LinuxQuestions.org
Latest LQ Deal: Latest LQ Deals
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Networking
User Name
Password
Linux - Networking This forum is for any issue related to networks or networking.
Routing, network cards, OSI, etc. Anything is fair game.

Notices


Reply
  Search this Thread
Old 08-11-2015, 04:33 PM   #1
leeelson
LQ Newbie
 
Registered: Apr 2010
Posts: 6

Rep: Reputation: 0
operating web site not accessible through certain providers


Please re-direct me if this is not the proper forum...

The site aviationweather.gov is suddenly unavailable to me via my Charter service (on 3 different OS's, 3 browsers). Traceroute shows packets getting to the right area (NOAA Boulder) but stopping short. Tried different DNS and multiple IP addresses for the site, nothing helps except going through another provider or using anonymouse.org. Charter doesn't have a clue and neither do I. What could be the problem?
 
Old 08-11-2015, 04:38 PM   #2
astrogeek
Moderator
 
Registered: Oct 2008
Distribution: Slackware [64]-X.{0|1|2|37|-current} ::12<=X<=15, FreeBSD_12{.0|.1}
Posts: 6,263
Blog Entries: 24

Rep: Reputation: 4194Reputation: 4194Reputation: 4194Reputation: 4194Reputation: 4194Reputation: 4194Reputation: 4194Reputation: 4194Reputation: 4194Reputation: 4194Reputation: 4194
How frequent are your requests? What is the nature of your requests - all web page hits or other service requests?

It is possible/likely that you have tripped some access control rule that has resulted in your IP being effectively blacklisted or dropped by the server.

If not your specific IP, it is also possible that another Charter subscriber on your subnet has abused the server and the subnet has been blocked.

If it does not clear after some period of time, you might contact the site and enquire.

Last edited by astrogeek; 08-11-2015 at 04:40 PM.
 
Old 08-11-2015, 04:42 PM   #3
leeelson
LQ Newbie
 
Registered: Apr 2010
Posts: 6

Original Poster
Rep: Reputation: 0
Quote:
Originally Posted by astrogeek View Post
How frequent are your requests? What is the nature of your requests - all web page hits or other service requests?

It is possible/likely that you have tripped some access control rule that has resulted in your IP being effectively blacklisted or dropped by the server.

If not your specific IP, it is also possible that another Charter subscriber on your subnet has abused the server and the subnet has been blocked.

If it does not clear after some period of time, you might contact the site and enquire.
Once or twice a day. I thought of contacting the site but find it hard to find an email address. Is there a good way of determining a point of contact for a server? This has been going on for about 6 days.
 
Old 08-11-2015, 04:48 PM   #4
astrogeek
Moderator
 
Registered: Oct 2008
Distribution: Slackware [64]-X.{0|1|2|37|-current} ::12<=X<=15, FreeBSD_12{.0|.1}
Posts: 6,263
Blog Entries: 24

Rep: Reputation: 4194Reputation: 4194Reputation: 4194Reputation: 4194Reputation: 4194Reputation: 4194Reputation: 4194Reputation: 4194Reputation: 4194Reputation: 4194Reputation: 4194
Quote:
Originally Posted by leeelson View Post
Once or twice a day. I thought of contacting the site but find it hard to find an email address. Is there a good way of determining a point of contact for a server? This has been going on for about 6 days.
Then it is likely due to another Charter subscriber having abused the site.

No magic for finding a contact, just browser the site (from another location or via proxy) and pick a starting point.

It might be easier to ask Charter if they can assign you a new IP address on a different subnet.

*** ADDITION: Are you CERTAIN that your own devices have not been hijacked to participate in a botnet? Always a possibility and worth looking into.

Last edited by astrogeek; 08-11-2015 at 04:52 PM.
 
Old 08-11-2015, 05:02 PM   #5
leeelson
LQ Newbie
 
Registered: Apr 2010
Posts: 6

Original Poster
Rep: Reputation: 0
Quote:
Originally Posted by astrogeek View Post



*** ADDITION: Are you CERTAIN that your own devices have not been hijacked to participate in a botnet? Always a possibility and worth looking into.
No but Android, IOS, Linux and Windows machines produce the same result. How do I check for botnet hijack? Also, this happens when router is removed. Direct connection to modem.

Last edited by leeelson; 08-11-2015 at 05:05 PM.
 
Old 08-11-2015, 05:15 PM   #6
astrogeek
Moderator
 
Registered: Oct 2008
Distribution: Slackware [64]-X.{0|1|2|37|-current} ::12<=X<=15, FreeBSD_12{.0|.1}
Posts: 6,263
Blog Entries: 24

Rep: Reputation: 4194Reputation: 4194Reputation: 4194Reputation: 4194Reputation: 4194Reputation: 4194Reputation: 4194Reputation: 4194Reputation: 4194Reputation: 4194Reputation: 4194
If they share the same modem, with or without the router, then the IP address shown to the internet will be the same for all.

The easiest visible indication of bot net compromise is continuous traffic from the device when it is idle. It can be the router itself that is compromised as well, so if the modem is busy with no computers turned on but router connected, that is a clue.

If your router makes traffic/logs accessible to you, sift through them for signs of unusual taffic.

You can use netstat on the Linux/Andriod(?)/iOS(?) devices to look for unusual activity.

I have no knowledge of Window$ but it should have some sismilar facility (I would just consider a Window$ machine compromised and just turn it off though... but thats just me ).

Again, Charter should be able to provide some information about your outgoing traffic as well.

Last edited by astrogeek; 08-11-2015 at 05:19 PM.
 
Old 08-30-2015, 02:08 PM   #7
Neville Hillyer
Member
 
Registered: Jul 2015
Posts: 57

Rep: Reputation: Disabled
Quote:
Originally Posted by leeelson View Post
Once or twice a day. I thought of contacting the site but find it hard to find an email address. Is there a good way of determining a point of contact for a server? This has been going on for about 6 days.
You could try: ncep.awc.avwx@noaa.gov
 
Old 08-30-2015, 05:06 PM   #8
leeelson
LQ Newbie
 
Registered: Apr 2010
Posts: 6

Original Poster
Rep: Reputation: 0
UPDATE (solved-sort of)

Turns out I've made progress on this and have found that Charter users on a certain (widely geographically distributed) subnet (66.x.x.x ) are all affected. The reason for this is unclear but could be the result of Charter using a certain protocol (WCCP) that results in data not being returned properly. At any rate, the work around was to ask Charter to put me on a different subnet.
 
Old 08-30-2015, 06:05 PM   #9
astrogeek
Moderator
 
Registered: Oct 2008
Distribution: Slackware [64]-X.{0|1|2|37|-current} ::12<=X<=15, FreeBSD_12{.0|.1}
Posts: 6,263
Blog Entries: 24

Rep: Reputation: 4194Reputation: 4194Reputation: 4194Reputation: 4194Reputation: 4194Reputation: 4194Reputation: 4194Reputation: 4194Reputation: 4194Reputation: 4194Reputation: 4194
Glad to hear that worked! Thanks for updating us!

Now if they will just remember to assign you to the different subnet across power outages and modem reboots!
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
block particular web site form multiple site hosted web server and allow others lasantha Linux - Security 2 08-17-2010 01:49 PM
block particular web site form multiple site hosted web server and allow others lasantha Linux - Security 1 08-17-2010 12:09 PM
site accessible on 2 servers rockymaxsource Linux - Server 1 04-27-2007 01:46 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - Networking

All times are GMT -5. The time now is 07:14 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration