operating web site not accessible through certain providers
Linux - NetworkingThis forum is for any issue related to networks or networking.
Routing, network cards, OSI, etc. Anything is fair game.
Notices
Welcome to LinuxQuestions.org, a friendly and active Linux Community.
You are currently viewing LQ as a guest. By joining our community you will have the ability to post topics, receive our newsletter, use the advanced search, subscribe to threads and access many other special features. Registration is quick, simple and absolutely free. Join our community today!
Note that registered members see fewer ads, and ContentLink is completely disabled once you log in.
If you have any problems with the registration process or your account login, please contact us. If you need to reset your password, click here.
Having a problem logging in? Please visit this page to clear all LQ-related cookies.
Get a virtual cloud desktop with the Linux distro that you want in less than five minutes with Shells! With over 10 pre-installed distros to choose from, the worry-free installation life is here! Whether you are a digital nomad or just looking for flexibility, Shells can put your Linux machine on the device that you want to use.
Exclusive for LQ members, get up to 45% off per month. Click here for more info.
operating web site not accessible through certain providers
Please re-direct me if this is not the proper forum...
The site aviationweather.gov is suddenly unavailable to me via my Charter service (on 3 different OS's, 3 browsers). Traceroute shows packets getting to the right area (NOAA Boulder) but stopping short. Tried different DNS and multiple IP addresses for the site, nothing helps except going through another provider or using anonymouse.org. Charter doesn't have a clue and neither do I. What could be the problem?
How frequent are your requests? What is the nature of your requests - all web page hits or other service requests?
It is possible/likely that you have tripped some access control rule that has resulted in your IP being effectively blacklisted or dropped by the server.
If not your specific IP, it is also possible that another Charter subscriber on your subnet has abused the server and the subnet has been blocked.
If it does not clear after some period of time, you might contact the site and enquire.
How frequent are your requests? What is the nature of your requests - all web page hits or other service requests?
It is possible/likely that you have tripped some access control rule that has resulted in your IP being effectively blacklisted or dropped by the server.
If not your specific IP, it is also possible that another Charter subscriber on your subnet has abused the server and the subnet has been blocked.
If it does not clear after some period of time, you might contact the site and enquire.
Once or twice a day. I thought of contacting the site but find it hard to find an email address. Is there a good way of determining a point of contact for a server? This has been going on for about 6 days.
Once or twice a day. I thought of contacting the site but find it hard to find an email address. Is there a good way of determining a point of contact for a server? This has been going on for about 6 days.
Then it is likely due to another Charter subscriber having abused the site.
No magic for finding a contact, just browser the site (from another location or via proxy) and pick a starting point.
It might be easier to ask Charter if they can assign you a new IP address on a different subnet.
*** ADDITION: Are you CERTAIN that your own devices have not been hijacked to participate in a botnet? Always a possibility and worth looking into.
*** ADDITION: Are you CERTAIN that your own devices have not been hijacked to participate in a botnet? Always a possibility and worth looking into.
No but Android, IOS, Linux and Windows machines produce the same result. How do I check for botnet hijack? Also, this happens when router is removed. Direct connection to modem.
If they share the same modem, with or without the router, then the IP address shown to the internet will be the same for all.
The easiest visible indication of bot net compromise is continuous traffic from the device when it is idle. It can be the router itself that is compromised as well, so if the modem is busy with no computers turned on but router connected, that is a clue.
If your router makes traffic/logs accessible to you, sift through them for signs of unusual taffic.
You can use netstat on the Linux/Andriod(?)/iOS(?) devices to look for unusual activity.
I have no knowledge of Window$ but it should have some sismilar facility (I would just consider a Window$ machine compromised and just turn it off though... but thats just me ).
Again, Charter should be able to provide some information about your outgoing traffic as well.
Once or twice a day. I thought of contacting the site but find it hard to find an email address. Is there a good way of determining a point of contact for a server? This has been going on for about 6 days.
Turns out I've made progress on this and have found that Charter users on a certain (widely geographically distributed) subnet (66.x.x.x ) are all affected. The reason for this is unclear but could be the result of Charter using a certain protocol (WCCP) that results in data not being returned properly. At any rate, the work around was to ask Charter to put me on a different subnet.
LinuxQuestions.org is looking for people interested in writing
Editorials, Articles, Reviews, and more. If you'd like to contribute
content, let us know.