNAME

2013-04-09 Thread Matus UHLAR - fantomas
ames that don't start with www. is the common case now. Can we save our energy for something more productive? Why did you post this then? -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie:

Re: Some Server not Resolving certain address

2013-04-08 Thread Matus UHLAR - fantomas
lid record? because while delegation NS records are OK, the NS records in domain itself are broken. With the first lookup you may get the answer from the parent servers, but later lookups will use broken NS records and thus they will fail. -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.f

Re: Some Server not Resolving certain address

2013-04-08 Thread Matus UHLAR - fantomas
root dns populate issue or something else? Is there a way to force DNS server to update from root? dopmain positivebrain.asia has invalid NS records. maybe a web DNS checker could provide correct answer, although you must try more of them... -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http

Re: rate limit dns query response ...

2013-04-04 Thread Matus UHLAR - fantomas
firewall level. -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto adresu chcem NEDOSTAVAT akukolvek reklamnu postu. Silvester Stallone: Father of the RISC concept

Re: Forward First on Master Zone (bypass SOA)

2013-03-29 Thread Matus UHLAR - fantomas
like this: On 28.03.13 17:00, Ben-Eliezer, Tal (ITS) wrote: Hi Chris, this looks interesting, I'll do some testing and report back! Note that this way you won't maintain two copies of the same file, but three different files and with each change you'll have to choose where to

Re: Recursion issue

2013-03-28 Thread Matus UHLAR - fantomas
ame result as Chris. Please show us how you do the "dig". -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto adresu chcem NEDOSTAVAT akukolvek reklamnu postu. They that can give up

Re: Recursion issue

2013-03-28 Thread Matus UHLAR - fantomas
answer the authoritative data. You have said you do not have recursion allowed, why do you expect it to be allowed now? -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto adresu chcem NEDOSTAVAT

Re: Suspecious DNS traffic

2013-03-25 Thread Matus UHLAR - fantomas
l incoming traffic to your DNS server where source port is 53. all the "security" is useless if blocks your service. Luckily, most of firewalls can track the "connection" state. -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to rece

Re: Setting a timeout for forwarders

2013-03-25 Thread Matus UHLAR - fantomas
ve DNS that are declared as a forwarder in the named.conf.options settings. Why do you define such forwarders in named.conf at all? -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto adresu c

Re: querying TLD nameservers - limitations

2013-03-25 Thread Matus UHLAR - fantomas
. Are there other limitations I should be aware of while developing my script? Yes, you should not abuse any service, whether you monitor it or not. For example, you should not send extensive queries to foreign servers. -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warni

Re: Suspecious DNS traffic

2013-03-25 Thread Matus UHLAR - fantomas
from TCP+UDP port 53 coming to any >=1024 port on your nameserver. -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto adresu chcem NEDOSTAVAT akukolvek reklamnu postu. The only substitute for g

Re: 100% CPU / wedge with 9.8.3-P4 & RPZ?

2013-03-16 Thread Matus UHLAR - fantomas
27;t see anything in the release notes for 9.8.4/9.8.5 - any ideas? This is with the Spamhaus DBL, in case it matters. do you have local copy of spamhaus DBL? -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address

Re: How to optimize dns requests

2013-03-15 Thread Matus UHLAR - fantomas
l.com : ; <<>> DiG 9.8.1-P1 <<>> mail.com [...] ;; flags: qr rd ra; QUERY: 1, ANSWER: 1, AUTHORITY: 0, ADDITIONAL: 0 this is clearly a cached answer (aa flag is missing). How did you come to the conclusion that caching does not work? -- Matus UHLAR - fanto

Re: forwarding & query-source (was Re: name caching and forwarding)

2013-03-05 Thread Matus UHLAR - fantomas
ed AS number for this, provider-independent IP Addresses are quite enough (at least here in Europe) I just did not want to explain this more deeply - that is question for the OP and their ISP. -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e

Re: forwarding & query-source (was Re: name caching and forwarding)

2013-03-02 Thread Matus UHLAR - fantomas
ssibly detect the link outage sooner and switch to another link, maybe with NATting to other IP. However, your DNS problem chould be solved by BIND configuration. -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this addre

Re: How to flush MX records from the cache

2013-02-28 Thread Matus UHLAR - fantomas
On 28.02.13 08:41, Abdul Khader wrote: Is there a way to flush MX records from the cache of a caching DNS server ? No. You only can flush whole cache (rndc flush) or flush records for given domain (rndc flushname). -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning

Re: Problems with resolving a local tld

2013-02-28 Thread Matus UHLAR - fantomas
re people just can not put their own domain anywhere in the DNS tree, because they simply do not have any domain seen in the public available (no company's domain, using multiple ISPs etc) -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-m

Re: allow-recursion slowing server to crawl

2013-02-28 Thread Matus UHLAR - fantomas
said: ANYONE, DO NOT ALLOW RECURSION FOR OUTSIDE CLIENTS. EVER. -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto adresu chcem NEDOSTAVAT akukolvek reklamnu postu. Boost your system's sp

Re: Unwanted resolver usage of /etc/host.conf

2013-02-24 Thread Matus UHLAR - fantomas
file. -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto adresu chcem NEDOSTAVAT akukolvek reklamnu postu. Microsoft dick is soft to do no harm

Re: Most specific match on PTR records

2013-02-22 Thread Matus UHLAR - fantomas
-stub; server-addresses { 192.168.1.23; 192.168.1.24; }; }; so a "type static-stub" works, while "type forward" does not? Is this another difference between those two types? ("type forward" has one advantage: it allows standard resolving to

Re: allow-query and views

2013-02-21 Thread Matus UHLAR - fantomas
is really allowed. Then what is the basic recursion option for now? Is it just a hold-over from more trusting days? it's kind of general switch to allow/deny recursion. -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertisi

Re: allow-query and views

2013-02-21 Thread Matus UHLAR - fantomas
rticularly when we are suppose to have different views for different clients. So for my internal view where I: match-clients{ httnets; }; match-destinations{ httnets; }; recursion yes; allow-query{ httnets; }; On 02/21/2013 10:40 AM, Matus UHLAR - fantomas wrote

Re: Resolver behavior on expired TTLs

2013-02-21 Thread Matus UHLAR - fantomas
searching. -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto adresu chcem NEDOSTAVAT akukolvek reklamnu postu. How does cat play with mouse? cat /dev/mouse __

Re: allow-query and views

2013-02-21 Thread Matus UHLAR - fantomas
he httnets ACL? , so nothing should be querying cache? correct, no external hosts should query your cache. -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto adresu chcem NEDOSTAVAT

Re: BIND master , Windows 2008 stub zone not transferring

2013-02-21 Thread Matus UHLAR - fantomas
or NS records for the BIND to know who to ask for records. -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto adresu chcem NEDOSTAVAT akukolvek reklamnu postu. Spam = (S)tupid (P)eople's (A)dve

Re: broken ISP in china

2013-02-18 Thread Matus UHLAR - fantomas
. expire 604800 change that to 4w not needed but and negative cache value 86400 drop that to no more than 3600, maybe even just use 600. I agree with this one. Value 86400 for negative cache is widely used, but mostly from obsolete understanding of SOA field name "minimum". -- Ma

Re: Difference between multiple NS and NS having multiple A

2013-02-18 Thread Matus UHLAR - fantomas
ny of them. when BIND (or whomever) logs nameserver it should log both name IP. -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto adresu chcem NEDOSTAVAT akukolvek reklamnu postu. My mind is l

Re: question about dns query distribution

2013-02-08 Thread Matus UHLAR - fantomas
reason behind it that both servers' having queries ? there are cases where DNS resolver sorts IP addresses and thus prefersone of them. There are also cases where DNS resolver measures response time and uses the faster DNS server. -- Matus UHLAR - fantomas, uh...@fantomas.sk ;

Re: reverse resolution failing

2013-02-07 Thread Matus UHLAR - fantomas
184.142.in-addr.arpa. Saturn works OK for most questions, and returns a PTR record if you ask for ANY, but if you request a PTR directly it ignores you. some kind of lame DNS "load balancers"? -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish N

Re: lame-servers: error (FORMERR) resolving [something]

2013-01-22 Thread Matus UHLAR - fantomas
getting non-authoritative responses, but with recursion allowed. Both are unexpected so named complains. -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto adresu chcem NEDOSTAVAT akukolvek rek

Re: Wildcard CNAME record?

2013-01-16 Thread Matus UHLAR - fantomas
Matus UHLAR - fantomas wrote: On 16.01.13 14:57, Baird, Josh wrote: > Is it acceptable to have a wildcard CNAME? Example: > > * IN CNAMEsomewhere.com. > > Or, would it be advised to only use wildcard 'A' records? while it is t

Re: Wildcard CNAME record?

2013-01-16 Thread Matus UHLAR - fantomas
ble to use solutions that require wildcards ;-) -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto adresu chcem NEDOSTAVAT akukolvek reklamnu postu. They that can give up essential libert

Re: lame-servers: error (FORMERR) resolving [something]

2013-01-08 Thread Matus UHLAR - fantomas
onality. I advise check with more of them, since there's none I would completely trust. -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto adresu chcem NEDOSTAVAT akukolvek reklamnu pos

Re: zone files in bind-9.9

2013-01-06 Thread Matus UHLAR - fantomas
should do -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto adresu chcem NEDOSTAVAT akukolvek reklamnu postu. Support bacteria - they're the only culture s

<    1   2   3   4   5   6   7   8   9   10   >