[Author Prev][Author Next][Thread Prev][Thread Next][Author Index][Thread Index]

Norwegian DNS compromized



$ dig +trace alolita.com
alolita.com.            3600    IN      A       69.5.162.133

dig @217.13.4.21 alolita.com
alolita.com.            1800    IN      A       80.202.4.7

217.13.4.21 is a DNS server which belongs to Norwegian ISP NextGenTel.

** EVEN MORE ALARMING: ** 

$ dig @18.244.0.188 tor.eff.org

; <<>> DiG 9.3.3rc3 <<>> @18.244.0.188 tor.eff.org
; (1 server found)
;; global options:  printcmd
;; Got answer:
;; ->>HEADER<<- opcode: QUERY, status: NOERROR, id: 4867
;; flags: qr rd ra; QUERY: 1, ANSWER: 2, AUTHORITY: 7, ADDITIONAL: 7

;; QUESTION SECTION:
;tor.eff.org.                   IN      A

;; ANSWER SECTION:
tor.eff.org.            7191    IN      CNAME   alcatraz.eff.org.
alcatraz.eff.org.       7191    IN      A       209.237.230.67

;; AUTHORITY SECTION:
eff.org.                7191    IN      NS      ns01.eff.org.
eff.org.                7191    IN      NS      pdns1.ultradns.net.
eff.org.                7191    IN      NS      pdns2.ultradns.net.
eff.org.                7191    IN      NS      pdns3.ultradns.org.
eff.org.                7191    IN      NS      pdns4.ultradns.org.
eff.org.                7191    IN      NS      pdns5.ultradns.info.
eff.org.                7191    IN      NS      pdns6.ultradns.co.uk.

;; ADDITIONAL SECTION:
ns01.eff.org.           27408   IN      A       209.237.230.67
pdns1.ultradns.net.     104763  IN      A       204.74.108.1
pdns2.ultradns.net.     104767  IN      A       204.74.109.1
pdns3.ultradns.org.     20162   IN      A       199.7.68.1
pdns4.ultradns.org.     19897   IN      A       199.7.69.1
pdns5.ultradns.info.    19897   IN      A       204.74.114.1
pdns6.ultradns.co.uk.   29335   IN      A       204.74.115.1

;; Query time: 10 msec
;; SERVER: 18.244.0.188#53(18.244.0.188)
;; WHEN: Tue Feb 27 08:50:03 2007
;; MSG SIZE  rcvd: 367

$  dig @217.13.4.21 tor.eff.org

; <<>> DiG 9.3.3rc3 <<>> @217.13.4.21 tor.eff.org
; (1 server found)
;; global options:  printcmd
;; Got answer:
;; ->>HEADER<<- opcode: QUERY, status: NOERROR, id: 18773
;; flags: qr rd; QUERY: 1, ANSWER: 0, AUTHORITY: 7, ADDITIONAL: 6

;; QUESTION SECTION:
;tor.eff.org.                   IN      A

;; AUTHORITY SECTION:
eff.org.                5771    IN      NS      pdns3.ultradns.org.
eff.org.                5771    IN      NS      pdns4.ultradns.org.
eff.org.                5771    IN      NS      pdns5.ultradns.info.
eff.org.                5771    IN      NS      pdns6.ultradns.co.uk.
eff.org.                5771    IN      NS      ns01.eff.org.
eff.org.                5771    IN      NS      pdns1.ultradns.net.
eff.org.                5771    IN      NS      pdns2.ultradns.net.

;; ADDITIONAL SECTION:
pdns1.ultradns.net.     64266   IN      A       204.74.108.1
pdns2.ultradns.net.     64266   IN      A       204.74.109.1
pdns3.ultradns.org.     64349   IN      A       199.7.68.1
pdns4.ultradns.org.     64349   IN      A       199.7.69.1
pdns5.ultradns.info.    64349   IN      A       204.74.114.1
pdns6.ultradns.co.uk.   64267   IN      A       204.74.115.1

;; Query time: 121 msec
;; SERVER: 217.13.4.21#53(217.13.4.21)
;; WHEN: Tue Feb 27 08:50:39 2007
;; MSG SIZE  rcvd: 312

dig @18.72.0.3 tor.linuxreviews.org
tor.linuxreviews.org.   60      IN      A       66.199.240.54

dig @217.13.7.136 tor.linuxreviews.org

; <<>> DiG 9.3.2 <<>> @217.13.7.136 tor.linuxreviews.org
; (1 server found)
;; global options:  printcmd
;; Got answer:
;; ->>HEADER<<- opcode: QUERY, status: NOERROR, id: 1672
;; flags: qr rd; QUERY: 1, ANSWER: 0, AUTHORITY: 6, ADDITIONAL: 5

;; QUESTION SECTION:
;tor.linuxreviews.org.          IN      A

;; AUTHORITY SECTION:
org.                    170324  IN      NS      TLD3.ULTRADNS.org.
org.                    170324  IN      NS      TLD4.ULTRADNS.org.
org.                    170324  IN      NS      TLD5.ULTRADNS.INFO.
org.                    170324  IN      NS      TLD6.ULTRADNS.CO.UK.
org.                    170324  IN      NS      TLD1.ULTRADNS.NET.
org.                    170324  IN      NS      TLD2.ULTRADNS.NET.

;; ADDITIONAL SECTION:
TLD1.ULTRADNS.NET.      17695   IN      A       204.74.112.1
TLD1.ULTRADNS.NET.      155105  IN      AAAA    2001:502:d399::1
TLD2.ULTRADNS.NET.      77630   IN      A       204.74.113.1
TLD3.ULTRADNS.org.      83928   IN      A       199.7.66.1
TLD5.ULTRADNS.INFO.     743     IN      A       192.100.59.11

;; Query time: 47 msec
;; SERVER: 217.13.7.136#53(217.13.7.136)
;; WHEN: Tue Feb 27 14:53:55 2007
;; MSG SIZE  rcvd: 292

*************'*************'*************'*************'*************'*************'

In Bullet Summary, We Now Know: Tor? You're looking up DNS in Norway. You're 
in Norway. NO TOR FOR YOU.