Bienvenido! - Willkommen! - Welcome!

Bitácora Técnica de Tux&Cía., Santa Cruz de la Sierra, BO
Bitácora Central: Tux&Cía.
Bitácora de Información Avanzada: Tux&Cía.-Información
May the source be with you!
Showing posts with label DNS. Show all posts
Showing posts with label DNS. Show all posts

Monday, June 3, 2013

DNSQuerySniffer

http://www.nirsoft.net/utils/dns_query_sniffer.html
DNSQuerySniffer is a network sniffer utility that shows the DNS queries sent on your system. For every DNS query, the following information is displayed: Host Name, Port Number, Query ID, Request Type (A, AAAA, NS, MX, and so on), Request Time, Response Time, Duration, Response Code, Number of records, and the content of the returned DNS records.
You can easily export the DNS queries information to csv/tab-delimited/xml/html file, or copy the DNS queries to the clipboard, and then paste them into Excel or other spreadsheet application. 
Download DNSQuerySniffer (32-bit)
Download DNSQuerySniffer (64-bit)

Saturday, January 26, 2013

not able to resolve by hostname

You are not able to resolve by hostname
http://forums.techguy.org/networking/994174-solved-ping-could-not-find.html
TCP/IP stack repair options for use with Windows XP with SP2 or SP3.
Start, Run, CMD, OK to open a command prompt.
Reset WINSOCK entries to installation defaults:
netsh winsock reset catalogReset TCP/IP stack to installation defaults.
netsh int ip reset c:\reset.log [also for Windows Seven]
Reboot the machine.
==============
http://forums.techguy.org/networking/1086453-ping-request-could-not-find.html

Make sure the following services are Started (Control Panel - Administrative Tools - Services).
DNS Client
Network Location Awareness
Remote Procedure Call (RPC)

-------------------
Also just to confirm go to the Command Prompt and do this:
nslookup
server 8.8.8.8
google.com

If you get a non-authorative response then you may have not done the GoogleDNS correctly.
=================
http://www.computing.net/answers/windows-2003/ping-request-could-not-find-host/11093.html
I understand you to say that local queries resolve but not remote ones. This means that you haven't configured a forwarder for your DNS server. Configure it to look at your ISP's DNS server for queries that it cannot resolve fro m the zones it hosts.

Friday, August 24, 2012

Redireccionamiento de sitios web

Fuente 
Eliminar Malware
 


Si algún paso no pudieses realizar, sáltalo
.- Descarga, Instala y/o actualiza estos programas: (pero no los ejecutes aun).
.- Desconectar de internet
Reiniciar e iniciar en "Modo a prueba de fallos" (modo seguro)
.- Malwarebytes' Antimalware (Ver Manual)
  • Actualizalo desde su pestaña Actualizar.
  • En su opción de Análisis Completo.
  • Al terminar presionas Mostrar Resultados.
  • Despues, verificas que todo este seleccionado y pulsas "Eliminar Seleccionados"
  • Cuando te indique aceptas el reinicio del sistema.
  • El reporte esta en la Pestaña Registros
.- Ccleaner (Ver Manual)
  • En su opcion "Limpiador" pulsas Ejecutar el Limpiador.
  • Luego usa su opción "Registro" pulsas Buscar Problemas, Despues Reparar Seleccionados y
Por ultimo Reparar todas las seleccionadas (haciendo copia de seguridad).
.- Reinicia en Modo Normal y comprueba cómo funciona el sistema.
.-Realice un escaneo con Panda Active Scan 2.0 siguiendo su Manual de Panda ActiveScan 2.0 (NO interferirá con tu antivirus)==================
1.- Descarga y ejecuta OTM by OldTimer:
  • Haz doble clic sobre el archivo OTM.exe para ejecutarlo
  • Pega el siguiente codigo bajo el area "Paste Instructions for items to be Moved"
    Código:
    :Files
    c:\users\user\downloads\opensebj-0-11i (1).exe
    c:\users\user\downloads\opensebj-0-11i.exe
    c:\users\user\downloads\dsc93673 (1).zip
    c:\users\user\downloads\dsc93673.zip
    
    :Commands
    [RESETHOSTS]
    [EMPTYFLASH]
    [EMPTYTEMP]
    [REBOOT]
  • Presiona el boton rojo MoveIt!
  • Espera hasta cuando el resultado aparezca en el marco Results.
  • Permite que se Reinicie el equipo, esto es importante.
2.- Descarga TDSSKiller y ejecútalo como indica su Manual.
  • Antes desconecta el ordenador de Internet o apaga el Modem.
3.- Pegas los reportes de OTM y TDSSKiller en la siguiente respuesta.
====================
1.- Descargando y ejecuta iniRem by InfoSpyware, lo descomprimes al escritorio.
  • Doble Clic en el archivo IniRem 3.0.exe
  • Ingresar la pagina de inicio que desee tener y marque las casillas de Internet Explorer y/o Firefox.
  • Presionar en el texto botón del programa “Desbloquear”
  • Haces clic en el botón Restaurar archivo hosts.
b)
1.- Muy importante: en primer lugar desconecte el ordenador de Internet.
2.- En la parte trasera del Modem vera un pequeña ranura al lado del botón de apagado; Dicho botón se utiliza para retesar al mismo introduciendo un objeto puntiagudo. Procede a resetearl
3.- Restablecer los parametros de navegacion/ configuración de DNS de la conexión a Internet:
  • Vaya a Inicio -> Panel de control -> Haga doble clic en redes e internet -> Redes y recursos compartidos-> Cambiar configuración del adaptador
  • Haga clic derecho sobre la conexión por defecto (en Conexión de área local o general, la conexión de red inalámbrica) y seleccione Propiedades.
  • Haga doble clic en Protocolo Internet (TCP / IPv4).
  • En la pestaña General:
  • Seleccione "Obtener una dirección IP automáticamente".
  • Seleccione "Obtener la dirección del servidor DNS automáticamente".
  • Haga clic en Aceptar dos veces para guardar la configuración.
  • Reinicie si tiene que cambiar cualquier configuración
4.- Renovar el caché de DNS:
  • Haga clic en de Inicio -> haga clic en Ejecutar
  • En la ventana de comandos de copia / pega el siguiente texto:
    Código:
    ipconfig /flushdns
  • A continuación, pulsa enter. Salga de la ventana de comandos.
5.- Vuelva a conectar: Una vez que haya seguido todos los pasos anteriores puede volver a conectar su ordenador a Internet. ====================
====================
el pc está limpio de infección
Realiza lo siguiente:

Descargar DDS.pif desde aquí y guardarla en su escritorio de Windows.
  • Si usas Firefox dale clic derecho y selecciona Guardar Como
  • Si falla lo anterior --> descarga DDS.scr
Deshabilite cualquier bloqueador de script y a continuación, haga doble clic en dds.pif para ejecutar la herramienta y espere pacientemente el reporte.
  • Cuando haya terminado, DDS, se abrirá dos (2) los reportes:
  1. DDS.txt
  2. Attach.txt
En la próxima respuesta:
Pega los reportes llamados DDS.txt y Attach.txt
==================
Lop S & D (manual):
  1. Haz doble clic en LopSD.exe
  2. Elige el idioma escribiendo la letra correspondiente y pulsa en Enter
  3. Haz clic en "Aceptar (Ok)" en la ventana informativa
  4. Haz clic en 2 para elegir la opción "2 (Fix + Hosts)" y a continuación pulsa en Enter
  5. Espera hasta el final de la exploración
  6. Se generará un informe, pega el contenido del mismo en tu próxima respuesta.
  7. (La copia del informe se puede encontrar en esta ubicación: %SystemDrive%\lopR.txt, en la mayoría de los casos en C:\lopR.txt).


Ejecutas Ccleaner --> Herramientas --> Inicio y dar a:

a)Desactivar a las siguientes entradas:


Código:
Si HKCU:Run msnmsgr "C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe" /background

Si HKCU:Run ares "C:\Program Files (x86)\Ares\Ares.exe" -h

Si HKLM:Run IAStorIcon C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe

Si HKLM:Run Adobe Reader Speed Launcher "C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe"

Si HKLM:Run BackupManagerTray "C:\Program Files (x86)\NewTech Infosystems\Acer Backup Manager\BackupManagerTray.exe" -h -k

Si HKLM:Run LManager C:\Program Files (x86)\Launch Manager\LManager.exe

Si HKLM:Run Adobe ARM "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"

Si HKLM:Run SynTPEnh %ProgramFiles%\Synaptics\SynTP\SynTPEnh.exe

Si HKLM:Run PLFSetI C:\Windows\PLFSetI.exe

Si HKLM:Run IgfxTray C:\Windows\system32\igfxtray.exe

Si HKLM:Run HotKeysCmds C:\Windows\system32\hkcmd.exe

Si HKLM:Run Persistence C:\Windows\system32\igfxpers.exe
Cita:
Cualquiera de estas entradas puedes reactivarlas yendo a Ccleaner -> Herramientas -> Inicio, seleccionándola y dando a -> Activar
b) No olvides reiniciar para que los cambios surtan efecto

Con Revo Uninstaller y siguiendo su manual; busca si están y desinstala las siguientes aplicaciones:

Cita:
Avira AntiVir Personal - Free Antivirus --> recomendaría sustituirlo por avast!

Bing Bar

eBay Worldwide --> si no haces uso de él

McAfee Internet Security Suite

MyWinLocker
MyWinLocker Suite --> si no haces uso de ambos

Norton Online Backup --> si no haces uso de él
Haz uso de las siguientes herramientas específicas de desinstalación de antivirus:

Cita:
>> Si decides cambiar Avira por avast!:



Avira no dispone de una herramienta específica para desinstalar el programa, pero si tenemos problemas a la hora de querer instalar otro antivirus si que disponemos de Avira AntiVir RegistryCleaner, es una utilidad que una vez hayamos desinstalado este antivirus nos servirá para eliminar todos las claves del registro que Avira haya dejado en el PC.



>> Haz uso de AppRemover para eliminar restos de otros antivirus salvo Malwarebytes' o Avira (si no deseas cambiarlo)



Una buena alternativa gratuita para desinstalar correctamente todo tipo de programas de seguridad tales como antivirus, antispywares, antimalwares y demás se trata de AppRemover
AppRemover. Desinstala prog

Tuesday, January 17, 2012

Ping request could not find host


Fix for Ping request could not find host "FQDN of server" Error
I can ping by their IP address but not by their name
ping 192.168.1.3 --works
ping familypc --doesn't work
Ping request could not find host ___ Please check the name and try again
Solution
Need to setup WINS server or service on one of the computer. Or if you're using one of those gateway/router for internet sharing, you can set your wins server as that since it has capabilities of DHCP
Best solution
Windows firewall was blocking port 137. After unblocking it worked fine.
At command prompt
ping myserver.mydomain.local
I get back the message “Ping request could not find host myserver.mydomain.local. Please check the name and try again.”
An nslookup works fine, so I know the SBS server is there and is responding to DNS requests.
In fact, I can “ping myserver” without problems. But for some reason, pinging the fully-qualified internal name doesn’t work.
Sometimes, I can just type “ipconfig /flushdns” to clear this up. Today that didn’t work. However once I actually stopped and started the DNS cache, ping started working
net stop DNScache
net start DNScache
---------
Windows XP Home SP3. “PING name” does not find the host, and “PING ip-address” works fine. Also, “NSLOOKUP name” and also “NSLOOKUP name dns-server-ip-address” both work fine; that is NSLOOKUP works using it’s own default, and also using any valid DNS server I specify. But, PING and various other software like browsers, anti-virus, and pretty much any other name-dependent software will not function.
--------
Can still ping both ways by IP addr but not by computer name and hence Network Neighborhood only shows the source PC name, and can not see the other shared folders
---------------
 Are NSLOOKUPs resolving the names correctly? Does it help if you stop then start the “DNS Client” service (not just “DNSCache”)?

Despite multiple cache clearings, browsers can't find it either (it's an internal website). I am suspecting this is why. I am not sure how, after several /flushdns and /registerdns, if nslookup finds it right off, why can't anything else..? 
--------------------------
nslookup does not use the same references as ping
Ping will directly query the DNS server defined in ipconfig
nslookup will quiery the DNS server, on the AD domain controller your security was authenticated on.
Ping simply asks DNS give me the ip so I can ping it.
Their is no record in DNS for a myhost PC. But the code within the AD DNS schema has a refernce for a nslookup so you are returned the address of your authentication server..
If you invoke nslookup and put a x in front of it, you will get a > prompt. Type in a question mark at the prompt and you can see the switches to get the info you need with nslookup.
---------------------------
Win 2k3 'Round Robin' setting
I didn't set this box up - looking at the DNS settings, i see it's set for round robin.
configured on the workstations? To clarify, on your workstations, do you have the primary DNS server as the ADC and a secondary DNS server ip that points to a non-Active Directory DNS server?
Answer
On Windows 2000 and later, if a request to your primary DNS server times out, it switches to the secondary DNS server and stays with it for a period of time. However, nslookup always connects to the primary.
Take a look at this article and be sure to read the part about caching negative responses.
Windows contains a client-side Domain Name System (DNS) cache. The client-side DNS caching feature may generate a false impression that DNS "round robin" is not occurring from the DNS server to the Windows client computer. When you use the ping command to search for the same A-record domain name, the client may use the same IP address. This behavior is different from Microsoft operating systems earlier than Windows 2000. These operating systems do not include the client-side DNS caching feature. This article describes how to disable DNS caching.
Note This article refers to the client portion of DNS. Do not use this information for making changes to DNS servers.
To stop DNS caching, run either of the following commands:
  • net stop dnscache
    -or-
  • sc servername stop dnscache
To disable the DNS cache permanently in Windows, use the Service Controller tool or the Services tool to set the DNS Client service startup type to Disabled. Note that the name of the Windows DNS Client service may also appear as "Dnscache."
Note The overall performance of the client computer decreases and the network traffic for DNS queries increases if the DNS resolver cache is deactivated.
The DNS Client service optimizes the performance of DNS name resolution by storing previously resolved names in memory. If the DNS Client service is turned off, the computer can still resolve DNS names by using the network's DNS servers.
When the Windows resolver receives a positive or negative response to a query, it adds that positive or negative response to its cache, and as a result, creates a DNS resource record. The resolver always checks the cache before querying any DNS server. If a DNS resource record is in the cache, the resolver uses the record from the cache instead of querying a server. This behavior expedites queries and decreases network traffic for DNS queries.
You can use the Ipconfig tool to view and to flush the DNS resolver cache. To view the DNS resolver cache, type ipconfig /displaydns at a command prompt. Ipconfig displays the contents of the DNS resolver cache, including the DNS resource records that are preloaded from the Hosts file and any recently queried names that were resolved by the system. After a certain time period, the resolver discards the record from the cache. The time period is specified in the Time to Live (TTL) associated with the DNS resource record. You can also flush the cache manually. After you flush the cache, the computer must query DNS servers again for any DNS resource records previously resolved by the computer. To delete the entries in the DNS resolver cache, type ipconfig /flushdns at a command prompt.
[...]
Subnet Prioritization 
The Windows XP DNS resolver also uses Subnet Prioritization. If the resolver receives multiple IP address mappings (A resource records) from a DNS server, and some of the records have IP addresses from networks to which the computer is directly connected, the resolver places those resource records first. This behavior reduces network traffic across subnets by forcing computers to connect to network resources that are closer to them.
Although subnet prioritization does reduce network traffic across subnets, in some cases you may prefer to have the round robin feature work as described in RFC 1794. If so, you can disable the Subnet Prioritization feature on your clients by adding the
PrioritizeRecordData
registry entry with a value of 0 (REG_DWORD data type) in the following registry key: For additional information, click the following article numbers to view the articles in the Microsoft Knowledge Base:
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\DnsCache\Parameters
297510  How to Modify Time to Live on Domain Name System Records
286834  The DNS Client Service Does Not Revert to Using the First Server
For more information, see the Microsoft Windows XP Professional Resource Kit Documentation, chapter "DNS Caching, Network Prioritization, and Security."
Reply
We have no secondary internal DNS, and had round-robin set on the DNS server: i already turned that off. We are serving 2nd/tertiary DNS servers via DHCP to client workstations. I've turned off neg caching for all stations, serving a .reg via GPO. So far, on my own machine, i have seen no issues. Since this has been sporadic, it'll likely be a few days before i know it's gone for good.
I'm hoping this will also clear up the weird sudden-loss-of-shares and exchange issues
...
So: it is NOT resolving the CNAME correctly, but when asked about the machine itself, data, it resolves to the correct IP, and then the CNAME resolves "thru" the machine name to the target IP.
I incremented the serial the last time i made DNS changes. I made the above-suggested zero-neg-cache registry change. I have rebooted the machine and ensured all settings are current and policies are being applied.



DNS resolve problem with ping but not nslookup
windows XP SP3
my PC was not able to resolve DNS with most internet software
I tried pinging google and it also fails.
ping www.google.com
Ping request could not find host www.google.com. Please check the name and try again.

But nslookup can still work
*** Can't find server name for address 192.168.0.1: Non-existent domain
*** Default servers are not available
Server: UnKnown
Address: 192.168.0.1
Non-authoritative answer:
Name: www.l.google.com
Addresses: 209.85.165.103, 209.85.165.104, 209.85.165.147, 209.85.165.99
Aliases: www.google.com

------------------
Ping isn't going to work with many of the external host sites, so this is normal. If you can do an nslookup on a site, then dns is resolving correctly.
------------------
tenroc2o0o:
I've had the exact same issue on two computers and until I read this form it didn't occur to me it might have to do with SP3. I had just deployed SP2 & SP3 via group policy to over 40 PCs at my clients location while joining all of their computers to the new active directory network.
Basically, unless I use nslookup, DNS doesn't work. This includes Firefox, Internet Explorer, as well as internal active directory lookups to authenticate usernames and passwords against the domain. Noone could log on to the computer as a domain user - had to logon as local admin to work on it.
This means I could, say, "nslookup myserver.mydomain.local", get the IP, and then manually ping the IP and get a reply.
However, if I said "ping myserver.mydomain.local" it would say "Ping request could not find host myserver.mydomain.local. Please check the name and try again."
To me, basically this means nslookup can query because it simply opens a winsock connection on the DNS port and gets a query itself, whereas ping, IE, Firefox, and Windows itself for active directory domain authentication all cannot since they use the DNS Client service.
I had this same problem on now two computers. The first one, which I worked on earlier this week, I ended up formatting the computer to fix.
I tried specifying a static IP & DNS instead of using DHCP.
I tried uninstalling/reinstalling the network adapter.
I checked the Winsock using LSPFix to make sure there weren't any files missing or malware.
I checked hijackthis log for other malware - all clean.
I tried resetting all of the registry entries for the TCP/IP stack using
netsh int ip reset c:\resetlog.txt
SP3 reinstallation fixed all of the DNS query issues.
It's worth noting that even though DNS didn't work, WINS and NetBIOS still did so I could still connect to our server via \\myservername (or by IP of course). (whereas \\myservername.mydomainname.local did not because that's a DNS entry)
I just connected to my server & ran the SP3 update again and it fixed all of the DNS resolution problems.
----------------
Linux
I got the same problem with my two new virtual redhat and suse. It was the directory LDAP client which was the problem. Now both servers are running correctly.
If using linux (redhat or suse):
look at nsswitch.conf & ldap.conf
1) put "bind_policy soft" in /etc/ldap.conf
2) nsswitch.conf must minimum have:
passwd: compat
group: compat
hosts: files dns
networks: files dns
services: files
protocols: files
rpc: files
ethers: files
netmasks: files
netgroup: files
publickey: files
bootparams: files
automount: files nis
aliases: files
3) reboot
4) check with: ping, nmap localhost.
5) now you can enable your ldap client again. (RH: authconfig ; suse: yast2 ldap). It will modify your nsswitch.conf
-------------------
pings and nslookup problems are not related to AD, rather they are based on the client's network configuration and the client side resolver service

Tuesday, November 8, 2011

The name could not be registered on the Interface

The name could not be registered on the Interface with IP address The machine with the IP address did not allow the name to be claimed by this machine
http://www.eventid.net/display.asp?eventid=4321&eventno=1822&source=NetBT&phase=1
http://forums.techarena.in/active-directory/655026.htm
http://www.experts-exchange.com/Networking/Windows_Networking/Internet_Protocols/WINS/Q_23774695.html

Tuesday, September 6, 2011

So funktioniert das DNS-System

Quelle: spiegel.de

Als Lösung für dieses Problem wurde das DNS-System entwickelt. Dabei handelt es sich um Datenbanken, in denen jeder IP-Adresse ein für Menschen verständlicher Name zugeordnet ist. Im Fall von SPIEGEL ONLINE übersetzt eine solche Datenbank die Browsereingabe www.spiegel.de in die IP-Adresse 195.71.11.67. Weil aber eine einzige Datenbank nicht ausreichen würde, um die Anfragen aller Internetnutzer zu beantworten, gibt es davon etliche Kopien, welche die Zugangsanbieter auf ihren eigenen DNS-Servern bereithalten und deren Datenbestände regelmäßig untereinander abgleichen.
DNS ist das Kürzel für "Domain Name System" und steht für eine Technik, die es erheblich erleichtert, das Internet zu benutzen. Das dem Internet als Netzstandard zugrunde liegende Internet-Protocol (IP) legt fest, dass jede Website durch eine aus vier Zahlen zusammengesetzte, vier- bis zwölfstellige IP-Adresse identifiziert wird. Im Grunde müsste man beim Websurfen deshalb immer Adressen nach dem Muster 195.71.11.67 (SPIEGEL ONLINE) in die Adresszeile des Browsers eingeben. Doch wer könnte sich schon die IP-Adressen all seiner Lieblings-Websites in dieser Form merken?

Thursday, June 30, 2011

OpenDNS.org

OpenDNS: Un DNS rápido y útil
Siguiente »

Resumen

Cada vez que ingresamos el nombre de una página web en la barra de direcciones (http://tux-y-cia.blogspot.com), el PC consulta a un servidor DNS para avriguar la dirección IP de la página.
Por lo general, utilizamos los servidores DNS de nuestro proveedor de acceso a Internet, pero podemos utilizar otros servidores DNS.
OpenDNS nos permite utilizar (gratuitamente) sus servidores DNS en lugar de los de nuestro proveedor de acceso a Internet.
Ventajas
Es más rápido y posee funciones de protección (anti-phishing y otros).
Características:
  • Generalmente más rápido que nuestro proveedor de acceso a Internet (estos poseen enormes servidores, con un caché DNS importante)
  • Más fiable (OpenDNS es muy fiable y sus servidores tienen una disponibilidad del 100%)
  • Autocorrección de pequeños errores al teclear (google.cmo → google.com)
  • Proposición automática (Motor de búsqueda) si el dominio no existe.
  • Protección anti-phishing (OpenDNS está conectado directamente a PhishTank.com)
  • El servicio es gratuito
  • No hay necesidad de instalar ningún programa (sólo la dirección del DNS por configurar)
  • Cuando queremos podemos dejar de utilizar OpenDNS.
La mayoría de usuarios de OpenDNS han constatado una mejora del rendimiento, en particular el de los navegadores.
Ejemplo de como bloquea OpenDNS una página de phishing: En lugar de la página fraudulenta aparece una página de advertencia:



Simplemente utiliza los servidores DNS siguientes:
208.67.222.222
208.67.220.220 
-----------------------------------------
OpenDNS no es:
  • OpenDNS no es un filtro web: El no filtra el contenido de las páginas web.
  • OpenDNS no es un filtro URL: El no filtra las URL, bloquea únicamente los dominios y sub-dominios y no examina el resto de la URL.
  • OpenDNS no es un antivirus/antimalware: El no bloqueará la descarga de virus y troyanos.
  • OpenDNS no mejora el bitrate de tu conexión: únicamente acelera las peticiones DNS.
  • OpenDNS no mejora el ping: El solamente acelera las peticiones DNS.

Saturday, March 19, 2011

Error message changing DNS

Warning: Multiple default gateways are intended to provide redundancy to a
single network such as and Intranet or the Internet. They will not function
properly when the gateways are on two separate, disjoint networks (such as
one on your intranet and one on the Internet). Do you want to save this
configuration?

Source
It's telling you to remove the default gateway from one of your connections as you should only have one.
---------
But that error message is still saying you are connected to two different networks.
Reset everything temporarily to dynamic and then run an ipconfig. What are the numbers? Does your router allow you to reserve an ip address for a specific network adapter? Might be a better way to go
Source

Monday, October 18, 2010

Servidores DNS de Google

Fuente
Otro paso de Google para dominar la red. Una vez que es el buscador de referencia, tiene el sistema de correo más exitoso y posee una de las mayores redes de fibra oscura, lo nuevo de Google es poner a disposición del gran público servidores DNS gratuitos alternativos a los que nos brinda el operador.
Se definen como servidores neutrales y muy rápidos
8.8.8.8
8.8.4.4

Wednesday, October 13, 2010

Acrylic DNS proxy

Source
Acrylic is a local DNS proxy which improves the performance of your computer by caching the responses coming from your DNS servers.

When you browse a Web page a portion of the loading time is dedicated to name resolution (usually from a few milliseconds to 1 second) while the rest is dedicated to the transfer of the page contents to your browser. What Acrylic does is to reduce the time dedicated to name resolution for frequently visited addresses closest to zero possible. It may not seem such a great optimization but in a few weeks of internet browsing you will probably save an hour or so, which is definitely not such a bad thing. With Acrylic you can also gracefully overcome short downtimes of your DNS servers without disrupting your work, because in this case you will at least be able to connect to your favourite websites and to your e-mail server. In addition Acrylic can help you to effectively block unwanted ads prior to their download through the use of HOSTS files, optimizing your navigation experience even further.

Another good thing is that Acrylic is released as open source, which means that it's completely free and its source code, written in ObjectPascal with Borland Delphi 7, is freely available to anyone under the GNU General Public License.

For informations about installation and configuration issues you can refer to the Acrylic User Manual and Frequently Asked Questions.
La puesta en marcha de Acrylic es más sencilla de lo que parece. Una vez instalado, abre el archivo de configuración y añade las direcciones de tus servidores DNS (los encontrarás tras ejecutar ipconfig /all en la consola de comandos).
Acto seguido, usa tu dirección local, 127.0.0.1, como servidor DNS; para ello, abre las propiedades de tu conexión y edita el componente TCP/IP. ¿El último paso? Iniciar el servicio de Acrylic con el atajo del menú Inicio. A partir de ese momento, Acrylic almacenará las peticiones en su caché.

DNS Resources and Info

DNS Articles and Information
Open DNS - Bad Idea

Appendix C: DNS Resources

DNS open source software

4. DNS Configuration Types

Most DNS servers are schizophrenic - they may be masters (authoritative) for some zones, slaves for others and provide caching or forwarding for all others. Many observers object to the concept of DNS types partly because of the schizophrenic behaviour of most DNS servers and partly to avoid confusion with the name.conf zone parameter 'type' which only allows master, slave, stub, forward, hint). Nevertheless, the following terms are commonly used to describe the primary function or requirement of DNS servers.

Contents

DNS proxies

symantec.com/business/DNSproxy
Introducción

El DNS proxy, DNSd, provee el servicio de resolución de nombres para equipos tanto internos como externos sin revelar las direcciones IP privadas al mundo exterior. Los equipos internos son aquellos que se conectan al firewall a través de una interfase designada, en los registros DNS, como privados. Los equipos internos tienen acceso a la información de direcciones privadas y públicas. Cualquier equipo que no esté conectado a una interfase privada es público y por lo tanto no puede acceder a la información de direcciones privadas. El proxy DNS tiene autoridad sobre los dominios y redes privados y está designado como la autoridad a través de la Consola de Administración de Symantec Raptor (SRMC, Symantec Raptor Management Console). DNSd responde con autoridad para estos nombres y direcciones cuando llega una solicitud desde una interfase privada. DNSd puede o no ser una autoridad sobre los dominios accesibles públicamente, dependiendo de su configuración.

El DNS proxy diferencia entre equipos públicos y privados de la siguiente manera:

Registros privados: Éstos se refieren a los equipos conectados al firewall a través de una interfase de red designada como privada por el firewall. Los equipos privados tienen acceso a la información de direcciones de host privadas y públicas.

Registros públicos: Éstos se refieren a los equipos conectados al firewall a través de una interfase de red designada como pública por el firewall. Los equipos públicos sólo tienen acceso a información de direcciones del host público.



Nota: Los términos "interno" y "privado" no tienen el mismo significado. Estas denominaciones funcionan de forma independiente. Una interfase interna puede ser designada como pública; por ejemplo, una interfase interna que se encuentre con una red de servicio puede requerir ser designada como pública para fines de resolución de nombres. Además, cambiar manualmente una interfase de interna a externa después de instalar el firewall (en Base Components > Network Interfaces) no afecta la forma como DNSd designa a dicha interfase (como privada o pública).
Source

About DNS proxy

DNS Proxy/Forwarding
The Domain Name Service is a system designed to allow the identification of Internet servers to be based on names rather than IP addresses. Because Internet communication is based on IP addresses, all names must be translated into an IP address. This is the purpose of a Domain Name Server.
WinRoute Lite has a built-in DNS proxy that can take DNS queries from the local network and forward them to an Internet Domain Name Server. By default the DNS Proxy is enabled and WinRoute will forward all requests to the servers detected by the operating system (usually assigned by your ISP). Alternatively you can choose to forward DNS queries to specified servers.
About DNS proxy

www.wolfermann.org/dnsproxy.html

Sunday, June 20, 2010

Change primary DNS suffix when Domain membership changes

What is the difference if it is checked or not?
With an XP machine on a Windows 2000 or 2003 domain, you can just leave them at the defaults, ie as they are shown in your screen shot. Once you've joined the domain, the DNS Suffix will automatically default to the domain you've joined, in your case test.net and the NETBIOS name will be the same as your computer name pro10
NETBIOS is really only used with legacy (Pre NT) machines such as Windows 98.
Q How does modifiy registration (registering connections address in DNS & using DNS suffix in registration) affect Active directory?
A I guess I don't understand the question.  What do you mean by registration?
When your machine boots up you talk to your DHCP server and get a lease.  DHCP may then talk to DNS on your behalf and create an A record for your device in your DNS domain (NOT AD domain...) along with a pointer if there is a reverse zone available.
You get 2 things from DNS... name resolutions & service announcements.  DNS tells you that www.msn.com equals some IP address. It also tells you which server to go to to logon to your domain and where to find a Global Catalog server when you're browsing AD objects.
Changing your local DNS suffix affects none of these things.  All changing your local DNS suffix does is to automatically append that suffix to host names when talking on the network.
For instance... if my DNS suffix is ACME.COM and I type in "ping server1" I will get a reply that says "Pinging server1.ACME.COM".  My machine then contacts my DNS server and asks it how to get to server1.ACME.com to which the DNS server replies with the IP address of server1 in domain ACME.COM.
So... since you access resources most of the time in a single domain it makes sense for you to make that your primary DNS suffix.  It doesn't mean that you cannot resolve names in other DNS domains, it just means that the first one it tries... the one displayed to you... is the primary.
Does that help any more?  Changing your DNS suffix doesn't have anything to do directly with Active Directory.  If you mess up your name resolution you might not be able to connect to a particular resource though.
--------------------------------------
Q Normally the check box "register this connections address in DNS is checked" and one may also check "use this connections DNS suffix in registration".  So,  was wondering AD would function any differently when these options are used or not used?
Essentially, these affect what name your computer registers with DNS.  Your computer's DNS registration is primarily used when other devices on the network attempt to connect to your computer.  If you have "domainA.local" as your suffix, when you get your DHCP address your computer registers "name.domainA.local" with the selected DNS server and registers your IP address as a reverse lookup to that same name.
The default configuration is to use your local AD domain name in this fashion as well as to check the box.  This is because you are expected to be accessing resources in your own domain most often.  In addition, it is expected that other devices trying to connect to your computer would be expected to be in your own domain.
The only reason why you would want to use a domain other than your own default would be if you expected devices in another domain to connect to your computer and you wanted to make sure your DHCP-enabled computer registered a name within the OTHER DNS domain name in addition to or instead of your own AD DNS domain name.
So, unless you're publishing data on desktop computers to people in the other domains don't worry about this.  If someone in another domain needs to be able to connect to a server in your domain you may need to put a static entry in DNS for them to be able to connect by name, but you probably won't even need to do that.
 --------------------------------------
Q What about the primary DNS suffix:  What if it were not used and we joined the AD domain with this box unchecked:  "Change primary DNS suffix when domain membership changes" ?
A Examples
You have 2 domains, DomainA and DomainB.
Your servers are in mostly in DomainA except for a domain controller in DomainB.
You have clients in both domains.  The clients all use resources in both domains.
Your clients in DomainA have their primary DNS suffix set to "DomainA" and your clients in DomainB have their primary DNS suffix set to "DomainB".
There is a trust between the domains.  All computers in each domain have a DNS server for their own domain selected in their IP configuration.  No WINS is available and broadcast traffic does not span the 2 domains (so NetBIOS won't work).  Basically we force all to use DNS for name resolution.
Scenario 1:
All clients have the "Change primary DNS suffix when domain membership changes" set.  You move a client from DomainA to DomainB.  Before the move, the primary DNS suffix for that client was "DomainA".  After the move, the primary DNS suffix automatically changes to "DomainB".
Scenario 2:
You do NOT check "Change primary DNS suffix when domain membership changes". You move a client from DomainA to DomainB.  Before the move, the primary DNS suffix for that client was "DomainA".  After the move, the primary DNS suffix remains "DomainA".
Scenario 3:
DNS is shared between both domains.  You have a client in DomainB trying to access Server1 in DomainA. The client queries DNS for the IP address of Server1.DomainA.  That address is returned to the client.
Scenario 4:
DNS is NOT shared between domains.  The client in DomainB tries to access Server1 in DomainA.  The client queries DNS for the IP address of Server1.DomainA.  The DNS server tells the client that it has no record of Server1.
Scenario 5:
Workstation1 in DomainB registers it's name with DNS using "DomainB" for the DNS suffix.  Workstation2 in DomainA attempts to access Workstation1.  Workstation2 queries DNS for "Workstation1.DomainA.com"
.  Since Workstation1 registered its name in DomainB but Workstation2 is querying for Workstation1 in DomainA the query fails and no resolution is made.
Scenario 6:
Workstation1 in DomainB registers it's primary suffix as "DomainB" but registers an additional DNS suffix for "DomainA".  Workstation2 queries DNS for "Workstation1.DomainA.com".  Since Workstation1 registered with both DNS domain names the query returns an IP address for Workstation1.
-----------------------------------------------------------------------------------------------
Q What about this scenario:  You do NOT check "Change primary DNS suffix when domain membership changes" AND not primary DNS suffix is blank to begin with?
A If you have no DNS suffix then when you go to a command line and type "ping server1" for instance. Then Windows does not automatically append "DomainA" to "server1".  The Change primary DNS suffix" option only applies when moving a client between domains.  The rest of the time it is ignored.
So then the question becomes... can you resolve "ping server1".  If you have no WINS and you cannot broadcast for "server1" and you don't have "server1" in cache then you cannot.
For more on how name resolution works on a Windows client check out http://support.microsoft.com/kb/172218.
The best practice is to use DHCP to put your home AD DNS domain name in the DNS suffix.  You can add other domains also if you are likely to interact with them.  Never specify this kind of thing directly on the client unless you have some sort of special exception.

Tuesday, November 18, 2008

OpenDNS

Welcome to OpenDNS!
Your Internet is safer, faster, and smarter
because you're using OpenDNS.
Thank you!
See OpenDNS in action

Saturday, October 4, 2008

Domain Name System: ODS

The Domain Name System (DNS) is a hierarchical naming system for computers, services, or any resource participating in the Internet. It associates various information with domain names assigned to such participants. Most importantly, it translates humanly meaningful domain names to the numerical (binary) identifiers associated with networking equipment for the purpose of locating and addressing these devices world-wide.
An often used analogy to explain the Domain Name System is that it serves as the "phone book" for the Internet by translating human-friendly computer hostnames into IP addresses. For example, www.example.com translates to 208.77.188.166.
The Domain Name System makes it possible to assign domain names to groups of Internet users in a meaningful way, independent of each user's physical location. Because of this, World-Wide Web (WWW) hyperlinks and Internet contact information can remain consistent and constant even if the current Internet routing arrangements change or the participant uses a mobile device. Internet domain names are easier to remember than IP addresses such as 208.77.188.166(IPv4) or 2001:db8:1f70::999:de8:7648:6e8 (IPv6). People take advantage of this when they recite meaningful URLs and e-mail addresses without having to know how the machine will actually locate them.
The Domain Name System distributes the responsibility for assigning domain names and mapping them to Internet Protocol (IP) networks by designating authoritative name servers for each domain to keep track of their own changes, avoiding the need for a central register to be continually consulted and updated.
In general, the Domain Name System also stores other types of information, such as the list of mail servers that accept email for a given Internet domain. By providing a world-wide, distributed keyword-based redirection service, the Domain Name System is an essential component of the functionality of the Internet.

Other identifiers such as RFID tags, UPC codes, International characters in email addresses and host names, and a variety of other identifiers could all potentially utilize DNS [1].

The Domain Name System also defines the technical underpinnings of the functionality of this database service. For this purpose it defines the DNS protocol, a detailed specification of the data structures and communication exchanges used in DNS, as part of the Internet Protocol Suite (TCP/IP). The context of the DNS within the Internet protocols may be seen in the following diagram. The DNS protocol was developed and defined in the early 1980's and published by the Internet Engineering Task Force.

A DNS recursor consults three nameservers to resolve the address www.wikipedia.org.
A DNS recursor consults three nameservers to resolve the address www.wikipedia.org. (Click on image)
---------------------------------------------------------
ODS.org If you're looking to host a website, ftp, irc, or email server but have a dynamic IP, you've come to the right place. Open Domain Server offers very low cost dynamic name server resolution for a number
of public domains.

Wednesday, September 24, 2008

Telefónicas de Bolivia -- DNS cache poisoning

Source
Explanatin of the problem
Test 
DNS

DNS cache poisoning

Básicamente, la explotación del fallo puede permitir a un usuario malintencionado, redirigir cualquier nombre de dominio a una web falsa.
Hay que recalcar lo de "cualquier nombre de dominio".
O sea, cualquiera podría caer en el engaño y cualquier página (por ejemplo: banca virtual accedida a través del servidor o servidores Domain Name Server del portal de Cotas) podría no ser legítima.

Dan Kaminsky fue el primero que encontró y reportó el problema, en su sitio web hay un test que permite comprobar si el proveedor del servicio de Internet ha aplicado el parche.
Cuándo se encargarán de arreglar eso los bien pagados ingenieros de Cotas?
Controlen los DNS de Entel, AXS, Telecel y los demás proveedores de Internet
Para hacer el test tuve que cambiar a los DNS de COTAS mis DNS de opendns.org :
208.67.222.222 y
208.67.220.220
(que uso desde 2005 y recomiendo a todo conectado con cualquier proveedor de internet en Bolivia)


DNS Checker
Recently, a significant threat to DNS, the system that translates names you can remember (such as www.doxpara.com) to numbers the Internet can route (66.240.226.139) was discovered, that would allow malicious people to impersonate almost any website on the Internet. Software companies across the industry have quietly collaborated to simultaneously release fixes for all affected name servers. To find out if the DNS server you use is vulnerable, click below.
RESULTS:
Your name server, at 200.58.161.25, appears vulnerable to DNS Cache Poisoning.
All requests came from the following source port: 32769
Due to events outside our control, details of the vulnerability have been leaked. Please consider using a safe DNS server, such as OpenDNS.
Note: Comcast users should not worry.


Por lo tanto, provecho con el servicio de Cotas! Pienso que las otras telefónicas también están en las mismas.
Eso se llama seguridad informática a la boliviana!