hidden hit counter
Welcome to WindowsForumz.com!
FAQFAQ    SearchSearch      ProfileProfile    Private MessagesPrivate Messages   Log inLog in

Were we poisioned, spoofed or something else?

 
   Win 2000/NT/98/ME (Home) -> DNS RSS
Next:  IE7 and SP2  
Author Message
Steve

External


Since: Dec 07, 2007
Posts: 1



(Msg. 1) Posted: Fri Dec 07, 2007 12:04 pm
Post subject: Were we poisioned, spoofed or something else?
Archived from groups: microsoft>public>win2000>dns (more info?)

Today, one of our internal DNS servers began reporting every host resolution
as an address that has been traced to somewhere in China. We are actively
trying to figure out what occurred. Replacing our actual domain with "test",
here is what we saw in nslookup or regular pings.

nslookup
>www.test.com
www.test.com.test.com (china address)
>validhost1.test.com
validhost1.test.com.test.com (china address)
>invalidname1.test.com
invalidname1.test.com.test.com (china address)

What was happening?

TIA

 >> Stay informed about: Were we poisioned, spoofed or something else? 
Back to top
Login to vote
Ace Fekay [MVP]

External


Since: Mar 29, 2006
Posts: 238



(Msg. 2) Posted: Thu Dec 13, 2007 12:10 am
Post subject: Re: Were we poisioned, spoofed or something else? [Login to view extended thread Info.]
Archived from groups: per prev. post (more info?)

In news:O4ClwPQOIHA.3556@TK2MSFTNGP03.phx.gbl,
Steve typed:
> Today, one of our internal DNS servers began reporting every host
> resolution as an address that has been traced to somewhere in China.
> We are actively trying to figure out what occurred. Replacing our
> actual domain with "test", here is what we saw in nslookup or regular
> pings.
> nslookup
> > www.test.com
> www.test.com.test.com (china address)
> > validhost1.test.com
> validhost1.test.com.test.com (china address)
> > invalidname1.test.com
> invalidname1.test.com.test.com (china address)
>
> What was happening?
>
> TIA

Try putting a period at the end of the query. Apparently it is suffixing
your search suffix and the period will stop that. Can you post an ipconfig
/all (unedited if you can please) so we can further evaluate your machine's
configuration?

Thanks,

--
Regards,
Ace

This posting is provided "AS-IS" with no warranties or guarantees and
confers no rights.

Ace Fekay, MCSE 2003 & 2000, MCSA 2003 & 2000, MCSE+I, MCT,
MVP Microsoft MVP - Directory Services
Microsoft Certified Trainer

Infinite Diversities in Infinite Combinations

Having difficulty reading or finding responses to your post?
Try using Outlook Express or any other newsreader, configure a news
account, and point it to news.microsoft.com. Anonymous access. It's
easy and it's free:

How to Configure OEx for Internet News
http://support.microsoft.com/?id=171164

"Life isn't like a box of chocolates or a bowl of cherries or
peaches... Life is more like a jar of jalapenos. What you do today
may burn your butt tomorrow." - Garfield

 >> Stay informed about: Were we poisioned, spoofed or something else? 
Back to top
Login to vote
Display posts from previous:   
   Win 2000/NT/98/ME (Home) -> DNS All times are: Eastern Time (US & Canada)
Page 1 of 1

 
You can post new topics in this forum
You can reply to topics in this forum
You can edit your posts in this forum
You can delete your posts in this forum
You can vote in polls in this forum

Categories:
 Windows XP
  Win 2000/NT/98/ME
 Windows Vista!


[ Contact us | Terms of Service/Privacy Policy ]