Site down
Feb 5 2015, 8:41 pm
By: NudeRaider  

Feb 5 2015, 8:41 pm NudeRaider Post #1

We can't explain the universe, just describe it; and we don't know whether our theories are true, we just know they're not wrong. >Harald Lesch

Hi folks, got a technical question to the following scenario:

The site http://www.bro[redacted]net.net/ (bronet) seems to have been taken down on first glance, because when I enter it in my browser I'm redirected to libertyreserve.com which is a site that's been taken down by FBI some time ago and has a banner stating the site has been taken down.

Now when I use a proxy to connect to bronet I can use the site, though every link I clicked is apparently not run through the proxy again because it also redirects to libertyreserve.com. But if I input the page link into the proxy directly it works. It functions normally otherwise. However there's a large message in the header stating the following:
Message (no it's not just badly translated, the German is already this bad. :P


I've also confirmed that some people in Germany can connect just fine. Those use a different provider, so that is likely the most important lead.

Now I'm wondering what exactly might be happening. Apparently they got new servers, and possibly a new domain provider, reachable under a new IP adress. Now all that needs to be done is update the DNS, right?

When the DNS hasn't been updated yet, why does it link to a totally different page?
When the DNS has already been updated why does it work only partially?

The answer is probably linked to how the DNS-system works. What if only my forwarder, the DNS of my provider, has still the old IP/name resolution cached, and not updated the DNS? How long does a full DNS update through all levels of DNS take? I'd guess minutes at most because I never had that kind of problem before. But this site is unreachable for hours now. And that still doesn't explain the redirect to libertyreserve.com, which is a different top level domain.
I'd also be surprised if that were a deliberate redirect on my providers part (forged DNS) because as far as I'm aware they'd only (be forced to) do such things if that site was dealing in felony, and not some forum discussing warez. And even then, not to some shady US site, but probably just send an error unreachable.

so... any ideas?

Other info that might or might not be relevant:
A traceroute to bronet shows at the end a few hops through an anti-DDos system run by a company named ovh.

- cutting power to the router for a minute and thus getting a new IP
- ipconfig /flushdns
- and deleting browsercache
all have had no effect




Feb 5 2015, 9:00 pm jjf28 Post #2

Cartography Artisan

Option 1: Manually configure DNS to a server that has the updated address (may need to clear your own DNS cache after doing so)
Option 2: Wait :( I recall a site of mine going down due to DDoS, the IP was changed quickly but it was inaccessible for at least a week while it propagated

Edit: I vaguely remember there was a way to manually map an IP to a DNS server for your network/computer with some non-trival method

Post has been edited 1 time(s), last time on Feb 5 2015, 9:05 pm by jjf28.



TheNitesWhoSay - Clan Aura - github

Reached the top of StarCraft theory crafting 2:12 AM CST, August 2nd, 2014.

Feb 5 2015, 9:16 pm NudeRaider Post #3

We can't explain the universe, just describe it; and we don't know whether our theories are true, we just know they're not wrong. >Harald Lesch

Quote from jjf28
Option 1: Manually configure DNS to a server that has the updated address (may need to clear your own DNS cache after doing so)
Option 2: Wait :( I recall a site of mine going down due to DDoS, the IP was changed quickly but it was inaccessible for at least a week while it propagated

Edit: I vaguely remember there was a way to manually map an IP to a DNS server for your network/computer with some non-trival method
I can map IPs to domain names in the hosts file in %systemroot%\system32\drivers\etc

But I don't have the new IP address. How can I tell the IP of a site im connected to via proxy, when I can't trust DNS?

1) Is a good idea though. I'll try google.
EDIT: Didn't help. When I directly enter the IP that google DNS returns it shows a default page of the webhoster - probably the one where it used to be.

Any other ideas?

Post has been edited 1 time(s), last time on Feb 5 2015, 9:22 pm by NudeRaider.




Feb 5 2015, 9:20 pm rockz Post #4

ᴄʜᴇᴇsᴇ ɪᴛ!

Use dns 8.8.8.8 and 8.8.4.4 or openDNS.

You can also use isup.me and an online ping tool to help identify the correct IP.



"Parliamentary inquiry, Mr. Chairman - do we have to call the Gentleman a gentleman if he's not one?"

Feb 5 2015, 9:27 pm NudeRaider Post #5

We can't explain the universe, just describe it; and we don't know whether our theories are true, we just know they're not wrong. >Harald Lesch

Quote from rockz
You can also use isup.me and
Wouldn't that give false positives due to the redirect and empty hoster pages?

Quote from rockz
an online ping tool to help identify the correct IP.
Interesting. This returns a different IP for bronet, but this IP also leads me to an empty hoster page of the same provider.




Options
  Back to forum
Please log in to reply to this topic or to report it.
Members in this topic: None.
[10:50 pm]
Vrael -- Ultraviolet
Ultraviolet shouted: How about you all send me your minerals instead of washing them into the gambling void? I'm saving up for a new name color and/or glow
hey cut it out I'm getting all the minerals
[10:11 pm]
Ultraviolet -- :P
[10:11 pm]
Ultraviolet -- How about you all send me your minerals instead of washing them into the gambling void? I'm saving up for a new name color and/or glow
[2024-4-17. : 11:50 pm]
O)FaRTy1billion[MM] -- nice, now i have more than enough
[2024-4-17. : 11:49 pm]
O)FaRTy1billion[MM] -- if i don't gamble them away first
[2024-4-17. : 11:49 pm]
O)FaRTy1billion[MM] -- o, due to a donation i now have enough minerals to send you minerals
[2024-4-17. : 3:26 am]
O)FaRTy1billion[MM] -- i have to ask for minerals first tho cuz i don't have enough to send
[2024-4-17. : 1:53 am]
Vrael -- bet u'll ask for my minerals first and then just send me some lousy vespene gas instead
[2024-4-17. : 1:52 am]
Vrael -- hah do you think I was born yesterday?
[2024-4-17. : 1:08 am]
O)FaRTy1billion[MM] -- i'll trade you mineral counts
Please log in to shout.


Members Online: jun3hong, Zergy, Ultraviolet