Strange DNS Problems
I've been experiencing random a DNS lookup problem that is ongoing (using slackware64-current). Here is what happened last night:
1. Opened Firefox and tried to go to www.cnn.com. 2. Firefox loaded the Washington Post's web site, but the URL said www.cnn.com and the favicon was for CNN. 3. Opened a terminal and ran 'traceroute www.cnn.com' to which it reported that there were two IPs available, so it was picking one. I've had this happen for other sites. I'm not sure what is causing my DNS cache to get corrupted like this. I have two other laptops on the network running Windows, and this doesn't happen, so I'm pretty sure it isn't ISP or router related. I also tried changing my DNS servers in my router to Google's DNS servers just to check, and I'm still having this problem. |
Are you running bind on the local machine? Have you checked the hosts file? What does your resolv.conf look like? If you manually resolve an address off one of the servers in the resolv.conf file does it work correctly? Has the machine been compromised at anytime that you're aware of? Have you checked to see if there are any well known root kits installed?
|
I'll check the files tonight and post them on here. In the meantime, I can answer some of the other questions.
1. I'm not running bind. 2. The machine has not been compromised, to my knowledge. I can run a rootkit scan again tonight, but I seriously doubt that is the issue. |
I just ran a scan with chkrootkit and rkhunter, and they didn't find anything. Here is a copy of my /etc/resolve.conf file:
Code:
# Generated by dhcpcd from wlan0 |
*bump*
Still having this problem... |
Hi,
Quote:
Quote:
Quote:
|
The wi.rr.com domain is from my ISP. It's a valid domain. As for the DNS servers (8.8.8.8 and 8.8.4.4), those are Google's servers. As I mentioned in my original post, I changed from my ISP's DNS servers to Google's to see if it was a problem with my ISP's DNS servers. 192.168.1.2 is my gateway (wireless router).
|
Hi,
Quote:
Quote:
The Google DNS are slow lately. Post your ISP DNS. I'll bet one or more of them belong to a 'OPENDNS' IP. :hattip: |
Hi,
One other thing! What does your kernel route table show? Post 'route -n'. |
Here is the output from 'route -n'. I'll keep playing around with the other suggestions.
Code:
Kernel IP routing table |
Do you have a Squid proxy which doubles up as a DNS proxy?
|
Quote:
|
Quote:
I went back into the router and removed the Google DNS servers since those seem to be acting up lately. Here is my current /etc/resolv.conf file with my ISP's DNS servers. Code:
# Generated by dhcpcd from wlan0 |
If your dns issues appear to be solved with your modified resolv.conf, then make the file immutable:
Code:
:~ # chattr -i /etc/resolv.conf cheers, |
Quote:
|
All times are GMT -5. The time now is 08:54 AM. |