[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: [cobalt-users] Major Trouble with DNS -- PLEASE HELP!!!!!!!



Gerald Waugh wrote:

> We have isolated part of the problem, particularly dealing with the domain
> names "microsoft.com", "hotmail.com", and "msn.com", to a DNS provider
> called "mydomains.com" which had mis-configured their DNS servers.

All the microsoft domains were affected on Wednesday and many were
affected again on Thursday.

While early reports blamed "mydomain.com", here's the real skinny on how
it could have happened with "mydomain.com" (from the Internet Access
List:

> > It's my understanding that, essentially, a bunch of places had put the
> > mydomain.com nameservers in /etc/resolv.conf (or OS equivalent) and
> > polluted their own DNS caches in so doing. :)
> > 
> > No root server corruption occurred. The roots were fine throughout. (I
> > know, I checked whilst in the middle of this situation *grin*)
> 
> I seem to recall some unices /etc/resolv.conf having an example using
> mydomain.com when you first installed it, but it was always commented
> out...I guess it could happen, but imagine the level of incompetence
> needed...

Note that no RaQ could have been affected by a "mydomain.com" problem,
nor could the entire Internet have been affected; if your machine was
set up correctly, it would have continued to get the right information,
no matter how many of the clueless were pointing towards mydomain.com.

And, btw, I was severely affected by the outage, and was one of the
volunteers who checked to see if we could determine the problem.

On Wednesday it appeared to be nameservers (all of which were on the
same network, btw, which is why I always say that nameservers should be
on disparate networks) were turned off and not reachable.  It did NOT
appear to be a DOS attack; a lot of us think that MS was in the midst of
switching from FreeBSD DNS servers (which they've always used in the
past) to new W2k DNS servers, and something broke BAD.

Yesterday the problem appeared to be routers down.

> and some parts of the Internet are still having problems reaching these
> domains

Only for companies using DNS servers that are improperly set to retain
NEGATIVE results for longer than three hours.

(As I've said before, DNS is not as simple as some would think.)

Jeff
-- 
Jeff Lasman <jblists@xxxxxxxxxxxxx>
nobaloney.net
P. O. Box 52672
Riverside, CA  92517
voice: (909) 787-8589  *  fax: (909) 782-0205