<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>dns | /var/logs/paulooi.log</title>
	<atom:link href="https://logs.paulooi.com/tag/dns/feed" rel="self" type="application/rss+xml" />
	<link>https://logs.paulooi.com</link>
	<description>Systems Admin, Web Development and etc</description>
	<lastBuildDate>Fri, 19 Mar 2021 09:54:59 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	
	<item>
		<title>Twitter, NYTimes and Huff Po Whois and DNS records altered, Syrian Electronic Army takes responsibility</title>
		<link>https://logs.paulooi.com/twitter-nytimes-and-huff-po-whois-and-dns-records-altered-syrian-electronic-army-takes-responsibility.php</link>
					<comments>https://logs.paulooi.com/twitter-nytimes-and-huff-po-whois-and-dns-records-altered-syrian-electronic-army-takes-responsibility.php#respond</comments>
		
		<dc:creator><![CDATA[Paul Ooi]]></dc:creator>
		<pubDate>Wed, 28 Aug 2013 02:34:19 +0000</pubDate>
				<category><![CDATA[lost+found]]></category>
		<category><![CDATA[Systems]]></category>
		<category><![CDATA[dns]]></category>
		<category><![CDATA[NYTimes]]></category>
		<category><![CDATA[twitter]]></category>
		<guid isPermaLink="false">http://systems.takizo.com/?p=1590</guid>

					<description><![CDATA[<p>At approximately 3pm PST, the Syrian Electronic Army seemingly hacked into Twitter, Huffington Post and NY Times’ registry accounts altering contact details, and more significantly, DNS records. Modifying DNS records of a domain will allow SEA to redirect visitors to...</p>
The post <a href="https://logs.paulooi.com/twitter-nytimes-and-huff-po-whois-and-dns-records-altered-syrian-electronic-army-takes-responsibility.php">Twitter, NYTimes and Huff Po Whois and DNS records altered, Syrian Electronic Army takes responsibility</a> first appeared on <a href="https://logs.paulooi.com">/var/logs/paulooi.log</a>.]]></description>
										<content:encoded><![CDATA[<p><a href="https://logs.paulooi.com/wp-content/uploads/2013/08/twitter-dns-changed.png"><img fetchpriority="high" decoding="async" src="https://logs.paulooi.com/wp-content/uploads/2013/08/twitter-dns-changed-285x300.png" alt="twitter-dns-changed" width="285" height="300" class="aligncenter size-medium wp-image-1591" srcset="https://logs.paulooi.com/wp-content/uploads/2013/08/twitter-dns-changed-285x300.png 285w, https://logs.paulooi.com/wp-content/uploads/2013/08/twitter-dns-changed.png 662w" sizes="(max-width: 285px) 100vw, 285px" /></a></p>
<p>At approximately 3pm PST, the Syrian Electronic Army seemingly hacked into Twitter, Huffington Post and NY Times’ registry accounts altering contact details, and more significantly, DNS records. Modifying DNS records of a domain will allow SEA to redirect visitors to any site of their choosing.</p>
<p>Contact details for the Twitter.com domain were changed, but it’s reasonable to assume that if the SEA had the ability to change contact information, they may very well have had the ability to change DNS records and point the Twitter.com domain elsewhere, redirecting visitors and users.</p>
<p>The SEA also altered the DNS records for twimg.com which Twitter uses for virtually all CSS, JS, images, cookies and more. This means for many users, Twitter.com wouldn’t load correctly and avatars were unavailable across many Twitter clients.</p>
<p>[Story via <a href="http://j.mp/19LTeCj" target="_blank">TNW</a>]</p>The post <a href="https://logs.paulooi.com/twitter-nytimes-and-huff-po-whois-and-dns-records-altered-syrian-electronic-army-takes-responsibility.php">Twitter, NYTimes and Huff Po Whois and DNS records altered, Syrian Electronic Army takes responsibility</a> first appeared on <a href="https://logs.paulooi.com">/var/logs/paulooi.log</a>.]]></content:encoded>
					
					<wfw:commentRss>https://logs.paulooi.com/twitter-nytimes-and-huff-po-whois-and-dns-records-altered-syrian-electronic-army-takes-responsibility.php/feed</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>How to Enable check_dns on Nagios Monitoring System</title>
		<link>https://logs.paulooi.com/how-to-enable-check_dns-on-nagios-monitoring-system.php</link>
					<comments>https://logs.paulooi.com/how-to-enable-check_dns-on-nagios-monitoring-system.php#comments</comments>
		
		<dc:creator><![CDATA[Paul Ooi]]></dc:creator>
		<pubDate>Fri, 25 Feb 2011 15:14:12 +0000</pubDate>
				<category><![CDATA[Application]]></category>
		<category><![CDATA[Systems]]></category>
		<category><![CDATA[dns]]></category>
		<category><![CDATA[dns monitoring]]></category>
		<category><![CDATA[monitor dns]]></category>
		<category><![CDATA[nagios]]></category>
		<guid isPermaLink="false">http://systems.takizo.com/?p=1401</guid>

					<description><![CDATA[<p>Most user who are new to Nagios doesn&#8217;t know there is a hidden plug-in called check_dns in Nagios Monitoring system. On FreeBSD server, the binary can be found at /usr/local/libexec/nagios. List the directory and you should see check_dns. check_dns usage...</p>
The post <a href="https://logs.paulooi.com/how-to-enable-check_dns-on-nagios-monitoring-system.php">How to Enable check_dns on Nagios Monitoring System</a> first appeared on <a href="https://logs.paulooi.com">/var/logs/paulooi.log</a>.]]></description>
										<content:encoded><![CDATA[<p><a href="https://logs.paulooi.com/wp-content/uploads/2011/02/nagios-logo.gif"><img decoding="async" class="alignleft size-full wp-image-1402" title="nagios-logo" src="https://logs.paulooi.com/wp-content/uploads/2011/02/nagios-logo.gif" alt="" width="64" height="64" /></a>Most user who are new to Nagios doesn&#8217;t know there is a hidden plug-in called check_dns in Nagios Monitoring system. On FreeBSD server, the binary can be found at <em>/usr/local/libexec/nagios</em>. List the directory and you should see check_dns.</p>
<p>check_dns usage is as below</p>
<pre><code>
$ ./check_dns -H host [-s server] [-a expected-address] [-A] [-t timeout] [-w warn] [-c crit]
</code></pre>
<p>Try to run the command as below and you will get the query result</p>
<pre><code>
$ ./check_dns -H systems.takizo.com -s 8.8.8.8        
DNS OK: 0.012 seconds response time. systems.takizo.com returns 70.32.103.130|time=0.011703s;;;0.000000
</code></pre>
<p><span id="more-1401"></span><br />
Sweet, that is the DNS query plugin, it does DNS query check on your DNS host server and return the query time.<br />
Here is how to activate the monitoring, add the check_dns plug-in into Nagios&#8217; commands.cfg configuration file.</p>
<p>On FreeBSD server, it&#8217;s located at /usr/local/etc/nagios/objects/commands.cfg<br />
Edit the file commands.cfg and add the line below</p>
<pre><code>
define command {
        command_name    check_dns
        command_line    $USER1$/check_dns -H $HOSTADDRESS$ -s $ARG1$
}
</code></pre>
<ul>
<li>$ARG1$ is the argument you will parse into in the configuration</li>
<li>$HOSTADDRESS$ is your host on Nagios monitoring.</li>
</ul>
<p>Next, put the line below into service check configuration file</p>
<pre><code>
define service {
        use                                  generic-service
        host_name                       your-dns-host
        service_description          Check Google.com on DNS Server
        check_command              check_dns!www.google.com
}
</code></pre>
<p>Restart your Nagios service now</p>
<pre><code>
$ /usr/local/etc/rc.d/nagios restart
</code></pre>
<p>If it&#8217;s failed, you will the red color on the monitoring status. There are a lot other plug-ins can be explore too. Have fun.</p>The post <a href="https://logs.paulooi.com/how-to-enable-check_dns-on-nagios-monitoring-system.php">How to Enable check_dns on Nagios Monitoring System</a> first appeared on <a href="https://logs.paulooi.com">/var/logs/paulooi.log</a>.]]></content:encoded>
					
					<wfw:commentRss>https://logs.paulooi.com/how-to-enable-check_dns-on-nagios-monitoring-system.php/feed</wfw:commentRss>
			<slash:comments>4</slash:comments>
		
		
			</item>
		<item>
		<title>Free eBook: Alternative DNS Servers</title>
		<link>https://logs.paulooi.com/free-ebook-alternative-dns-servers.php</link>
					<comments>https://logs.paulooi.com/free-ebook-alternative-dns-servers.php#respond</comments>
		
		<dc:creator><![CDATA[Paul Ooi]]></dc:creator>
		<pubDate>Fri, 25 Feb 2011 13:32:36 +0000</pubDate>
				<category><![CDATA[Application]]></category>
		<category><![CDATA[Systems]]></category>
		<category><![CDATA[bind]]></category>
		<category><![CDATA[bind dlz]]></category>
		<category><![CDATA[bind ldap]]></category>
		<category><![CDATA[dns]]></category>
		<category><![CDATA[dns server]]></category>
		<category><![CDATA[ldap dns]]></category>
		<category><![CDATA[power dns]]></category>
		<guid isPermaLink="false">http://systems.takizo.com/?p=1394</guid>

					<description><![CDATA[<p>Grab this 747 pages DNS eBook for Free; Written by Jan-Piet Mens, titled &#8220;Alternative DNS Servers&#8221;. I glance through at the eBook and found several interesting topics for DNS deployments. Bind DLZ &#8211; The Bind extension which can store your...</p>
The post <a href="https://logs.paulooi.com/free-ebook-alternative-dns-servers.php">Free eBook: Alternative DNS Servers</a> first appeared on <a href="https://logs.paulooi.com">/var/logs/paulooi.log</a>.]]></description>
										<content:encoded><![CDATA[<p><a href="https://logs.paulooi.com/wp-content/uploads/2011/02/20081027.exact-size.front_.jpg"><img decoding="async" src="https://logs.paulooi.com/wp-content/uploads/2011/02/20081027.exact-size.front_-150x150.jpg" alt="" title="20081027.exact-size.front" width="150" height="150" class="alignleft size-thumbnail wp-image-1395" /></a> Grab this 747 pages DNS eBook for Free; Written by Jan-Piet Mens, titled &#8220;Alternative DNS Servers&#8221;. I glance through at the eBook and found several interesting topics for DNS deployments.</p>
<ul>
<li>Bind DLZ &#8211; The Bind extension which can store your data in database MySQL, PostgreSQL and etc.</li>
<li>NSD &#8211; A lot people didn&#8217;t know about Name Server Daemon, find out more from the eBook.</li>
<li>DNS Planning &#8211; Name Server deployment planning, capacity planning and how to scale.</li>
<li>PowerDNS &#8211; Configure and master it.</li>
<li>LDAP DNS &#8211; Deploy DNS server with LDAP.</li>
</ul>
<p>Alright, enough with the talks, where to download the eBook? It&#8217;s <a href="http://blog.fupps.com/2010/10/29/alternative-dns-servers-the-book-as-pdf/?ref=systems.takizo.com" target="_blank">FREE for Download here</a></p>The post <a href="https://logs.paulooi.com/free-ebook-alternative-dns-servers.php">Free eBook: Alternative DNS Servers</a> first appeared on <a href="https://logs.paulooi.com">/var/logs/paulooi.log</a>.]]></content:encoded>
					
					<wfw:commentRss>https://logs.paulooi.com/free-ebook-alternative-dns-servers.php/feed</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>Reverse DNS Lookup with Dig</title>
		<link>https://logs.paulooi.com/reverse-dns-lookup-with-dig.php</link>
					<comments>https://logs.paulooi.com/reverse-dns-lookup-with-dig.php#respond</comments>
		
		<dc:creator><![CDATA[Paul Ooi]]></dc:creator>
		<pubDate>Sat, 22 Jan 2011 11:51:28 +0000</pubDate>
				<category><![CDATA[Systems]]></category>
		<category><![CDATA[dns]]></category>
		<category><![CDATA[dns server]]></category>
		<category><![CDATA[freebsd]]></category>
		<category><![CDATA[ip address]]></category>
		<category><![CDATA[reverse dns]]></category>
		<guid isPermaLink="false">http://systems.takizo.com/?p=1127</guid>

					<description><![CDATA[<p>Reverse DNS, in simple explanation it means that resolve your IP address into hostname. Nowaday it became a must have requirement for mail server&#8217;s IP address. It is also one of the method to determine your mail server IP is...</p>
The post <a href="https://logs.paulooi.com/reverse-dns-lookup-with-dig.php">Reverse DNS Lookup with Dig</a> first appeared on <a href="https://logs.paulooi.com">/var/logs/paulooi.log</a>.]]></description>
										<content:encoded><![CDATA[<p>Reverse DNS, in simple explanation it means that resolve your IP address into hostname. Nowaday it became a must have requirement for mail server&#8217;s IP address. It is also one of the method to determine your mail server IP is glue to the hostname. </p>
<p>Here is how to find out the reverse DNS IP address is pointed to which DNS server for zone delegation.</p>
<pre>
<code>
dig -x 175.136.188.90

; <<>> DiG 9.6.0-APPLE-P2 <<>> -x 175.136.188.90
;; global options: +cmd
;; Got answer:
;; ->>HEADER<<- opcode: QUERY, status: NXDOMAIN, id: 21938
;; flags: qr rd ra; QUERY: 1, ANSWER: 0, AUTHORITY: 1, ADDITIONAL: 0

;; QUESTION SECTION:
;90.188.136.175.in-addr.arpa.   IN      PTR

;; AUTHORITY SECTION:
136.175.in-addr.arpa.   10800   IN      SOA     ns1.tm.net.my. dnsadm.tmnet.com.my. 2011012113 10800 3600 604800 86400

;; Query time: 37 msec
;; SERVER: 192.168.0.1#53(192.168.0.1)
;; WHEN: Sat Jan 22 19:39:12 2011
;; MSG SIZE  rcvd: 111
</pre>
<p></code></p>
<p>The result above shown </p>
<ul>
<li>The SOA record shown the IP Address is pointed to ns1.tm.net.my for reverse DNS delegation.</li>
<li>The zone 136.175.in-addr.arpa is delegating the IP 175.136.188.90</li>
</ul>
<p>This command is pretty useful when you want to find out is the reverse DNS delegation works correctly. </p>The post <a href="https://logs.paulooi.com/reverse-dns-lookup-with-dig.php">Reverse DNS Lookup with Dig</a> first appeared on <a href="https://logs.paulooi.com">/var/logs/paulooi.log</a>.]]></content:encoded>
					
					<wfw:commentRss>https://logs.paulooi.com/reverse-dns-lookup-with-dig.php/feed</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>Bind Error: &#8220;max open files (3520) is smaller than max sockets (4096)&#8221;</title>
		<link>https://logs.paulooi.com/bind-error-max-open-files-3520-is-smaller-than-max-sockets-4096.php</link>
					<comments>https://logs.paulooi.com/bind-error-max-open-files-3520-is-smaller-than-max-sockets-4096.php#comments</comments>
		
		<dc:creator><![CDATA[Paul Ooi]]></dc:creator>
		<pubDate>Mon, 28 Jun 2010 08:34:30 +0000</pubDate>
				<category><![CDATA[Systems]]></category>
		<category><![CDATA[bind]]></category>
		<category><![CDATA[dns]]></category>
		<category><![CDATA[freebsd]]></category>
		<category><![CDATA[kernel]]></category>
		<category><![CDATA[sysctl]]></category>
		<guid isPermaLink="false">http://systems.takizo.com/?p=1002</guid>

					<description><![CDATA[<p>Just notice one of the DNS server has the error message 28-Jun-2010 16:28:24.283 general: max open files (3520) is smaller than max sockets (4096) It&#8217;s something to do with kernel setting, on FreeBSD, configure the following shell> sysctl kern.maxfiles=4096 shell>...</p>
The post <a href="https://logs.paulooi.com/bind-error-max-open-files-3520-is-smaller-than-max-sockets-4096.php">Bind Error: “max open files (3520) is smaller than max sockets (4096)”</a> first appeared on <a href="https://logs.paulooi.com">/var/logs/paulooi.log</a>.]]></description>
										<content:encoded><![CDATA[<p>Just notice one of the DNS server has the error message</p>
<pre>
<code>
28-Jun-2010 16:28:24.283 general: max open files (3520) is smaller than max sockets (4096)
</code>
</pre>
<p>It&#8217;s something to do with kernel setting, on FreeBSD, configure the following</p>
<pre>
<code>
shell> sysctl kern.maxfiles=4096  
shell> sysctl kern.maxfilesperproc=4096
</code>
</pre>
<p>Alternatively, put the above configuration on /etc/sysctl.conf in order to configure it at start up level. </p>The post <a href="https://logs.paulooi.com/bind-error-max-open-files-3520-is-smaller-than-max-sockets-4096.php">Bind Error: “max open files (3520) is smaller than max sockets (4096)”</a> first appeared on <a href="https://logs.paulooi.com">/var/logs/paulooi.log</a>.]]></content:encoded>
					
					<wfw:commentRss>https://logs.paulooi.com/bind-error-max-open-files-3520-is-smaller-than-max-sockets-4096.php/feed</wfw:commentRss>
			<slash:comments>1</slash:comments>
		
		
			</item>
		<item>
		<title>Turn on DNS Query Log on Bind</title>
		<link>https://logs.paulooi.com/turn-on-dns-query-log-on-bind.php</link>
					<comments>https://logs.paulooi.com/turn-on-dns-query-log-on-bind.php#comments</comments>
		
		<dc:creator><![CDATA[Paul Ooi]]></dc:creator>
		<pubDate>Wed, 12 May 2010 13:28:50 +0000</pubDate>
				<category><![CDATA[Systems]]></category>
		<category><![CDATA[bind]]></category>
		<category><![CDATA[dns]]></category>
		<category><![CDATA[logging]]></category>
		<guid isPermaLink="false">http://systems.takizo.com/?p=968</guid>

					<description><![CDATA[<p>You are running a recursive DNS server and would like to find out the statistic of your user browser behavior (Whether they browse Facebook or Google?). Turn on DNS query logs will allow you to find out the statistic. To...</p>
The post <a href="https://logs.paulooi.com/turn-on-dns-query-log-on-bind.php">Turn on DNS Query Log on Bind</a> first appeared on <a href="https://logs.paulooi.com">/var/logs/paulooi.log</a>.]]></description>
										<content:encoded><![CDATA[<p>You are running a recursive DNS server and would like to find out the statistic of your user browser behavior (Whether they browse Facebook or Google?). Turn on DNS query logs will allow you to find out the statistic. To turn on DNS query log in Bind, configure lines below on named.conf </p>
<pre>
<code>
logging{
        channel query_logging {
                file "/var/log/query.log" versions 3 size 10m;
                severity debug 3;
                print-time yes;
                print-severity yes;
                print-category yes;
        };

        category queries {
                query_logging;
        };
};
</code>
</pre>
<p>To turn on query logging while DNS service is running; you need to to <strong>rndc querylog</strong> and check the status with <strong>rndc status</strong></p>
<pre>
<code>
shell> rndc querylog
shell> rndc status 
version: 9.x.x
number of zones: 1200
debug level: 3
xfers running: 0
xfers deferred: 0
soa queries in progress: 0
query logging is ON
recursive clients: 0/0/1000
tcp clients: 0/100
server is up and running
</code>
</pre>
<p><strong>query logging is ON</strong> indicates that DNS query logging is activated. </p>The post <a href="https://logs.paulooi.com/turn-on-dns-query-log-on-bind.php">Turn on DNS Query Log on Bind</a> first appeared on <a href="https://logs.paulooi.com">/var/logs/paulooi.log</a>.]]></content:encoded>
					
					<wfw:commentRss>https://logs.paulooi.com/turn-on-dns-query-log-on-bind.php/feed</wfw:commentRss>
			<slash:comments>1</slash:comments>
		
		
			</item>
		<item>
		<title>How to do DNS Setup On your Machine</title>
		<link>https://logs.paulooi.com/how-to-do-dns-setup-on-your-machine.php</link>
					<comments>https://logs.paulooi.com/how-to-do-dns-setup-on-your-machine.php#respond</comments>
		
		<dc:creator><![CDATA[Paul Ooi]]></dc:creator>
		<pubDate>Fri, 07 May 2010 06:30:10 +0000</pubDate>
				<category><![CDATA[Systems]]></category>
		<category><![CDATA[dns]]></category>
		<category><![CDATA[dns setup]]></category>
		<guid isPermaLink="false">http://systems.takizo.com/?p=961</guid>

					<description><![CDATA[<p>Most of us know, without DNS Setup on your machine or PC, you can&#8217;t browse on the website at all, DNS setup is a must, cause what DNS does is translate the Domain Name to IP Address in order to...</p>
The post <a href="https://logs.paulooi.com/how-to-do-dns-setup-on-your-machine.php">How to do DNS Setup On your Machine</a> first appeared on <a href="https://logs.paulooi.com">/var/logs/paulooi.log</a>.]]></description>
										<content:encoded><![CDATA[<p>Most of us know, without DNS Setup on your machine or PC, you can&#8217;t browse on the website at all, DNS setup is a must, cause what DNS does is translate the Domain Name to IP Address in order to reach the server. </p>
<p>What DNS Server to use? We will use OpenDNS server for DNS Setup. </p>
<p><strong>DNS Setup on Windows Vista</strong></p>
<p>On your Windows Vista, follow the step below;</p>
<ul>
<li>Click on &#8220;Windows Start Button&#8221;, then select &#8220;Control Panel&#8221;. </li>
<li>Click on &#8220;Network and Internet&#8221;</li>
<li>Click on &#8220;Network Center&#8221;</li>
<li>Click on &#8220;Personalize&#8221;, next to your network</li>
<li>Click on &#8220;Properties&#8221; button. </li>
<li>Another window will pop up &#8211; click on &#8220;Properties&#8221; button, again</li>
<li>Vista will ask for your permission to make changes. Click &#8220;Continue&#8221; button.<br />
Make sure you have administrative rights on your system before making changes.</li>
<li>Select &#8220;Internet Protocol Version 4 (TCP/IPv4)&#8221;, then click on &#8220;Properties&#8221; button. </li>
<li>Click the radio button &#8220;Use the following DNS server addresses&#8221; and type in OpenDNS addresses in the &#8220;Preferred DNS server&#8221; and &#8220;Alternate DNS server&#8221; fields. </li>
<p>Preferred DNS server address for Open DNS is: 208.67.222.222<br />
Alternate DNS server address for Open DNS is: 208.67.220.220 </p>
<li>Click on &#8220;OK&#8221; button. </li>
<li>Restart your computer. </li>
<p><strong>DNS Setup on Apple Mac OS X</strong></p>
<p>On Apple Mac, follow the steps below for DNS Setup;</p>
<li>Click on the Apple icon on top left menu</li>
<li>Select System Preferences</li>
<li>Click on Network</li>
<li>On DNS Server, type: 208.67.222.222, 208.67.220.220</li>
<li>Click on Apply. That&#8217;s all</li>
<p>DNS Setup is pretty easy, happy browsing!</p>The post <a href="https://logs.paulooi.com/how-to-do-dns-setup-on-your-machine.php">How to do DNS Setup On your Machine</a> first appeared on <a href="https://logs.paulooi.com">/var/logs/paulooi.log</a>.]]></content:encoded>
					
					<wfw:commentRss>https://logs.paulooi.com/how-to-do-dns-setup-on-your-machine.php/feed</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
	</channel>
</rss>
