Jump to content

Recommended Posts

Posted (edited)

What a brilliant start to the week. Visitors to our website are being shown the following page this morning:

domain down 1.jpg

 

It seems that, somehow, our main DNS record has been hijacked from our usual address to 209.99.40.222, owned by Confluence Networks in Austin TX.

 

I've opened a support ticket with CSNewMedia (@CSNM-Carl) who host our DNS Zone File, to see if they can shed any light on the idea, because I've no idea. Our DNS Zone File there is correct, so I suspect it's a poisoned DNS server somewhere upstream, but if anyone has got any ideas on how it's happened (and would that have been preventable?) and anything I can do to mitigate, I'm all ears. I've already updated our zone file with new TTL values to try and trigger a new propogation but I'm conscious that this is a problem that is probably not our fault but is making us look stupid.

 

Might also be worth you all checking your own websites; our school.org address was fine, but our school.county.sch.uk is incorrect (although only in the UK, interestingly - seems to be correct abroad).

Edited by sonofsanta
Posted
A DNS lookup showed this:

[TD="class: dClass"]
[TD="class: hostName"]dns11.parkpage.foundationapi.com. abuse.opticaljungle.com. 2011062801 3600 900 604800 86400

Posted

Just had a (speedy) reply from @CSNM-Carl on the support ticket:

Good Morning,

 

There has been a problem with our csnewmedia.com domain name which is used for domains nameservers. The issue has been resolved but it is going to take a few hours for things to fully propagate again.

 

Please accept our apologies for the issue.

 

Warm Regards,

 

Carl Shepherdson

 

For the record: internal access was fine as we have the domain set up internally on our DCs, to redirect certain external services on subdomains directly to their internal IP. The problem only manifested on external connections. Google's DNS servers seem to be fine, but BT Broadband's are certainly poisoned. That may be why the problem isn't showing up for some of you, if the poisoned records aren't propogated evenly.

 

So this is more of a heads up now: if, like me, you've taken advantage of CSNM's wonderfully generous free hosting, be prepared for some phone calls in case you were affected as well.

 

Massive disclaimer: none of this is intended as an attack on CSNM or a complaint about their services, it's just me panicking that I've done something stupid again. I'd still thoroughly recommend 'em as DNS hosts, especially for the price of free.

  • Thanks 1
Posted
... I suspect it's a poisoned DNS server somewhere upstream ...
"Poisoned" implies deliberate intent, whereas posts lower down seem to indicate that this is something broken in your DNS provider's infrastructure.

 

If you set your TTLs (time-to-live) to something like five minutes, this won't produce much more load on your DNS servers, but should allow you to fix any future problems within five minutes, plus however long your DNS provider takes to reload your zone. Any "poisoned" DNS servers, wherever they are, should refresh any cached RRs at least every five minutes.

 

Personally, if you are using a free DNS service, I would suggest that you are likely to get what you pay for :)

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...