Is It Normal To Be An Open DNS Server
Mar 20, 2007I found out that my server has open DNS. Anyone in the world can query it for domains it is not authoritative for. Is it normal?
View 6 RepliesI found out that my server has open DNS. Anyone in the world can query it for domains it is not authoritative for. Is it normal?
View 6 Repliesmy server runs sata 2 but this is only consumer and recommended to use 7 hours per day while there is sata 2 server hdd type
which one should i pick?
i have this hard disk ST3500830AS
i want to get this instead but will that be necessary? will RE3 get a longer lifespan ST3500830AS
re3 [url]
And i dont plan to get raid
What is the maximum load on a shared hosting server for it to be considered normal?
View 6 Replies View Relatedwhat is the normal load on this server
Single Processor Quad Core Xeon 5310 - 1.60GHz (Clovertown) - 1 x 8MB cache
4 GB ram
i hosted on it about 220 VB forums
Hi over the last week ive been having numerous problems with hosting accounts on 2 different servers which has lead me to think that my 'security' is not 'secure' and a malicious user is at play. im in the uk on broadband on a private connection to the internet - no-one else should be sharing this connection. This is the traceroute from my connection at home to the server ive had the most problems with - is this normal?
Traceroute has started ...
a certain host I've been with for over 6 months now experiences what I would consider always very high server load. The server load is normally around 4-6ish, rarely below that. A few times a day it spikes to around 12ish, sometimes even more. The server has 4 cpus. Is this just some really big time overselling? They had downtime once for 2 days when a server crashed, and after that the server load has been really high, when before that it was normally around 1-2, and in the 0.50s
View 14 Replies View RelatedI reserved a private server on a company n I supposed to have 10GB of space, I recived it with about 2.4GB space used, I thought it's the system files, is that correct or the files shall be deleted?
View 14 Replies View RelatedI have a webserver that our main two company websites reside on and this box also hosts ~50 other misc. websites. None of the websites on the server are very CPU intensive and bandwidth usage on the box is next to none.
Every morning around 4-6am the server takes forever to load anything. Seeing as this is when I do most of my work, I quickly become frustrated when trying to load our admin area, webmail, etc. Note that things do load, just very slowly...
I've contacted my tech a couple of times but he says this is normal as it's backups and stats running. I guess my question is, IS this normal? If so, is there a way to lessen the load at all?
I just did a reverse IP lookup for my newly purchased dedicated server and found out that the domain hosts two other domains, not owned by me.
By the way, I'm yet to updated the DNS address to point to my new dedicated server.
Is this normal or I need some more clarifications from my web host?
Host will only update DNS in batches, takes several hours for a DNS change, is that normal?
Well today my mail stopped working and it turns out the A record for mail was deleted. How it got deleted I don't know.
I called my host and after speaking to 2 techs, they said that have added my request to a batch, and that would update in a few hours.
I said to him, batch? What can't you do it instantly?
He said thats not the way their DNS works and any DNS change would affect thousands of other sites they are hosting.
Does anyone know what kind of dns system these people could possibly have where they can not reload a single zone?
And by affected, I think he means the sites will go down for a minute or so, while it relaods every zone. Is this really the case, or are these people just idiots?
I have dedicated server..i installed cpanel on it but when am accessing it
[url]
i am not able to open it..so i think port is not open so can any one tell me how to open ports...the os installed is centos..
A potential client asked us the followingo you allow PHP to open sockets on your server? If yes, is there any restriction on the amount of data that can be downloaded?
Will we be able to access and load our remote webpage using PHP? We will use sockets and a Pear library to accomplish this.
We are basically planning on using some content from our remote site on the new site which will be hosted on your servers. Kindly reply back at the earliest.
Is this a potential spammer?
I've run "DNS report" test for one hosting in dnsstuff.com and got this warning (as some times before for other hosts:
---------------------
Fail:
Open DNS server
ERROR: One or more of your nameservers reports that it is an open DNS server. This usually means that anyone in the world can query it for domains it is not authoritative for (it is possible that the DNS server advertises that it does recursive lookups when it does not, but that shouldn't happen). This can cause an excessive load on your DNS server. Also, it is strongly discouraged to have a DNS server be both authoritative for your domain and be recursive (even if it is not open), due to the potential for cache poisoning (with no recursion, there is no cache, and it is impossible to poison it). Also, the bad guys could use your DNS server as part of an attack, by forging their IP address.
-----------------------
Is this anythhing important?
Just being doing a load of DNSstuff.com queries to try and get everything to "pass", I noticed that some big players in the hosting scene have either open or closed DNS servers.
Softlayer.com have closed, while liquidweb.com are open...?
I have changed all mine to closed, just because dnsstuff advises it, but is there any reason you would want them open..?
I have a server that is running linux with WHM/cPanel , some of servers are rejecting mails through server and says that your server is open proxy mail server.
how to check that our server is open proxy or stop open proxy and how can i prevent our server from spammer?
I'm having problems with users using open proxies accessing, abusing, and defacing my website.
I'd like to get a list of all open proxies and incorporate it into my site (i.e. block open proxy accesses)
I've already looked at SORBS, but that is DNS based, and I'm not sure I want to go that route. (I am running one DNS server for my own webserver to use. Don't want to mess with adding another zone for the dnsbl).
I've be much happier building my own php/mysql lookup of the proxy blacklist.
So I'm looking for somewhere I can simply download a proxy blacklist, and update it periodically as needed.
I am using Putty to connect to my server via ssh.
When opening a direct connection, i can login quickly without any problem
Quote:
login as: gracie
gracie@server1's password:
Last login: Thu May 7 07:31:26 2009 from 192.168.0.5
gracie@server1 [~]# sudo su -
Password:
root@server1 [~]#
When I open a connection FROM ANOTHER SERVER, I have to wait more than 20 seconds
Quote:
login as: tech2
tech2@server2's password:
Last login: Thu May 7 07:32:07 2009 from 192.168.0.5
tech2@server2 [~]# ssh gracie@192.168.0.222
Password:
After I enter the password, I waited 20 seconds before I am logged in.
Our new data center provided us with a Cisco ASA5510 firewall. We're setting up all new servers and will begin migrating all of our domains from our current co-lo to the new place.
At the old co-lo, they provided us a very basic BSD based router, and our servers all had external public facing IPs on them. Firewalling was handled at the server (Windows Firewall or Linux IPtables).
The new place is NAT'ing us, so our servers all have a 192.168.10.x address inside, and they map the external address for us through to the inside.
By default, they are locking everything down. I had to ask them to open ssh so I could remote into my CentOS box last night.
I'm not a network guru-- what ports are going to NEED to be opened so I can give them a list? This is a standard PLESK hosting server so http (80), https, ssh, ftp, pop3, smtp, what else? Anyone have a list?
subdomains on my dedicated server with co.il endings (israeli) dont work though with com domains they do work i anybody has a clue for fixing this? maybe its DNS directing problems.
View 2 Replies View RelatedThought this might be of interest to folks on WHT. We put together a solution using Nginx ( Engine-X ) to do Global Server Load Balancing. This solution lets you do GSLB without having to fork over $26k per site to F5 or Foundry.
Thought it would be of interest to both end-users as well as dedicated hosting providers who might want to make it into a service (eg. sell a dedicated host in Europe and the US as a group, with the solution pre-installed).
The entire project, including relavent configs is available for download in the latest ( issue 6 ) FREE issue of o3 magazine (o3magazine.com)
I want to set up a dedicated server for spam and virus filtering (MX)
But i was wondering, is there a good opensource based tool for this?
How can I open port 3000 on my linux server.
I need it for Canada Post live shipping quotes.
I have used the patch : [URL] .... to disable ssl v3.
After I applied the patch getting error below when i try to send email via horde webmail:
There was an error sending your message: Could not open secure TLS connection to the server.
Roundcube can send mails well but horde not. Otherwise since applied the parch i can't get mails from gmail and maybe other providers i don't know yet.
I found these strange random name files on the tmp anyone know what are they and are that normal?
4Hq7Xb Dbrfns lost+found MGlWaF p6w849 PP5uVI SoArWn spamd_light.sock ToL3Ah Vt0ICH xEgXsU zVLVDa
AGs49w fcKNmJ LyC11q O3VQwM pAD0WL psa spamd_full.sock tLnzRx tXqqGI x7uxxo XuFzJl
I had a client ask me earlier if there was any downsides to having his main site be SSL only ,not his billing his actual site.
For exmaple it would be https://www.yoursite.com rather than the normal http and having that redirect to the https.
Obviously he would need all his images being linked to https in order for it to be secure but apart from that, I couldn't think of any of the top of my head, I was wondering what you guys all thought.
I just uploaded a wordpress site and it already used up 300mb ram. The site receives very little traffic so I doubt the traffic is the cause of the ram usage. Is this normal? my control panel is webmin
Code:
ID Owner Size Command
17691 mysql 129620 kB /usr/libexec/mysqld --basedir=/usr --datadir=/var/lib/mysql --user=mysql --pid-f ...
13799 named 70392 kB /usr/sbin/named -u named
14329 apache 44176 kB /usr/sbin/httpd
28588 apache 41028 kB /usr/sbin/httpd
7812 apache 38016 kB /usr/sbin/httpd
23719 apache 37416 kB /usr/sbin/httpd
23825 apache 36800 kB /usr/sbin/httpd
19656 root 24224 kB /usr/sbin/httpd
23973 root 12628 kB /usr/libexec/webmin/proc/index_size.cgi
23972 root 12232 kB /usr/libexec/webmin/blue-theme/left.cgi
19533 root 10776 kB /usr/bin/perl /usr/libexec/webmin/miniserv.pl /etc/webmin/miniserv.conf
18376 root 9024 kB sendmail: accepting connections
18384 smmsp 8116 kB sendmail: Queue runner@01:00:00 for /var/spool/clientmqueue
17479 root 7120 kB /usr/sbin/sshd
32654 root 5568 kB /usr/sbin/saslauthd -m /var/run/saslauthd -a pam -n 2
32655 root 5568 kB /usr/sbin/saslauthd -m /var/run/saslauthd -a pam -n 2
32644 root 4396 kB crond
17631 root 3608 kB /bin/sh /usr/bin/mysqld_safe --datadir=/var/lib/mysql --socket=/var/lib/mysql/my ...
32594 root 2716 kB xinetd -stayalive -pidfile /var/run/xinetd.pid
7794 nobody 2480 kB proftpd: (accepting connections)
11909 root 2144 kB /sbin/udevd -d
1 root 2060 kB init [3]
32556 root 1716 kB syslogd -m 0
just reading my exim mainlog
there are soo many entries in there like activities every second
is this thing normal? does everyone get things like that?
2007-12-01 15:39:03 [24780] H=(acasa-wunxr966z) [89.137.206.241]:4505 I=[69.16.237.199]:25 F=<hurdlingm290@tulipjewelry.com> rejected RCPT <a$
2007-12-01 15:39:03 [24780] SMTP connection from (acasa-wunxr966z) [89.137.206.241]:4505 I=[69.16.237.199]:25 closed by DROP in ACL
2007-12-01 15:39:03 [24777] H=pool-71-178-230-135.washdc.fios.verizon.net (Wireless_Broadband_Router) [71.178.230.135]:4624 I=[69.16.237.199]$
2007-12-01 15:39:03 [24777] SMTP connection from pool-71-178-230-135.washdc.fios.verizon.net (Wireless_Broadband_Router) [71.178.230.135]:462$
2007-12-01 15:39:03 [24776] H=pool-71-178-230-135.washdc.fios.verizon.net (Wireless_Broadband_Router) [71.178.230.135]:4623 I=[69.16.237.199]$
2007-12-01 15:39:03 [24776] SMTP connection from pool-71-178-230-135.washdc.fios.verizon.net (Wireless_Broadband_Router) [71.178.230.135]:462$
2007-12-01 15:39:03 [1382] SMTP connection from [200.61.182.11]:55819 I=[69.16.237.199]:25 (TCP/IP connection count = 7)
GNU nano 1.2.4 File: exim_mainlog
2007-12-02 01:25:14 [17530] ident connection to 85.168.154.92 timed out
2007-12-02 01:25:15 [1382] SMTP connection from [75.82.171.71]:1614 I=[69.16.237.199]:25 (TCP/IP connection count = 9)
2007-12-02 01:25:16 [17527] H=adsl196-236-229-217-196.adsl196-16.iam.net.ma [196.217.229.236]:59900 I=[69.16.237.199]:25 F=<patti@myrealbox.c$
2007-12-02 01:25:16 [17527] SMTP connection from adsl196-236-229-217-196.adsl196-16.iam.net.ma [196.217.229.236]:59900 I=[69.16.237.199]:25 c$
2007-12-02 01:25:16 [17528] H=79.red-83-42-176.dynamicip.rima-tde.net [83.42.176.79]:29547 I=[69.16.237.199]:25 F=<mostafa.Brindel@bhcat.com>$
2007-12-02 01:25:16 [17528] SMTP connection from 79.red-83-42-176.dynamicip.rima-tde.net [83.42.176.79]:29547 I=[69.16.237.199]:25 closed by $
2007-12-02 01:25:16 [1382] SMTP connection from [79.120.55.8]:4202 I=[69.16.237.199]:25 (TCP/IP connection count = 8)
2007-12-02 01:25:17 [17531] ident connection to 75.82.171.71 timed out
2007-12-02 01:25:17 [17529] H=(cpe-76-91-84-170.socal.res.rr.com) [76.91.84.170]:4913 I=[69.16.237.199]:25 F=<occurrenceq@bhrugu.com> rejecte$
2007-12-02 01:25:17 [17529] SMTP connection from (cpe-76-91-84-170.socal.res.rr.com) [76.91.84.170]:4913 I=[69.16.237.199]:25 closed by DROP $
2007-12-02 01:25:17 [17530] H=m92.net85-168-154.noos.fr [85.168.154.92]:1310 I=[69.16.237.199]:25 F=<Eng-Mroz@ROWELLMANAGEMENT.COM> rejected $
2007-12-02 01:25:17 [17530] SMTP connection from m92.net85-168-154.noos.fr [85.168.154.92]:1310 I=[69.16.237.199]:25 closed by DROP in ACL
2007-12-02 01:25:18 [17531] H=cpe-75-82-171-71.socal.res.rr.com [75.82.171.71]:1614 I=[69.16.237.199]:25 F=<Kallio@jeunesfilles.org> rejected$
2007-12-02 01:25:18 [17531] SMTP connection from cpe-75-82-171-71.socal.res.rr.com [75.82.171.71]:1614 I=[69.16.237.199]:25 closed by DROP in$
2007-12-02 01:25:18 [1382] SMTP connection from [201.228.173.190]:48177 I=[69.16.237.199]:25 (TCP/IP connection count = 6)
2007-12-02 01:25:18 [1382] SMTP connection from [24.29.242.1]:1137 I=[69.16.237.199]:25 (TCP/IP connection count = 7)
2007-12-02 01:25:18 [1382] SMTP connection from [189.138.165.115]:3302 I=[69.16.237.199]:25 (TCP/IP connection count = 8)
2007-12-02 01:25:19 [17535] H=ppp1-139.ciscom.ru [79.120.55.8]:4202 I=[69.16.237.199]:25 F=<attorneylff8@torborg.com> rejected RCPT <azeer@mp$
2007-12-02 01:25:19 [17535] SMTP connection from ppp1-139.ciscom.ru [79.120.55.8]:4202 I=[69.16.237.199]:25 closed by DROP in ACL
2007-12-02 01:25:19 [1382] SMTP connection from [189.31.128.172]:52503 I=[69.16.237.199]:25 (TCP/IP connection count = 8)
2007-12-02 01:25:20 [17538] ident connection to 201.228.173.190 timed out
2007-12-02 01:25:20 [17538] no host name found for IP address 201.228.173.190
2007-12-02 01:25:20 [17538] list matching forced to fail: failed to find host name for 201.228.173.190
2007-12-02 01:25:20 [17539] ident connection to 24.29.242.1 timed out
2007-12-02 01:25:20 [17539] no IP address found for host cpe-24-29-242-1.neo.res.rr.com (during SMTP connection from [24.29.242.1]:1137 I=[69$
2007-12-02 01:25:20 [17539] list matching forced to fail: failed to find host name for 24.29.242.1
2007-12-02 01:25:20 [17540] ident connection to 189.138.165.115 timed out
2007-12-02 01:25:20 [17540] no IP address found for host dsl-189-138-165-115.prod-infinitum.com.mx (during SMTP connection from [189.138.165.$
2007-12-02 01:25:20 [17540] list matching forced to fail: failed to find host name for 189.138.165.115
2007-12-02 01:25:21 [17539] H=(cpe-24-29-242-1.neo.res.rr.com) [24.29.242.1]:1137 I=[69.16.237.199]:25 F=<lesley.Ervamaa@agustinbarreto.com> $
2007-12-02 01:25:21 [17539] SMTP connection from (cpe-24-29-242-1.neo.res.rr.com) [24.29.242.1]:1137 I=[69.16.237.199]:25 closed by DROP in A$
2007-12-02 01:25:21 [17541] ident connection to 189.31.128.172 timed out
2007-12-02 01:25:21 [17541] no host name found for IP address 189.31.128.172
2007-12-02 01:25:21 [17541] list matching forced to fail: failed to find host name for 189.31.128.172
2007-12-02 01:25:21 [17538] H=(201.228.173.190) [201.228.173.190]:48177 I=[69.16.237.199]:25 F=<thiam3@searchhound.com> rejected RCPT <larifi$
2007-12-02 01:25:21 [17538] SMTP connection from (201.228.173.190) [201.228.173.190]:48177 I=[69.16.237.199]:25 closed by DROP in ACL
2007-12-02 01:25:22 [1382] SMTP connection from [82.73.58.94]:1465 I=[69.16.237.199]:25 (TCP/IP connection count = 7)
2007-12-02 01:25:22 [17540] H=(dsl-189-138-165-115.prod-infinitum.com.mx) [189.138.165.115]:3302 I=[69.16.237.199]:25 F=<emasculateq@tulsavrp$
2007-12-02 01:25:22 [17540] SMTP connection from (dsl-189-138-165-115.prod-infinitum.com.mx) [189.138.165.115]:3302 I=[69.16.237.199]:25 clos$
2007-12-02 01:25:22 [1382] SMTP connection from [71.107.124.63]:1886 I=[69.16.237.199]:25 (TCP/IP connection count = 7)
I plan on installing dos_evasive as it can temporarily kill/ban an IP that makes over X amount of connections.
I ran netstat -ntu | awk '{print $5}' | cut -d: -f1 | sort | uniq -c | sort -n, and this is what I got:
10 218.111.214.231
10 219.95.251.185
10 222.124.226.228
10 58.187.167.20
10 61.94.234.75
10 62.168.125.217
10 82.160.42.74
10 87.116.131.18
10 89.41.71.178
11 200.193.24.226
11 218.186.9.1
11 219.93.199.121
11 220.235.171.64
11 59.128.43.234
11 60.53.77.34
11 63.109.246.234
11 83.20.72.102
11 83.237.102.75
11 84.234.144.107
11 88.226.100.145
11 88.240.137.82
12 195.229.236.216
12 203.79.252.192
12 212.90.248.182
12 220.132.87.2
12 80.130.75.239
12 82.114.184.16
12 83.26.18.242
12 85.30.223.227
12 86.108.127.28
12 87.109.49.69
12 88.247.64.131
13 200.52.193.228
13 202.155.71.40
13 222.124.172.177
13 82.116.129.110
14 195.93.21.1
14 41.251.65.79
14 80.5.154.95
14 81.10.80.75
14 82.224.40.111
14 86.17.117.193
15 196.218.42.134
15 201.19.134.99
15 212.200.185.213
15 217.171.180.249
15 218.208.196.224
15 222.124.101.183
15 80.134.70.222
15 85.160.97.238
15 88.232.120.183
16 200.188.254.9
16 200.52.193.236
16 212.118.15.140
16 81.192.124.52
16 83.14.145.170
16 85.138.71.91
16 87.207.16.154
16 89.113.75.141
17 61.196.234.202
17 82.89.37.29
17 86.135.231.183
18 80.232.249.45
18 82.114.184.206
18 88.101.26.210
19 163.121.149.170
19 194.29.137.41
19 194.44.45.13
19 195.242.99.125
19 196.202.14.244
19 196.218.117.135
19 202.158.121.223
19 81.67.245.180
19 84.255.141.132
20 200.52.193.229
20 219.83.5.20
20 88.229.128.50
20 89.245.120.136
21 196.218.143.124
21 203.130.201.196
21 63.170.84.176
21 66.249.72.173
21 72.14.207.191
21 81.192.135.224
21 82.66.227.150
21 84.29.1.151
22 155.143.244.17
22 195.207.101.112
22 202.153.240.168
22 61.94.125.143
22 85.101.146.161
23 124.106.151.75
23 88.149.99.7
24 82.77.27.129
24 88.16.34.231
25 160.39.145.94
25 202.153.240.70
25 216.125.127.12
26 196.205.97.92
26 200.104.157.183
26 202.163.117.8
26 213.180.127.198
26 60.50.95.39
26 85.71.230.49
27 194.29.137.52
27 195.189.142.249
27 201.226.162.206
27 210.6.13.208
27 81.203.41.204
27 86.90.238.96
28 193.0.240.121
28 212.76.37.150
28 89.120.133.44
29 125.162.66.116
29 74.53.121.131
30 203.222.202.121
30 213.39.219.81
30 71.109.116.122
31 222.124.143.18
31 89.34.87.91
33 193.0.240.113
33 201.9.175.242
33 212.71.37.101
33 70.68.249.239
33 81.77.85.207
34 195.229.236.215
34 86.123.142.128
35 72.49.255.217
35 85.31.137.11
36 193.231.17.50
36 202.69.97.206
36 90.156.29.82
37 77.122.158.251
37 89.40.138.184
38 121.52.52.6
38 203.218.71.132
38 82.167.71.189
39 213.17.10.87
40 196.218.145.82
40 201.22.94.226
40 206.73.210.65
40 86.9.66.1
41 152.78.243.248
42 201.220.93.84
42 210.5.121.190
43 196.204.241.250
43 196.218.89.213
44 196.218.96.82
46 84.56.103.77
48 125.212.148.112
48 41.251.69.199
49 83.203.134.84
50 213.119.151.116
50 80.133.209.50
52 81.38.15.124
53 195.245.232.26
54 88.0.63.179
57 82.201.222.144
57 83.131.27.137
57 84.226.41.129
61 129.215.149.96
64 195.113.227.31
65 198.150.36.49
65 61.102.87.80
71 84.56.109.139
73 82.216.54.222
76 196.218.136.202
76 87.118.157.79
77 89.35.90.211
78 59.127.203.49
79 81.10.35.77
81 82.148.97.68
82 213.171.62.94
84 84.36.132.189
104 213.6.215.214
108 213.51.9.184
108 41.250.0.35
110 83.41.58.76
125 84.22.2.55
132 87.209.11.249
155 196.218.142.212
165 195.242.99.84
176 200.73.225.104
190 62.135.105.86
2946 195.242.99.102
server:/#
Does that look normal to you? Because I read somewhere that you should allow no more then 30 connections per IP. But most are taking much more then that.
the Normal VPS load,
As for mine is:
Server Load 0.35 (2 cpus)
Memory Used 57.5 %
Swap Used 0.00 %
Disk /dev/simfs (/) 27 %
Also I am not getting why the swap on VPS is not used at all...