admin (no pm's please)
|
Name server outagesThere seems to be a chronic issue with the nameserver service we use to backup our own nameservers and also critically to act as the nameserver to point to our nameservers
As these things are cached, it may be some time until issues occur or hopefully never as the issue gets resolved.
But if you have your own domain pointing to a forum via ourselves you may see an issue sooner, as most such domains are set to use the nameservers that are currently down
All we can currently do is hope the issue gets resolved, as trying to switch services on the fly would be more chaotic than waiting.
|
admin (no pm's please)
|
The outage is still there and I have set up an alternate nameserver for our own nameserves, but have not activated it yet.
It is more prudent to give everydns.net time to sort things out.
|
admin (no pm's please)
|
As of the minute things seem to be struggling but in essence coming back online as if this was quite a wide spread outage well beyond our own nameservers.
So touch would the don't panic approach looks like it was the right one....
|
CodyT07
|
sorry for off topic but could you briefly explain the servers
I thought a name server worked as a redirector to a different server that hosts the site/forum. And DNS Servers that act as redirectors around the world. And then you have satellites
Do i basically get the general idea so i know what your talking about.
|
admin (no pm's please)
|
nameservers and the DNS are the same thing.
Every domain name needs to be pointed to an ip address, so each domain you register you assign a number of nameservers that know about your domain names, and of course your nameserver must also be locatable. Hence for example telling the registrar that:
myfreeforum.org has a nameserver ns1.myfreeforum.org
would be totally useless as ns1.myfreeforum.org could itself not be resolved.
We run a redundant set of nameservers using two servers we rent that simply run as nameservers and don't host forums, which themselves mirror to the normally reliable and large array of everydns.net nameservers which we have viewed as more reliable than our own nameservers.
Hence the divide here has been to use our own nameservers for addresses that get dynamically changed as say a forum moves to the new zaphod server, and use everydns directly for sites in general like the gallery site.
I have been pretty pleased with this combination of our own dynamically updated service on totally independent servers backed up by a renowned independent DNS service. It took months of careful consideration and programming and has functioned very well for close to a year now.
Tonight we saw a total outage on the everydns service but what it actually was is still unknown. However at the end of the day the forums have basically stayed running!
So are there lessons?
I think the answer is yes. The forums stayed alive as they are using nameservers that are both on our own systems and on everydns. Whereas things like the gallery are only on everydns and hence are more vulnerable.
|
CodyT07
|
2 quick questions
Zaphod is the new servers name?
and what is everydns.net
Why not use those nameservers to host forums? As you could get a quicker connection from North and maybe South America and UK to your servers located there. Im sure quite expensive but its an idea.
So the IP i my firefwall received earlier in my last topic is just the nameserver? and the forums are actually hosted in UK?
|
admin (no pm's please)
|
All forums are hosted in the US.
Our name servers are in Europe and don't need to be powerful enough to host forums, best to leave them to do just the DNS for maximum reliability.
www.everydns.net
explains everydns, and hopefully you can see makes a lot more sense for us to have farmed out part of the nameserver role to a dedicated DNS organisation than to have tried to do it ourselves.
|
CodyT07
|
| Quote: | | Update #2: December 1st, 2006. EveryDNS is currently under a wide-scale DDoS attack. The attack is currently being mitigated and is under close watch by a team of network administrators around the world. Thanks to the tireless network and security operations folks who support EveryDNS. |
i typed in DDoS on google and this poped up
http://en.wikipedia.org/wiki/Denial-of-service_attack
or
http://searchsecurity.techtarget....nition/0,,sid14_gci557336,00.html
If it is the same remember my firewall problem a few posts back? My firewall report a DDS attack from Fastservers inc.
| My Firewall wrote: | | A computer at IP Address 64.38.58.178 has sent traffic to your computer that was blocked by our Intrusion Detection System (IDS). The source IP address has apparently attempted a Denial of Service against your computer by sending a large amount of invalid fragmented packets. |
|
admin (no pm's please)
|
Well spotted, that seems to have appeared in the last few minutes.
What the point of this sort of thing is, is beyond me
|
CodyT07
|
So basically everyone using and their members of that site is getting attacked by hackers.... They attacked me and they probably will attack other members of other forums, so big forums should be worried till this gets resolved? Or am i over reacting?
|
admin (no pm's please)
|
The question to think about is should we create secondary DNSs on our own nameservers to backup those on everydns?
This sort of thing is always a matter of weighing the issues you can create by the increases in complexity with the chances of an issue with the system as it stands. e.g. Do we add something that might cause its own problems to deal with an issue that has arisen for 6 hours in 18 months and which has not effected core forum availability?
You may never truly know if your own backup name server solution works well, until the main ones fail!
It's a rhetorical question that I have no considered answer to at the moment.
|
admin (no pm's please)
|
| CodyT07 wrote: | | So basically everyone using and their members of that site is getting attacked by hackers.... They attacked me and they probably will attack other members of other forums, so big forums should be worried till this gets resolved? Or am i over reacting? |
How have they attacked you? aside from our gallery being offline as a result of this?
Our forums themselves should be okay unless a DDOS attack hit both our own nameservers and everydns.
|
CodyT07
|
Possible Location of DDoS Attacker?
everydns.net is located in California and there is something in Florida that is attacking me.
My firewall
Somehow there in the forums if the attack can from there.
|
admin (no pm's please)
|
I also see from another thread that some people have had issues seeing the forums
This is despite the nameservers being set to use both our nameservers and everydns
I can't explain that at the moment either.
|
CodyT07
|
seems from my above post of maps they might be using the servers to plan attacks and be hidden As all i can tell its staged in Florida when they attacked me.
|
admin (no pm's please)
|
Finally 24 hours on, we have the nameservers not only working, but on a detailed report:
http://dnsreport.com/tools/dnsreport.ch?domain=myfreeforum.org
looking healthy in the essential aspects like all being in sync.
Jury is still out on whether to go to work more on this.
|
CodyT07
|
| Quote: | WARNING: One or more of your mailservers does not accept mail to abuse@myfreeforum.org. Mailservers are expected by RFC2142 to accept mail to abuse.
myfreeforum.org's abuse response:
>>> RCPT TO:<abuse@myfreeforum.org>
<<< 550 sorry, no mailbox here by that name. (#5.7.17)
|
| Quote: | ERROR: Your nameservers disagree as to which version of your DNS is the latest (118481 versus 118508). This is OK if you have just made a change recently, and your secondary DNS servers haven't yet received the new information from the master. I will continue the report, assuming that 118508 is the correct serial #. The serial numbers reported by each DNS server are:
84.244.9.130: 118508
84.244.3.46: 118508
209.131.97.97: 118481
|
What about those
|
admin (no pm's please)
|
Abuse should be there admittedly. The serial information is getting in sync as the everydns name servers come back fully online, that situation was worse earlier today, and totally fubar before that.
|
CodyT07
|
| Quote: | ERROR: Some of your nameservers listed at the parent nameservers did not respond. The ones that did not respond are:
82.165.186.20
Note: If you are running a Watchguard Firebox with DNS Proxy enabled, there may be a bug causing port numbers get mixed up -- if this is the case, you can contact Watchguard to see if they have a fix. |
appearing as that now. didnt yesterday/
|
admin (no pm's please)
|
They do still seem to have issues
Quite frustrating really, as I don't want to tinker with the system whilst it is flaky, DNS is quite complex enough as it is without the prospect of changes not being quickly reflected down the system
|
admin (no pm's please)
|
Seems like they are having problems again
|
CodyT07
|
the server according to the link at the top responds now. I also see you added an abuse e-mail but considering how spam preventive you are, shouldnt your worry about this one?
| Quote: | | Your domain does not have an SPF record. This means that spammers can easily send out E-mail that looks like it came from your domain, which can make your domain look bad (if the recipient thinks you really sent it), and can cost you money (when people complain to you, rather than the spammer). You may want to add an SPF record ASAP, as 01 Oct 2004 was the target date for domains to have SPF records in place (Hotmail, for example, started checking SPF records on 01 Oct 2004). |
|
admin (no pm's please)
|
I think when I was reporting in the last post, I was probably catching them "mid fix".
|
admin (no pm's please)
|
Report now has a few more boxes checked
http://dnsreport.com/tools/dnsreport.ch?domain=myfreeforum.org
Our DNS management software which was developed about a year ago has been quite significantly upgraded in the last day or two, allowing far more flexibility as well as more error checking.
The idea is that new domains we create will use our own system as primary and everydns.net as secondary.
This job was probably long overdue anyway, but was in the if it ain't broke don't fix it camp.
|
CodyT07
|
everytime i reload the report something else is failing and sometimes its perfect
| Quote: | ERROR. One or more of your DNS servers are missing A records (per NS records that may be cached). As a result, they cannot be used. The problem hostnames are:
ns2.myfineforum.com. has no A record. |
| Quote: | ERROR: Some of your nameservers listed at the parent nameservers did not respond. The ones that did not respond are:
209.131.97.97
Note: If you are running a Watchguard Firebox with DNS Proxy enabled, there may be a bug causing port numbers get mixed up -- if this is the case, you can contact Watchguard to see if they have a fix. |
the bottom one occurs more.
Sometimes its everyone, both or not at all, when i reload the page.
|
admin (no pm's please)
|
it's a funny old business, still at least part of the point of 4 name servers is redundancy.
|
CodyT07
|
| admin wrote: | | it's a funny old business, still at least part of the point of 4 name servers is redundancy. |
now 2 arent responding at
204.152.184.150
209.131.97.97
and a new one
| Quote: | Error: At least one of your NS records points to an IP address that is not a public IP. The problem IP(s) are:
is not a public IP
These IPs are not reachable on the Internet, causing DNS delays, extra resource usage, and possibly no DNS response. |
Though i think the "AOL's proxy farm" is having trouble. Through AOL im getting a gateway timeout. Firefox using my other connection its fine.
|
admin (no pm's please)
|
everydns.net reports the attack is continuing:
http://www.everydns.net/index.php
Unfortunately the very fact of the attack is making it hard for us to change what needs to be changed to get us out of the firing line.
We do now have records on another third party service, and have as already mentioned done some major upgrades to our own internal service.
|
admin (no pm's please)
|
Ok, it may take time to propagate, but the route to our nameservers is no longer dependent on everydns.net
|
CodyT07
|
| admin wrote: | Ok, it may take time to propagate, but the route to our nameservers is no longer dependent on everydns.net  |
Hold on. I thought every DNS did nameservers. But i was attack from Fast Servers Inc. Couldnt they still attack us from Fast Servers?
|
admin (no pm's please)
|
Fast servers are our colocation centre, I have a feeling that you have seen not an attack but a random glitch of same nature.
Meanwhile everydns.net is still struggling, with there secondary DNS set up code not responding, which means that on some domains we are running two totally independent unmirrored DNS systems, which is not the greatest idea in the world
|
admin (no pm's please)
|
Finally a reasonable looking status report again, as well as secondary DNS setup coming back online
|
|
|