Protecting Bind Areas
Jan 22, 2008how to protect My datas about domains in My bind, when using command
a@r:~$host -l -t any example.com?
how to protect My datas about domains in My bind, when using command
a@r:~$host -l -t any example.com?
I am using vps
I am receving calls from some countries or areas when they say they can not access my site ( site can not be found)
I called my provider and they say every thing is alright from their site
and from my side too but some areas in other countries like right now I received a call from canada they can not access my site my provider wants me to send Tracert
I can ask my friends to send that but not every user why this happanes and what tools are available to check and see if my site is alright from all areas or counties?
Any Dedicatednow.com customers here? Where do you pay your bills?
I got an invoice but there are about 3 different areas for logging in it seems and I can only log into one of them. But that area does not have an invoice...
Here are the 3 different possible areas.
[url]
[url]
[url]
Which the heck is the correct area for all your billing, so I can contact them for my login? I have been paying last 2-3 months but I cannot remember how on earth I paid. I also don't know how to contact them except their technical support which is support@.
I looked at their initial welcome emails which also don't provide much information, a billing info directs me to the pwebtech website which is just ubersmith - and it looks out of date, I have 2 servers with them but only 1 appear and the latest invoice that was email does not appear nor its server.
I have a client who uses formmail on our dedicated server(another 140 clients also share this PLESK/LINUX server). While the formmail script has not been hacked, some schmuk spends the time to fill it out with spam 5-6 times a day and sends them to the client.
I verified the emails go only to the site owner and nobody else.
QUESTION: Is there a way to exclude the entire world and only allow visitors from the metro Chicago area? This would need to be done via .htaccess and not IPTABLES, as the other sites on the server draw world wide traffic.
I'm scratching my head on this, but if possible it would exclude our schmuk friend while allowing the local traffic this client draws from.
I was on my visitors on AWstats, and when looking up most of the top IPs (the ones that viewed the most pages), most of them were associated with IANA, and tagged as spam/hacker IPs.
Of course, I've blocked all of those IPs with my .htaccess file, but how can I further protect my server from such threats? How can I rid my server of these spammers/hackers?
how do i protect a file directory from be accessed view a web browser but still allowing scripts like flash to access it?
i have a folder with xml files in it and i don't want a user pulling them up via there webbrowser.
My company provides various reports and dynamic website content to clients whose websites we design and host as well as to clients who have their sites designed and hosted elsewhere. We do not want people to be able to easily link to our content or bring it up in an iframe or whatever unless they are a paid subscriber. We would like to be able to limit the content to the domains of paying clients and keep it from displaying elsewhere. Note also that out of several reports, publications and content we offer, clients can mix and match, subscribe to just one element or all of them (The subscription levels are managed by us on the back end.)
Currently we have a system that is built in Perl/Postgres SQL and it is problematic(constantly failing and not very secure) Also it requires that the content be loaded into an iframe on the client's site or linked directly. We would like a solution that is PHP-based and can talk to our existing database. We would also like to be able to display the content on the page without an iframe so it is more search engine friendly, etc.
An off-the-shelf solution would be preferable if one is available - and we like to support the open source community.
This is a quote from an unrelated thread in the Dedicated Server Forum, I didnt want to hijack the thread so thought I would bring my question over here:
Quote:
Originally Posted by HRDev Hady
I believe they use BurstNet, which isn't really a good choice for DDoS-prone sites as their Top Layer devices don't seem to handle attacks very well in my opinion. If you're running a DDoS prone site, you'd likely be better off with a DDoS-specialized provider such as Awknet, Staminus, or Black Lotus. But as mentioned, a lot of attacks can be stopped simply by proper tuning of your IP stack and some simple firewall rules.
My question is as a new Dedicated Server Owner what tuning and rules do I need to implement in order to protect me from these "small scale DDoS Attacks"?
I do not run a DDoS prone site(i hope not lol) but I want to secure myself as much as possible and have a headache free run other than the headaches I cause myself of course.
Is there any good way to be able to put an e-mail address on one's own Web site, without making it an image, and keep it from harvesting bots?
I found this site: [url] and was wondering if it's valid and workable.
I was curious to know if there's a way to protect memory for certain programs. I have a VPS that is fairly light on memory, and there's been a few occasions when a program/bug will go wild and eat up all the memory locking me out of ssh/webmin.
Is there any way I can protect certain memory for certain processes/programs. Ideally I'd like some way for ssh to stay up in all situations.
I had no problems protecting my webpages hosted by Yahoo, but cannot figure it out for Go Daddy. I'm using Hosting Configuration 1.0. Can anyone help?
My .htaccess and .htpasswd looks good to me, but still the webpages are not protected.
I am looking to backup client data to a second hard drive on the server. I was wondering if there is any way to protect this data from virus's or any other software attack that may compromise the server data.
View 9 Replies View RelatedI am seeing some some some strange behaviour when password protecting directories served by nginx and PHP-FPM. If I have a site set up so that 'Process PHP by nginx' is selected under ('Websites & Domains>Web Server Settings>nginx settings') and set up password protection ('Websites & Domains>Password-Protected Directories') PHP pages are still served without asking for a password.
If I untick 'Process PHP by nginx' the behaviour returns to normal and an attempt to any access files results in the password request.Is this behaviour by design? If so, it is not made clear when you set up the password protection that it will not apply to PHP pages if you have nginx process the PHP pages.
OS: CentOS 6.6 (Final)
Plesk version: 12.0.18 Update #51
I upgrade bind with this :
# wget [url]
# tar xvfz bind-9.4.1-P1.tar.gz
# cd bind-9.4.1-P1
# ./configure
# make
# make install
but doesnt work I have always bind version is
PHP Code:
[root@server bind-9.4.1-P1]# named -vBIND 9.2.4
how can I make upgrade with the correct way?
i work in a new ISP company, and ive been assigned to the DNS server, and before this i have never even heard of BIND, but now im in need of learning it ....and im only fairly familiar to Linux..so here are me questions:
1. where can i find a beginners guide to DNS and BIND?
2. what distribution is best suited for the server?
3. are there any default templates for the BIND config files that one could start with and modify?
4. how many files are there? i mean every time a read a bit about BIND pops up a new file name.. so how many files are enough?
5. would any1 care to help me out step by step throught my ordeal?
6. are there any training courses that i could take? are there any onlline ones? or videos that i could grab off the net?
7. how many times does a swallow have to flap its wings to maintain airspeed velocity in order to carry a coconut?
which one is better for me?
VPS 512 ram and cpanel/whm centos
BIND or NSD?
and what's different between them?
This has been troubling me for a long time.. I know you can do this in FreeBSD with ipfw but I'm wanting to do this in linux.
Basicly bind an IP address say eth0:1 to a UID or GID so that this user may only listen on that particular IP, etc.
I have managed to install BIND 9.4 on my home web server so that i can have my own domain (one that i can manage). I have made a domain with it called h2o-cms.org, the domain will work when i connect to it from my home lan but if i use a cgi proxy to connect it can't be found.
I'm using Windows XP
This is my named.conf
Code:
// Config file for caching only name server
acl "friends" {
localnets;
127.0.0.1;
};
options {
directory "C:
amedetc";
version "SERVFAIL";
allow-transfer { none; };
allow-recursion { "friends";};
// Uncommenting this might help if you have to go through a
// firewall and things are not working out. But you probably
// need to talk to your firewall admin.
query-source port 53;
};
zone "." {
type hint;
file "named.root";
};
zone "0.0.127.in-addr.arpa" {
type master;
file "locals.hosts";
};
zone "h2o-cms.org" {
type master;
file "h2o-cms.org";
};
this is my h2o-cms.org file
Code:
$TTL 600
; h2o-cms.org
@ IN SOA laxlxns01.h2o-cms.org. hostmaster.h2o-cms. (
2005062601 ; serial
12h ; refresh
1h ; retry
2w ; expire
1h ; minimum
)
IN NS laxlxns01.h2o-cms.org.
IN NS laxlxns02.h2o-cms.org.
IN MX 10 mail.h2o-cms.org.
@ IN A 80.46.117.13
; host records
localhost IN A 127.0.0.1
www IN A 80.46.117.13
I have forwarded the port 535 to the server too
Not sure if this is the right place - sorry if it isn't. Recently, I got really pi**ed off with cPanel - and have decided to try and load my server without it.
I'm using Webmin/Usermin/Virtualmin with Apache, PHP, MySQL, proftpd, and BIND.
But I'm not entirely sure on how to create nameservers on BIND - I've looked all over the internet, but have found nothing helpful.
if it is possible to bind 2 NS to the same IP
For example, I previously had n1.abc.com , ns2.abc.com bind to certain IP. Now I registered another domain name, say abcdummy.com at another reseller and was given the option to choose my private dns. But instead of ns1.abcdummy.com and ns2.abcdummy.com, I thought this name doesn't sound that nice to be an NS. So I asked for ns3.abc.com and ns4.abc.com
Which has been registered and propogated successfully. But I want to move these domains on abc.com to abcdummy.com server, as i will not be using my reseller package at abc.com any more
So now, but its a lot work to do if I was to change these domain name NS one by one. So could I instead bind ns1.abc.com and ns2.abc.com to the same IP as ns3.abc.com and ns4.abc.com
I am trying to use BIND on Windows XP Professional to host a website off my computer using a domain. I have downloaded BIND but now I have no clue what to do. For the name servers of the domain I have put in my IP address.
What do I need to do to get a domain to point towards my computer?
I get the following message via SSH when i try named restart
named: symbol lookup error: named: undefined symbol: dns_resolver_setudpsize
All my sites are currently down but the server is up and bind wont restart either in WHM or SSH
i am using WHM 10.6.0 cPanel 10.8.0-R8
CentOS 4.3 i686 - WHM X v3.1.0
Linux ***.server.com 2.6.9-11.EL #1 Wed Jun 8 16:59:52 CDT 2005 i686 i686 i386 GNU/Linux
I spoke to live support at nexpoint but they told me to email their dedicated server support but I havent had a reply in the last few hours.
I am having some trouble with my DNS recently. Here are the errors I am receiving:
06-Apr-2009 19:09:13.921 could not open entropy source /dev/random: file not found
06-Apr-2009 19:09:13.921 ignoring config file logging statement due to -g option
06-Apr-2009 19:09:13.921 couldn't open pid file '/var/run/named/named.pid': Permission denied
[url]
Upgrade if this affects you.
has anyone successfully updated from bind9.2.x to BIND 9.5.0-P1? Were there any problems regarding settings, zone files, etc etc? Can you explain the process in detail for the update? One of my customers wishing to have this done, is running CentOS, I assume yum would be the best course of actions?
View 14 Replies View RelatedI ran "yum update" on one of my servers, and it must've updated BIND, because now named doesn't start.
I basically hit all the problems in this thread:
[url]
This is CentOS4 with Plesk.
Even though I don't have that package installed, and tried every suggestion there, it still doesn't start... I mucked with the configs and moved so many files I don't know how to get back to where I started.
Quote:
Jul 24 05:08:06 www named: /etc/named.conf:67: open: /etc/rndc.key: file not found
What's my best bet for fixing this mess? I sent in an e-mail to two "server administration" companies I found in signatures here, hopefully one of them will be available today.
I changed the nameservers on critical domains to a free DNS service to get them back online, but they're acting oddly (like DB timeouts), perhaps because of the lack of a local nameserver to talk to.
But in the meantime is there anything I can do to try to fix this quick?
bind in my server isn't working and when I restart it on cPanel this is what I get:
Restarting Bind
ERROR: ld.so: object '/tmp/libno_ex.so.1.0' from /etc/ld.so.preload cannot be preloaded: ignored.
Attempting to restart named Waiting for named to restart.... . . . . . . . . . . finished.
ERROR: ld.so: object '/tmp/libno_ex.so.1.0' from /etc/ld.so.preload cannot be preloaded: ignored. ERROR: ld.so: object '/tmp/libno_ex.so.1.0' from /etc/ld.so.preload cannot be preloaded: ignored. named status
ERROR: ld.so: object '/tmp/libno_ex.so.1.0' from /etc/ld.so.preload cannot be preloaded: ignored. ERROR: ld.so: object '/tmp/libno_ex.so.1.0' from /etc/ld.so.preload cannot be preloaded: ignored. named has failed, please contact the sysadmin (result was "named is not running"). Apr 26 17:54:09 orion named: ERROR: ld.so: object '/tmp/libno_ex.so.1.0' from /etc/ld.so.preload cannot be preloaded: ignored. Apr 26 17:54:09 orion named: zone localdomain/IN: loaded serial 42 Apr 26 17:54:09 orion named: zone localhost/IN: loaded serial 42 Apr 26 17:54:09 orion named: zone 0.0.127.in-addr.arpa/IN: loaded serial 1997022700 Apr 26 17:54:09 orion named: zone 0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.ip6.arpa/IN: loaded serial 1997022700 Apr 26 17:54:09 orion named: zone 255.in-addr.arpa/IN: loaded serial 42 Apr 26 17:54:09 orion named: zone 0.in-addr.arpa/IN: loaded serial 42 Apr 26 17:54:09 orion named: zone ns1.(domain.com)/IN: loaded serial 2008012001 Apr 26 17:54:09 orion named: zone orion.(domain.com)/IN: loaded serial 2008012001 Apr 26 17:54:09 orion named: zone (domain.com)/IN: loaded serial 2008042601 Apr 26 17:54:09 orion named: zone (domain.net)/IN: loaded (...)
And so on... for a lot of domains configured on this server. I don't think it loads all of them.
Then, right after seeing this problem I tried to connect to SSH while googling the problem and I got this:
Quote:
m-c-b:~ mcb$ ssh -l root (domain.com)
root@(domain.com)'s password:
Last login: Thu Apr 24 19:20:13 2008 from 87-196-13-151.ne
ERROR: ld.so: object '/tmp/libno_ex.so.1.0' from /etc/ld.so.preload cannot be preloaded: ignored.
ERROR: ld.so: object '/tmp/libno_ex.so.1.0' from /etc/ld.so.preload cannot be preloaded: ignored. ....
Im trying to Downgrade bind to 9.2.4 and im using Centos 5.1
Cant do it for some reason. Just getting error messages all the time.
I followed this tutorial but then found out its centos 4.1 so that was no help.
[url]