Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations gkittelson on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

Problems with dns. [A hack?]

Status
Not open for further replies.

Praetor2000

Programmer
Aug 4, 2003
7
RU
Hi!
Some time ago there was a hack into my network. I don't know, what was done (except: changed permissions on /usr and /etc to 777 !), but now my dns doesn't work. I checked all the configs on my server - they haven't been changed. The guys who provide secondary dns also say they're ok with it. But the fact is: all remote requests to my domain name result in the obvious "dns error: unable to resolve name...". So, neither my http page or the email work. (Apache and Sendmail configs are also untouched).
I've got Altlinux Master on my server.
What can the problem be?

ps: here's an extraction from the log, when the attack took place:

Feb 3 11:36:46 iemrams portmap[12469]: connect from 211.53.213.144 to getport(status): request from unauthorized host
Feb 3 11:37:46 iemrams portmap[12500]: connect from 211.53.213.144 to getport(status): request from unauthorized host
Feb 3 11:38:46 iemrams portmap[12531]: connect from 211.53.213.144 to getport(status): request from unauthorized host
Feb 3 11:39:46 iemrams portmap[12562]: connect from 211.53.213.144 to getport(status): request from unauthorized host
Feb 3 11:40:46 iemrams portmap[12595]: connect from 211.53.213.144 to getport(status): request from unauthorized host
Feb 3 11:41:39 iemrams init: Switching to runlevel: 6
Feb 3 11:41:46 iemrams portmap[12652]: connect from 211.53.213.144 to getport(status): request from unauthorized host


Regards,
Praetor Mortis King
Leading programmer
Wanamingo Mine inc.
Dominican Republic
 
Do you have anything in the event logs showing errors or problems? What do you get with the basics? From a different machine, do a tracert to the problems server and see where it dies out. Good luck.

Glen A. Johnson
"Give the laziest man the hardest job and he'll find the easiest way to do it."

Want to get great answers to your Tek-Tips questions? Have a look at FAQ219-2884
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top