pete Posted November 19, 2012 Posted November 19, 2012 Anyone else spotted that Someone Has Done Something Over The Weekend? Using the LSN ep1 forwarders, I'm seeing nslookup returning queries as google.com.lincs.sch.uk (for example) and instead of a 404 for invalid domains, I'm getting an OpenDNS page with (among other things) pregnancy test adverts. Invalid URLS are all being redirected to 67.215.65.132 (OpenDNS). Ticket is open, just wondering if anyone else has noticed it.
Geoff Posted November 19, 2012 Posted November 19, 2012 So Lincolnshire DNS uses OpenDNS for upstream queries? That's not exactly playing by the rules. OpenDNS will probably ban the forwarders as soon as they notice the traffic volumes.
pete Posted November 19, 2012 Author Posted November 19, 2012 (edited) So Lincolnshire DNS uses OpenDNS for upstream queries? That's not exactly playing by the rules. OpenDNS will probably ban the forwarders as soon as they notice the traffic volumes. No, it shouldn't be using it at all, hence the WTF? this morning. Don't know whether it's deliberate, a band-aid while they fix an underlying problem or a foul-up. All I know is that when I send an invalid domain to their DNS servers it sends a response that corresponds to the IP of an OpenDNS server. Edited November 19, 2012 by pete
tommej Posted November 19, 2012 Posted November 19, 2012 Noticing the same thing here. Perhaps this was the temporary fix in response to the DDOS attack on tuesday.
pete Posted November 20, 2012 Author Posted November 20, 2012 Heard back - it's apparently a band-aid due to KCOM DNS being unreliable. Which KCOM will be fixing RealSoon .
pete Posted February 13, 2013 Author Posted February 13, 2013 (edited) And this is still ongoing and causing issues with SSL requests ("I can't find that website, so I'll respond with an OpenDNS SSL cert, that's cool, right?") Can other people start poking Mouchel and KCOM please, because this is silly now. Mouchel say it's a KCOM issue, so if that's the case others using KCOM DNS should be getting dodgy service as well. Edited February 13, 2013 by pete
Geoff Posted February 13, 2013 Posted February 13, 2013 Are the ports for DNS filtered? If not, don't use the forwarders?
pete Posted February 14, 2013 Author Posted February 14, 2013 Are the ports for DNS filtered? If not, don't use the forwarders? They're not and that's my temporary workaround, but there's a fair bit of internal stuff that's not published to external DNS and it's not grouped in a manner that makes setting up exceptions for those things easy.
Geoff Posted February 14, 2013 Posted February 14, 2013 Intercept and redirect DNS traffic going to the LSN DNS servers at your network border to go somewhere else. Probably your main internal DNS forwarder that's talking to the root the DNS servers.
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now