LinuxQuestions.org
Visit Jeremy's Blog.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Server
User Name
Password
Linux - Server This forum is for the discussion of Linux Software used in a server related context.

Notices


Reply
  Search this Thread
Old 08-21-2009, 02:26 PM   #1
schapman43
LQ Newbie
 
Registered: May 2005
Posts: 24

Rep: Reputation: 15
Reverse DNS lookup question


OK, the guy who normally takes care of this sort of thing is out of vacation so I've been asked to look at it. Unfortunately I'm a linux newb and need direction. We were recently alerted to the fact that our DNS server did a reverse lookup on an IP address owned by UKrTelegroup (85.255.112.58). As some of you know already this is a well known company hosting fake DNS servers for DNS poisoning and such. So what I need to do is search the logs for this address and try to find out what initiated this lookup. I know how to use grep and believe the log file I need to look at is in /var/log. I am under the impression that the file I'm looking for is messages, is that correct? I've dug around through /var/log and couldn't find anything using grep -i 82.255.112.58 /var/log/*. Can anyone point me in the right direction?
 
Old 08-21-2009, 03:19 PM   #2
bathory
LQ Guru
 
Registered: Jun 2004
Location: Piraeus
Distribution: Slackware
Posts: 13,163
Blog Entries: 1

Rep: Reputation: 2032Reputation: 2032Reputation: 2032Reputation: 2032Reputation: 2032Reputation: 2032Reputation: 2032Reputation: 2032Reputation: 2032Reputation: 2032Reputation: 2032
IF it isn't in /var/log, take a look in /etc/named.conf under the logging section, to find where bind saves its logs.
Mind that if you're running named chrooted, the path to the logfile is relative to the chroot directory.
To find the chroot directory
Code:
run ps -ef|grep named
The chroot path is the atgument of the -t option
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
how do i perform an reverse dns lookup? HyperTrey Linux - Networking 4 05-23-2008 08:48 AM
reverse DNS lookup mimithebrain Linux - Networking 5 06-08-2006 08:28 AM
DNS Reverse lookup problem pazvant Linux - Networking 3 10-10-2005 06:36 AM
Reverse DNS lookup, or any way to contact an IP.. MasterC Linux - Networking 6 02-21-2003 03:34 AM
reverse DNS lookup phil1076 Linux - General 1 01-22-2002 03:24 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Server

All times are GMT -5. The time now is 08:40 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration