[71174] in North American Network Operators' Group

home help back first fref pref prev next nref lref last post

Urgent help needed with SORBS

daemon@ATHENA.MIT.EDU (Michael Tokarev)
Thu Jun 10 13:59:45 2004

Date: Thu, 10 Jun 2004 21:56:32 +0400
From: Michael Tokarev <mjt@tls.msk.ru>
Reply-To: mjt@tls.msk.ru
To: nanog@merit.edu
Errors-To: owner-nanog-outgoing@merit.edu


This may be somewhat off-topic here, but still..

Today at about 00:00 UTC, one of SORBS official
nameservers somehow got a corrupt datafile, and
started spreading incorrect information.  The
problem had gone at next reload or next data
transfer (which was after about 20 minutes),
but some caches got corrupt data.  We need to
identify the "bad" nameserver, but so far was
unable to do so.

If you're running BIND8 caches (note bind8,
bind9 won't not help), and are expiriencing
problems resolving dnsbl.sorbs.net zone, please,
perform a nameserver dump (by sending SIGINT
to the named process) and find the origin of
NS records for dnsbl.sorbs.net.

Problematic data is like this:

dnsbl.sorbs.NET.	119671	NS	\@.
			119671	NS	safe.
			119671	NS	socks.
			119671	NS	ip4set.
			119671	NS	relays.
			119671	NS	proxies.
			119671	NS	sDATASET.

(as of why this happened, -- that's another
topic, I have only one guess - two processes
writing into the same file at the same time,
which may, in theory, have this effect, -- but
in order to be able to check this, we need to
determine which nameserver performed badly).

Thank you.

/mjt

P.S. Reply-To set to prevent filling NANOG with
somewhat offtopic posts...

home help back first fref pref prev next nref lref last post