1. Advertising
    y u no do it?

    Advertising (learn more)

    Advertise virtually anything here, with CPM banner ads, CPM email ads and CPC contextual links. You can target relevant areas of the site and show ads based on geographical location of the user if you wish.

    Starts at just $1 per CPM or $0.10 per CPC.

Explain DNS poisoning please? Why everyone should worry

Discussion in 'Site & Server Administration' started by mcfox, Apr 11, 2006.

  1. #1
    Ok, I've been keeping up ... sorta ... with this thread on WMW about DNS poisoning and have read this latest thread on Threadwatch (earlier one here) and I just can't seem to get my head round it all.

    I would appreciate it if a few kind individuals would take a few minutes to explain this phenomenon of DNS cache poisoning.

    The results I get from www.dnsreport.com, while they appear to be comprehensive, also mean very little to my 'copy' / 'paste' orientated brain :eek:
     
    mcfox, Apr 11, 2006 IP
    yo-yo and Jat like this.
  2. forkqueue

    forkqueue Guest

    Messages:
    401
    Likes Received:
    21
    Best Answers:
    0
    Trophy Points:
    0
    #2
    IMO the uproar is 60% link bait and 40% confusion. Make sure recursion is disabled on your server and don't worry.

    Basically the problem is this:


    • Spammer buys domain give-me-cheap-viagra-please.com
    • Spammer now changes his DNS records to point at your server
    • It now looks as though you're the spammer

    Unfortunately, this issue has got confused with DNS poisoning attacks, for example where www.google.com goes to an IP address controller by the attacker. For this to happen the client (or the DNS server they are using) needs to be vulnerable. The act of you running a DNS server which allows recursion has no bearing on this situation. Just because you run a DNS server which allows recursion, you aren't going to suddenly find that someone has stolen all your adsense revenue.

    Turn off recursion, make sure your DNS daemon is up to date and stop worrying.
     
    forkqueue, Apr 12, 2006 IP
    mcfox likes this.
  3. mcfox

    mcfox Wind Maker

    Messages:
    7,526
    Likes Received:
    716
    Best Answers:
    0
    Trophy Points:
    360
    #3
    Thanks for that. I wouldn't say 'worried' so much as 'wtf does that all mean?' :)

    I thought I had a grasp of it but it seems the more I read, the more confused I get about the whole dns recursion / poisoning thing. I think I will file it under the same category as pagerank in the 'don't give a f*** section' of my brain.
     
    mcfox, Apr 12, 2006 IP
  4. ronmojohny

    ronmojohny Active Member

    Messages:
    729
    Likes Received:
    20
    Best Answers:
    0
    Trophy Points:
    68
    #4
    I'm pretty sure I'm a victim of DNS cache poisioning. My traffic has dropped 90% while my ranking have not changed, I purchased software called "adsense checker" and found that my top 3 pages were not displaying any adsense code... I did a traceroute on my site, and it goes from the US to singapore, germany, then back to my ISP.. and I changed ISP's recently to see if that would stop the problem.. it did, for about 3 hours, then the traffic slowed again.
    This is serious stuff and I'm losing hundreds of dollars a day because of it.
     
    ronmojohny, Aug 20, 2006 IP
  5. ronmojohny

    ronmojohny Active Member

    Messages:
    729
    Likes Received:
    20
    Best Answers:
    0
    Trophy Points:
    68
    #5
    Does anyone know about DNS cache poisoning? I now think my old hosting company is involved, they won't let me log into my old server.. to take down my old pages, and do a 301 permanent redirect to my new site, and since they were my old DNS severs as well, could they just continually poison the DNS cache and steal my traffic?
     
    ronmojohny, Aug 23, 2006 IP
  6. theblight

    theblight Peon

    Messages:
    246
    Likes Received:
    9
    Best Answers:
    0
    Trophy Points:
    0
    #6
    Configure you dns in a split view or stealth to avoid the recursion
     
    theblight, Aug 24, 2006 IP
  7. mcfox

    mcfox Wind Maker

    Messages:
    7,526
    Likes Received:
    716
    Best Answers:
    0
    Trophy Points:
    360
    #7
    I think I speak for most people when I say, "Huh?"
    :p
     
    mcfox, Aug 25, 2006 IP
  8. theblight

    theblight Peon

    Messages:
    246
    Likes Received:
    9
    Best Answers:
    0
    Trophy Points:
    0
    #8
    theblight, Aug 25, 2006 IP