Solved

Strange DNS

Posted on 2006-06-28
14
322 Views
Last Modified: 2010-03-18
OK this is a strange one. I recently changed internet providers for our company. Everything went well and things checkout fine with DNSSTUFF.

The problem I am having is whenever someone internal tries to go to a bad address or mistyped address it defaults to our website. This wouldn’t be a big deal but I’m getting complaints, and I would rather have the unavailable error screen come up. So it seems that my DNS has decided that if it can’t find something then they must be looking for the website address.

I made no changes that should be causing this; all I did is change providers.
0
Comment
Question by:captony
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 6
  • 6
14 Comments
 
LVL 33

Expert Comment

by:MikeKane
ID: 17002859
So a mistyped URL results in your web page instead of the Microsoft standard error message "This page cannot be displayed".  


Sounds like someone has modified the DNSError webpage that is displayed for this type of error.  

If you START-RUN and type in  "res://shdoclc.dll.dnserror.htm"   DO you get the "this page cannot be displayed"  or do you get your company's homepage?  

If you get the homepage, then the DLL has been edited somehow, probably with a redirect or forward?    

If you get the standard page not displayed error, then this is not the cause of your issue.  

Try that and come back with the results....


0
 

Author Comment

by:captony
ID: 17003138
Ya if I run "res://shdoclc.dll.dnserror.htm" I get the "The page cannot be displayed" but if I type in http://hjkhjk/ it goes to our website LOL

I can't for the life of me figure out how I pulled that off.. This happens on all systems inside my network.
0
 
LVL 33

Expert Comment

by:MikeKane
ID: 17003271
If you run an nslookup and search for lkjdsahflkjh.ddd    Do you get an answer from the server, if so, what is the response.   Is it the IP for your website?  

Could it be cache related?    Clear out all the cache in your DNS server?  Both DNS' if you have more than 1 dns server.    Any change with that?  

I'm curious as to the nslookup results...
 

0
Online Training Solution

Drastically shorten your training time with WalkMe's advanced online training solution that Guides your trainees to action. Forget about retraining and skyrocket knowledge retention rates.

 

Author Comment

by:captony
ID: 17003462
yup I get a non-autoritative from my dns server with the address of my webserver
0
 
LVL 33

Expert Comment

by:MikeKane
ID: 17003769
Is your server Microsoft DNS or a version of BIND?  

0
 

Author Comment

by:captony
ID: 17004240
It's MS DNS running on windows 2000 server. I'm starting to think this might be my new service provider. Is there somthing they could have set that would make lost pages default to my website?
0
 
LVL 33

Expert Comment

by:MikeKane
ID: 17004410
Very odd.  Since the nslookup should have returned a ** Non-existant domain **  message instead.  

A few more tests:
1) Do you have a Forwarder setup in your MS DNS setup?   If so are these your new ISP's DNS servers?    Curious to see what happens if you try another ISP's DNS  (i.e. ATT DNS Servers 12.127.16.67 and 12.127.17.71)  

2) If your machine is setup as a DNS server for your Domain name?  Or do you rely on an ISP for your website's hostname resolution?  

3) If you try a NSLOOKUP and use 'SERVER 12.127.16.67' (this ip is ATT, you should use your ISP's DNS servers here also).   This sets the server to the ISPs DNS , not yours.   Try a lookup for slkjdfsls.aaa and see if you get your website or the Non existant domain message.    

0
 

Author Comment

by:captony
ID: 17011675
Yes, I had forwarders setup but turned them of while having this issue.

Our PDC is the DNS server for our Domain.

When I do an nslookup using the other server I still get our website for sdfsdfsfd.aaa, which I find very odd....
0
 
LVL 33

Expert Comment

by:MikeKane
ID: 17012308
Did I understand you right - nslookup, changed server to att's DNS, used garbage for a hostname and ATT returned the Non-autoritative answer of your website's IP??  

0
 

Author Comment

by:captony
ID: 17012789
You got it. Don't ask me how...
0
 

Author Comment

by:captony
ID: 17012867
One thing I find odd is that anytime I do a lookup it tags our domain on the end. for example lets say I'm google.com and I do a lookup for sadsdf.aaa, what I get is

name: sadsdf.aaa.google.com
address: the address of our webserver

So something is putting our domain name on the end of the searches, is that supposed to be happening?
0
 
LVL 33

Accepted Solution

by:
MikeKane earned 250 total points
ID: 17013347
Ahhh....   in XP you can append a DNS suffix to any dns query.  

You can configure the DNS suffix search order on a Windows system by following these steps:

   1. Access the properties of the network interface you wish to configure.
   2. Double-click on "Internet Protocol (TCP/IP)."
   3. In the Internet Protocol (TCP/IP) Properties dialog box, click the Advanced button.
   4. Click the DNS tab in the Advanced TCP/IP Settings dialog box.
   5. Click the "Append these DNS suffixes (in order)" radio button.
   6. Now click the Add button to add DNS suffixes to the connection.
   7. In the TCP/IP Domain Suffix dialog box, enter the name of the first domain name to append to any DNS search (Example: mcpmag.com).
   8. Repeat steps 6-7 for each additional domain.
   9. When finished, click OK to close the Advanced TCP/IP Settings dialog box.
  10. Click OK to close the Internet Protocol (TCP/IP) Properties dialog box.
  11. Click OK to close the network connection's Properties dialog box


Then use nslookup on a DNS client and query a name of a non existant server. Then you can open the %systemroot%\system32\dns\dns.log file on the DNS server to see the query results and check if the dns suffix is being appended to the search.    

0

Featured Post

Efficient way to get backups off site to Azure

This user guide provides instructions on how to deploy and configure both a StoneFly Scale Out NAS Enterprise Cloud Drive virtual machine and Veeam Cloud Connect in the Microsoft Azure Cloud.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

The Need In an Active Directory enviroment, the PDC emulator provide time synchronization for the domain. This is important since Active Directory uses Kerberos for authentication.  By default, if the time difference between systems is off by more …
Are you one of those front-line IT Service Desk staff fielding calls, replying to emails, all-the-while working to resolve end-user technological nightmares? I am! That's why I have put together this brief overview of tools and techniques I use in o…
How to Install VMware Tools in Red Hat Enterprise Linux 6.4 (RHEL 6.4) Step-by-Step Tutorial
This video shows how to use Hyena, from SystemTools Software, to update 100 user accounts from an external text file. View in 1080p for best video quality.

752 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question