Sponsored Content
Top Forums UNIX for Advanced & Expert Users udp sockets of dns requests not showing anywhere... Post 302257195 by angeloio on Tuesday 11th of November 2008 03:34:27 PM
Old 11-11-2008
udp sockets of dns requests not showing anywhere...

Dear guys,

I am facing the most weird problem I have ever encountered!
Ok here is the situation:
From my dns query.log file - it is generated using usual bind9 logging:
logging {
channel query.log {
file "/var/log/bind9/query.log" versions 10 size 2m;
severity debug 2;
print-time yes;
};

category queries { query.log; };
};

I get many requests from localhost (like the following):
11-Nov-2008 12:27:01.010 client 127.0.0.1#45976: query: cyberfortress.com IN AAAA +
11-Nov-2008 12:27:01.010 client 127.0.0.1#57628: query: cyberfortress.com.smart-vision.eu IN AAAA +
11-Nov-2008 12:27:01.011 client 127.0.0.1#39766: query: cyberfortress.com IN A +
11-Nov-2008 12:27:01.055 client 127.0.0.1#58181: query: a094.server.lu IN A +

(domain cyberfortress.com is hosted on the same machine).
I tried to find where these requests are coming from. So using tcpdump:
Code:
tcpdump -vvv -n -i lo src host 127.0.0.1 and dst port 53

I get many packets:
21:25:02.000103 IP (tos 0x0, ttl 64, id 41188, offset 0, flags [DF], proto: UDP (17), length: 63) 127.0.0.1.54038 > 127.0.0.1.53: [bad udp cksum 400e!] 58884+ AAAA? cyberfortress.com. (35)
21:25:02.000412 IP (tos 0x0, ttl 64, id 41188, offset 0, flags [DF], proto: UDP (17), length: 79) 127.0.0.1.54188 > 127.0.0.1.53: [bad udp cksum 3a21!] 4651+ AAAA? cyberfortress.com.smart-vision.eu. (51)
21:25:02.000542 IP (tos 0x0, ttl 64, id 41188, offset 0, flags [DF], proto: UDP (17), length: 63) 127.0.0.1.56204 > 127.0.0.1.53: [bad udp cksum def1!] 5360+ A? cyberfortress.com. (35)


The actual question is which processes are sending these packets.
I tried using lsof, netstat, fuser even a perl program called socklist.pl, which I modified to print only udp sockets and run into a while (1) loop but the above sockets (54038, 54188, 56204 etc...) cannot be seen anywhere !!! [Could it be because they are so short-lived ???]
I am running a grsec-enabled 2.6 kernel in a debian etch system.

Do you have any ideas what is happening and how to pinpoint there processes that generate these packets ???

It is very important for me. I could possible give some money to a really good solution.

Thanks to all for your time
 

10 More Discussions You Might Find Interesting

1. IP Networking

UDP sockets

hi... i have made this client server prog with UDP sockets but im not getting the output. the client sends the message but the server just keeps on waiting. Im running the prog an a solaris 10 box... server: main() { int sd; struct sockaddr_in server; char buf; int rc,len; ... (2 Replies)
Discussion started by: strider
2 Replies

2. Solaris

Solaris DNS Client For Microsoft DNS Server

hey guys, how to add soalris box as a microsoft DNS Client ? and how to register in the microsoft DNS ?? i managed to query from the DNS server after adding /etc/resolve.conf and editing /etc/nsswitch.conf but i need to register the soalris server (dns Client) into Microsoft DNS automatically.... (3 Replies)
Discussion started by: mduweik
3 Replies

3. UNIX for Advanced & Expert Users

DNS server choice: Windows DNS vs Linux BIND

I'd like to get some opnions on choosing DNS server: Windows DNS vs Linux BIND comparrsion: 1) managment, easy of use 2) Security 3) features 4) peformance 5) ?? I personally prefer Windows DNS server for management, it supports GUI and command line. But I am not sure about security... (2 Replies)
Discussion started by: honglus
2 Replies

4. Programming

Accept (sockets) queuing up connection requests

Yes, I guess that is what it is sort of meant to do but it is sort of a problem. Scenario: Server is running and is blocked at ACCEPT Client A connects with server Server returns from ACCEPT and moves to RECV call waiting for incoming string Client... (4 Replies)
Discussion started by: Kam5FCC
4 Replies

5. Red Hat

DNS A-Record point to another DNS

Hi, I have a question on how to point the DNS server-1's A-record to second DNS server, which is DNS server-2. So, the computer can access other domain which only listed in the DNS server-2. The scenario is as follow: http://img689.imageshack.us/img689/6333/12234.png How to configure this... (4 Replies)
Discussion started by: Paris Heng
4 Replies

6. HP-UX

Some I/O requests to this LV are waiting

Hi All I have a blade BL860c running on a C7000 chassis, in which is connected to a NetApp, so lately I am having I/O issues, and dmesg as well as syslog.log is reporting the following: /dev/vg01/lvol2 file system file data error in dev/block 0/55892768 Page I/O error occurred while paging... (2 Replies)
Discussion started by: fretagi
2 Replies

7. Red Hat

DHCP & DNS - Clients get IP but don't register in DNS

I am trying to setup a CentOS 6.2 server that will be doing 3 things DHCP, DNS & Samba for a very small office (2 users). The idea being this will replace a very old Win2k server. The users are all windows based clients so only the server will be Linux based. I've installed CentOS 6.2 with... (4 Replies)
Discussion started by: FireBIade
4 Replies

8. IP Networking

DNS requests through SSH/443

Anybody know how to force all DNS requests through port 443 or an SSH tunnel such as Putty in Ubuntu 10.4? (2 Replies)
Discussion started by: 3therk1ll
2 Replies

9. Solaris

Identify process sending ldap requests to old DNS server

Hi, I have a Solaris 10 system, which appears to be sending out LDAP queries to a server that is due to be decomissioned. Is there a way to identify which process is sending out these queries? The problem is that the local port constantly changes, and the connections do not stay open long... (3 Replies)
Discussion started by: badoshi
3 Replies

10. Solaris

DNS client added to DNS server but not working

Hi, We have built a new server (RHEL VM)and added that IP/hostname into dns zone configs file on DNS server (Solaris 10). Reloaded the configuration using and added nameserver into resolv.conf on client. But when I am trying nslookup, its not getting resolved. The nameserver is not able to... (8 Replies)
Discussion started by: snchaudhari2
8 Replies
dns(n)								Domain Name Service							    dns(n)

__________________________________________________________________________________________________________________________________________________

NAME
dns - Tcl Domain Name Service Client SYNOPSIS
package require Tcl 8.2 package require dns ?1.3.3? ::dns::resolve query ?options? ::dns::configure ?options? ::dns::name token ::dns::address token ::dns::cname token ::dns::result token ::dns::status token ::dns::error token ::dns::reset token ::dns::wait token ::dns::cleanup token ::dns::nameservers _________________________________________________________________ DESCRIPTION
The dns package provides a Tcl only Domain Name Service client. You should refer to (1) and (2) for information about the DNS protocol or read resolver(3) to find out how the C library resolves domain names. The intention of this package is to insulate Tcl scripts from prob- lems with using the system library resolver for slow name servers. It may or may not be of practical use. Internet name resolution is a complex business and DNS is only one part of the resolver. You may find you are supposed to be using hosts files, NIS or WINS to name a few other systems. This package is not a substitute for the C library resolver - it does however implement name resolution over DNS. The pack- age also extends the package uri to support DNS URIs (4) of the form dns:what.host.com or dns://my.nameserver/what.host.com. The dns::resolve command can handle DNS URIs or simple domain names as a query. Note: The package defaults to using DNS over TCP connections. If you wish to use UDP you will need to have the tcludp package installed and have a version that correctly handles binary data (> 1.0.4). This is available at http://tcludp.sourceforge.net/. If the udp package is present then UDP will be used by default. COMMANDS
::dns::resolve query ?options? Resolve a domain name using the DNS protocol. query is the domain name to be lookup up. This should be either a fully qualified domain name or a DNS URI. -nameserver hostname or -server hostname Specify an alternative name server for this request. -protocol tcp|udp Specify the network protocol to use for this request. Can be one of tcp or udp. -port portnum Specify an alternative port. -search domainlist -timeout milliseconds Override the default timeout. -type TYPE Specify the type of DNS record you are interested in. Valid values are A, NS, MD, MF, CNAME, SOA, MB, MG, MR, NULL, WKS, PTR, HINFO, MINFO, MX, TXT, SPF, SRV, AAAA, AXFR, MAILB, MAILA and *. See RFC1035 for details about the return values. See http://spf.pobox.com/ about SPF. See (3) about AAAA records and RFC2782 for details of SRV records. -class CLASS Specify the class of domain name. This is usually IN but may be one of IN for internet domain names, CS, CH, HS or * for any class. -recurse boolean Set to false if you do not want the name server to recursively act upon your request. Normally set to true. -command procname Set a procedure to be called upon request completion. The procedure will be passed the token as its only argument. ::dns::configure ?options? The ::dns::configure command is used to setup the dns package. The server to query, the protocol and domain search path are all set via this command. If no arguments are provided then a list of all the current settings is returned. If only one argument then it must the the name of an option and the value for that option is returned. -nameserver hostname Set the default name server to be used by all queries. The default is localhost. -protocol tcp|udp Set the default network protocol to be used. Default is tcp. -port portnum Set the default port to use on the name server. The default is 53. -search domainlist Set the domain search list. This is currently not used. -timeout milliseconds Set the default timeout value for DNS lookups. Default is 30 seconds. -loglevel level Set the log level used for emitting diagnostic messages from this package. The default is warn. See the log package for details of the available levels. ::dns::name token Returns a list of all domain names returned as an answer to your query. ::dns::address token Returns a list of the address records that match your query. ::dns::cname token Returns a list of canonical names (usually just one) matching your query. ::dns::result token Returns a list of all the decoded answer records provided for your query. This permits you to extract the result for more unusual query types. ::dns::status token Returns the status flag. For a successfully completed query this will be ok. May be error or timeout or eof. See also ::dns::error ::dns::error token Returns the error message provided for requests whose status is error. If there is no error message then an empty string is returned. ::dns::reset token Reset or cancel a DNS query. ::dns::wait token Wait for a DNS query to complete and return the status upon completion. ::dns::cleanup token Remove all state variables associated with the request. ::dns::nameservers Attempts to return a list of the nameservers currently configured for the users system. On a unix machine this parses the /etc/resolv.conf file for nameservers (if it exists) and on Windows systems we examine certain parts of the registry. If no name- server can be found then the loopback address (127.0.0.1) is used as a default. EXAMPLES
% set tok [dns::resolve www.tcl.tk] ::dns::1 % dns::status $tok ok % dns::address $tok 199.175.6.239 % dns::name $tok www.tcl.tk % dns::cleanup $tok Using DNS URIs as queries: % set tok [dns::resolve "dns:tcl.tk;type=MX"] % set tok [dns::resolve "dns://l.root-servers.net/www.tcl.tk"] Reverse address lookup: % set tok [dns::resolve 127.0.0.1] ::dns::1 % dns::name $tok localhost % dns::cleanup $tok REFERENCES
[1] Mockapetris, P., "Domain Names - Concepts and Facilities", RFC 1034, November 1987. (http://www.ietf.org/rfc/rfc1034.txt) [2] Mockapetris, P., "Domain Names - Implementation and Specification", RFC 1035, November 1087. (http://www.ietf.org/rfc/rfc1035.txt) [3] Thompson, S. and Huitema, C., "DNS Extensions to support IP version 6", RFC 1886, December 1995. (http://www.ietf.org/rfc/rfc1886.txt) [4] Josefsson, S., "Domain Name System Uniform Resource Identifiers", Internet-Draft, October 2003, (http://www.ietf.org/internet- drafts/draft-josefsson-dns-url-09.txt) [5] Gulbrandsen, A., Vixie, P. and Esibov, L., "A DNS RR for specifying the location of services (DNS SRV)", RFC 2782, February 2000, (http://www.ietf.org/rfc/rfc2782.txt) [6] Ohta, M. "Incremental Zone Transfer in DNS", RFC 1995, August 1996, (http://www.ietf.org/rfc/rfc1995.txt) AUTHORS
Pat Thoyts BUGS, IDEAS, FEEDBACK This document, and the package it describes, will undoubtedly contain bugs and other problems. Please report such in the category dns of the Tcllib SF Trackers [http://sourceforge.net/tracker/?group_id=12883]. Please also report any ideas for enhancements you may have for either package and/or documentation. SEE ALSO
resolver(5) KEYWORDS
DNS, domain name service, resolver, rfc 1034, rfc 1035, rfc 1886 COPYRIGHT
Copyright (c) 2002, Pat Thoyts dns 1.3.3 dns(n)
All times are GMT -4. The time now is 11:22 AM.
Unix & Linux Forums Content Copyright 1993-2022. All Rights Reserved.
Privacy Policy