CastleCops, Internet Crime Fighters
Need help? Click here to register for free! Absolutely zero advertisements on this site!

$9736.22 of $21422.68
left sidedonated so farneed $11686.46 donated to reach our goalright side, our goal
Help CastleCops serve the community on new servers, Donate Here to reach our goal.

Donation/Premium
spacer
block bottom
Security Central
spacer
· Home
· PIRT/Fried Phish
· MIRT
· SIRT
· Deutsch
· Wiki
· Newsletter
· O16/ActiveX
· CLSID List
· Contest2007
· Downloads
· Feedback (send)
· Forums
· HijackThis
· Hijacktrend
· LSPs
· My Downloads
· O18
· O20
· O21
· O22
· O23
· O9
· Premium
· Private Messages
· Proxomitron
· Reviews
· Search
· StartupList
· Stories Archive
· Submit News
· WsIRT
· Your Account
· Acceptable Use Policy
block bottom
Survey
spacer
Was 2007 a good year?

Yes it was a wonderful year
Yes, but there is always room for improvement
Status quo
It was a challenge
Other (leave comment)



Results
Polls

Votes: 937
Comments: 25
block bottom
spacer spacer

Mysteries of domains, name servers, etc.

 
Post new topic   Reply to topic       All -> FavForums -> Complainterator [del.icio.us!] [digg it!] [reddit!]
View previous topic :: View next topic  
Author Message
pwillener

SRT Trainee
SRT Trainee
Premium Member

Joined: Apr 17, 2006
Posts: 1721
Location: Japan
Premium

PostPosted: Tue Jun 03, 2008 5:05 am    Post subject: Mysteries of domains, name servers, etc.
Reply with quote

Well, there is something I don't understand, so let me start a thread for "mysteries". I'm sure someone here has a good explanation.

The domain name lookup

Quote:
Domain Name: wassdoe.com

Status: ok

Registrar: XIN NET TECHNOLOGY CORPORATION
Whois Server: whois.paycenter.com.cn
Referral URL: http://www.xinnet.com

Expiration Date: 2009-05-13
Creation Date: 2008-05-13
Last Update Date: 2008-05-13

Name Servers:
ns1.yuoowrx.com
ns2.yuoowrx.com

The traversal
Quote:
Getting NS record list at b.root-servers.net... Done!
Looking up at the 13 com. parent servers:

ServerResponseTime
l.gtld-servers.net [192.41.162.30][Reports no a record (NXDOMAIN)]62ms
e.gtld-servers.net [192.12.94.30][Reports no a record (NXDOMAIN)]31ms
f.gtld-servers.net [192.35.51.30][Reports no a record (NXDOMAIN)]46ms
g.gtld-servers.net [192.42.93.30][Reports no a record (NXDOMAIN)]62ms
d.gtld-servers.net [192.31.80.30][Reports no a record (NXDOMAIN)]46ms
k.gtld-servers.net [192.52.178.30][Reports no a record (NXDOMAIN)]156ms
h.gtld-servers.net [192.54.112.30][Reports no a record (NXDOMAIN)]124ms
i.gtld-servers.net [192.43.172.30][Reports no a record (NXDOMAIN)]140ms
j.gtld-servers.net [192.48.79.30][Reports no a record (NXDOMAIN)]155ms
c.gtld-servers.net [192.26.92.30][Reports no a record (NXDOMAIN)]77ms
a.gtld-servers.net [192.5.6.30][Reports no a record (NXDOMAIN)]62ms
m.gtld-servers.net [192.55.83.30][Reports no a record (NXDOMAIN)]252ms
b.gtld-servers.net [192.33.14.30][Reports no a record (NXDOMAIN)]312ms

Status: Records all match.

MY question: why does the URL still go to the original "Prestige Replica" website...?

Back to top
View users profile Send private message Visit posters website
pwillener

SRT Trainee
SRT Trainee
Premium Member

Joined: Apr 17, 2006
Posts: 1721
Location: Japan
Premium

PostPosted: Tue Jun 03, 2008 8:40 am    Post subject:
Reply with quote

I have to add that both wassdoe.com and www.wassdoe.com resolve to 89.38.113.107.

Back to top
View users profile Send private message Visit posters website
tembow

Blue Angel
Premium Member

Joined: Oct 10, 2005
Posts: 2883

Blue Security Premium

PostPosted: Tue Jun 03, 2008 10:09 am    Post subject:
Reply with quote

You can't trust the Last Update Date information. Not all systems modify it when updates occur.

My guess is that its address record was removed in the past 24 hours. The whois shows a status of OK. That means that the removal was performed by either an incompetent registrar, or the domain name owner.

That it was loading when you tested it reflects the way the Internet is designed to perform, using cached name->address resolution data. Removing access to a site can take 24 hours to filter out across the whole Internet.

If the Address record is not reinstated, you will see access to the site fail after a day. The traversal fails because it does everything it can to bypass the caching. In a way, a traversal gives you a preview of what will happen to the site over the next 24 hours after a change has been made and put into effect - in this case the removal of the address resolution
records.

Back to top
View users profile Send private message Visit posters website AIM Address
pwillener

SRT Trainee
SRT Trainee
Premium Member

Joined: Apr 17, 2006
Posts: 1721
Location: Japan
Premium

PostPosted: Wed Jun 04, 2008 3:20 am    Post subject:
Reply with quote

Thanks!

Quote:
Firefox can't find the server at www.wassdoe.com

Cool

Back to top
View users profile Send private message Visit posters website
pwillener

SRT Trainee
SRT Trainee
Premium Member

Joined: Apr 17, 2006
Posts: 1721
Location: Japan
Premium

PostPosted: Tue Jul 01, 2008 4:17 am    Post subject:
Reply with quote

Another mystery - to me, at least...

Quote:
Domain Name: truakos.com

Status: ok

Registrar: HICHINA WEB SOLUTIONS (HONG KONG) LIMITED
Whois Server: grs.hichina.com
Referral URL: http://whois.hichina.com

Expiration Date: 2009-06-21
Creation Date: 2008-06-21
Last Update Date: 2008-06-21

Name Servers:
 dns217.deletedns.com
 dns218.deletedns.com

The traversal shows IP address 0.0.0.0 for both domain name servers. Yet both truakos.com and www.truakos.com resolve to truakos.com, and display their target website in the browser.

Back to top
View users profile Send private message Visit posters website
ahoier

SIRT Handler


Joined: Jan 14, 2006
Posts: 1024
Location: USA

PostPosted: Tue Jul 01, 2008 12:43 pm    Post subject:
Reply with quote

tried clearing all your caches, dns, etc?

That is very odd....traversal shows the 0.0.0.0
http://private.dnsstuff.com/tools/traversal.ch?domain=truakos.com&type=A&token=11a0aba66da33b3d25d2b49601999019

But both dns servers are "timing out"

Opendns.com/cache resolves the domain to 222.186.13.10 in New York, New York, USA, London, England, UK, and Palo Alto, CA, USA, BUT, 221.230.2.221 from Washington, DC, USA and Seattle, Washington, USA...

definately a mystery Smile

Back to top
View users profile Send private message Visit posters website AIM Address Yahoo Messenger MSN Messenger
tembow

Blue Angel
Premium Member

Joined: Oct 10, 2005
Posts: 2883

Blue Security Premium

PostPosted: Wed Jul 02, 2008 6:27 am    Post subject:
Reply with quote

queries will be returned by 222.186.13.10 (dns217.deletedns.com)
truakos.com. 130 IN A 222.186.13.10 **

queries will be returned by 221.230.2.221 (dns218.deletedns.com)
truakos.com. 130 IN A 221.230.2.221 **
** person: Chinanet Hostmaster
e-mail: anti-spam@ns.chinanet.cn.net

http://uptime.netcraft.com/up/graph/?host=truakos.com

Back to top
View users profile Send private message Visit posters website AIM Address
Display posts from previous:   
Post new topic   Reply to topic       All -> FavForums -> Complainterator All times are GMT
Page 1 of 1

 
Quick Reply:
Username: 

Quote the last message
Attach signature (signatures can be changed in profile)
 
You can post new topics in this forum
You can reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
You can attach files in this forum
You can download files in this forum


Powered by phpBB © 2001 phpBB Group
spacer spacer