PDA

View Full Version : Open DNS servers


msource
25th May 2007, 20:59
I,

on DNSSTUFF, doing a report on a domain in my DNS Server's, i saw a FAIL in Open DNS servers.

There is anyway in MyDNS to mask/fake this pioint? Ore there are anything that a don't do and now is worng?

FAIL

Open DNS servers

ERROR: One or more of your nameservers reports that it is an open DNS server. This usually means that anyone in the world can query it for domains it is not authoritative for (it is possible that the DNS server advertises that it does recursive lookups when it does not, but that shouldn't happen). This can cause an excessive load on your DNS server. Also, it is strongly discouraged to have a DNS server be both authoritative for your domain and be recursive (even if it is not open), due to the potential for cache poisoning (with no recursion, there is no cache, and it is impossible to poison it). Also, the bad guys could use your DNS server as part of an attack, by forging their IP address. Problem record(s) are:

Server 62.48.187.50 reports that it will do recursive lookups. [test]
Server 62.48.187.49 reports that it will do recursive lookups. [test]
See this page for info on closing open DNS servers.

Sincirely,
Marcos Pinto

edge
26th May 2007, 00:27
http://www.howtoforge.com/forums/showthread.php?t=6900
(Please note that this is for ISPconfig. I do not know the path for MyDNSConfig)

msource
4th July 2007, 14:34
I,

That Fix is for Bind, could someone know's how to FIX in MyDNS?

Sincerely,
Marcos Pinto

falko
5th July 2007, 14:39
I think the recursive setting is what you're looking for: http://mydns.bboy.net/doc/html/mydns_32.html#SEC32

msource
9th November 2007, 12:40
Hi Falko,

I follow this toturial: http://www.howtoforge.com/mydns_mydnsconfig_dnsmasp_on_ubuntu_edgy

Installed on debian etch, with two NS server's with MySQL DB Replication.

What i whant is to "maskarate" the messege OpenDNS. When i do a test on one domain.tld in www.dnsstuff.com, it apeers a message [Open DNS servers(Server 62.48.187.49 reports that it will do recursive lookups.) ], i know that in BIND we can change the config for this option apears changed but the resursion is active the same.

How can we do this in MyDNS ?

till
14th November 2007, 10:58
Comment out the line:

recursive = 127.0.0.1

in mydns.conf and restart mydns.

attadaved
20th April 2008, 09:40
Try www.dnsenquiry.com as a dnsstuff replacement

aamir_usaf
22nd June 2008, 17:45
thanx alot

aamir_usaf
22nd June 2008, 17:46
........................sorry