LinuxQuestions.org
Support LQ: Use code LQ3 and save $3 on Domain Registration
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Server
User Name
Password
Linux - Server This forum is for the discussion of Linux Software used in a server related context.

Notices

Reply
 
Search this Thread
Old 08-21-2009, 02:26 PM   #1
schapman43
LQ Newbie
 
Registered: May 2005
Posts: 24

Rep: Reputation: 15
Reverse DNS lookup question


OK, the guy who normally takes care of this sort of thing is out of vacation so I've been asked to look at it. Unfortunately I'm a linux newb and need direction. We were recently alerted to the fact that our DNS server did a reverse lookup on an IP address owned by UKrTelegroup (85.255.112.58). As some of you know already this is a well known company hosting fake DNS servers for DNS poisoning and such. So what I need to do is search the logs for this address and try to find out what initiated this lookup. I know how to use grep and believe the log file I need to look at is in /var/log. I am under the impression that the file I'm looking for is messages, is that correct? I've dug around through /var/log and couldn't find anything using grep -i 82.255.112.58 /var/log/*. Can anyone point me in the right direction?
 
Old 08-21-2009, 03:19 PM   #2
bathory
Guru
 
Registered: Jun 2004
Location: Piraeus
Distribution: Slackware
Posts: 10,897

Rep: Reputation: 1322Reputation: 1322Reputation: 1322Reputation: 1322Reputation: 1322Reputation: 1322Reputation: 1322Reputation: 1322Reputation: 1322Reputation: 1322
IF it isn't in /var/log, take a look in /etc/named.conf under the logging section, to find where bind saves its logs.
Mind that if you're running named chrooted, the path to the logfile is relative to the chroot directory.
To find the chroot directory
Code:
run ps -ef|grep named
The chroot path is the atgument of the -t option
 
  


Reply


Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
reverse DNS lookup mimithebrain Linux - Networking 6 02-10-2011 12:53 AM
how do i perform an reverse dns lookup? HyperTrey Linux - Networking 4 05-23-2008 08:48 AM
DNS Reverse lookup problem pazvant Linux - Networking 3 10-10-2005 06:36 AM
Reverse DNS lookup, or any way to contact an IP.. MasterC Linux - Networking 6 02-21-2003 03:34 AM
reverse DNS lookup phil1076 Linux - General 1 01-22-2002 03:24 PM


All times are GMT -5. The time now is 03:43 PM.

Main Menu
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
identi.ca: @linuxquestions
Facebook: linuxquestions Google+: linuxquestions
Open Source Consulting | Domain Registration