LinuxQuestions.org
Share your knowledge at the LQ Wiki.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Other *NIX Forums > AIX
User Name
Password
AIX This forum is for the discussion of IBM AIX.
eserver and other IBM related questions are also on topic.

Notices


Reply
  Search this Thread
Old 06-20-2006, 07:56 AM   #1
looseCannon
Member
 
Registered: Dec 2003
Location: Little Rock, AR
Distribution: Fedora Core 2, AIX, HP-UX, Solaris, Whitebox
Posts: 193

Rep: Reputation: 31
Question Named giving bogus IP?


We've had a rash of servers getting bogus IP addresses lately and all of them are using the same DNS server. That DNS server is running on AIX 5.3 MR 3. The DNS server is set up to forward to another set of DNS servers if it cannot resolve the address that is being searched for. The AIX DNS server is a subdomain, the 'forwarders' are in the parent domain.

aaa.bbb.com <<< AIX
bbb.com <<< forwarders

If you search for something, without a domain supplied, and the DNS server doesn't know about it, it will respond with a bogus IP. For instance, if I search for blahblah and the DNS server knows nothing about it, then it will respond with an address of 204.251.15.190, even if it is in the parent domain bbb.com. I would expect it to say 'couldn't find that address'.

If I update /etc/resolv.conf to include 'search bbb.com' then I will get the correct response for the address.

I've checked out the config files for the DNS server and can't find the bogus IP in them anywhere, which makes this more confusing...

Help???
 
Old 06-21-2006, 03:45 AM   #2
nukkel
Member
 
Registered: Mar 2003
Location: Belgium
Distribution: Hardened gentoo
Posts: 323

Rep: Reputation: 30
I think your 'parent' ISP is one of those braindead ISPs, who configure their DNS servers so that when they get a query for a non-existing domain name, they send you to some ad site (instead of replying with a "no such domain" message, as they should). Just surf to that IP address and it should be obvious. Sadly, this is becoming more and more standard practice...

So basically, there's nothing wrong with your set-up.
Best thing to do is complain to your ISP, tell them they violate RFC standards and engage in the general detriment of the world wide web; or even better switch to another ISP and tell your current one why you took your business elsewhere

Best regards,
nukkel
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
Renamed bogus "/var/mail/macleanl" into "/var/mail/BOGUS.macleanl.xPVB" paul_mat Linux - Networking 1 07-04-2006 12:50 PM
Bogus logical sector Jeebizz Slackware 4 01-07-2005 05:57 PM
Bogus XP systems on ebay etc beagle2 General 1 11-05-2004 04:51 AM
cannot find named.conf and /var/named kaushikma Red Hat 1 02-07-2004 12:49 PM
Virtual Host type, named or IP via SSL? Named VH is not possible? piratebiter Linux - Security 3 08-20-2003 05:27 PM

LinuxQuestions.org > Forums > Other *NIX Forums > AIX

All times are GMT -5. The time now is 03:57 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration