BIND servers for their product called Simple DNS Plus and all of our DNS problems went
away. It's been two years now without a single problem. Anyhow here is what they had
to say about the Verisign issue:
During the last 24 hours, we have received a lot of emails from Simple DNS Plus users about a new "Site Finder Service" just launched by VeriSign. Most of them requesting a new feature in Simple DNS Plus to neutralize this.
What VeriSign has done is add "*.com" and "*.net" DNS wildcard records on all the top-level DNS servers. These wildcard records point to a search engine type website operated by VeriSign themselves.
We assume that the intention is that any web-browser request for an un-registered domain name under ".com" and ".net" will be directed to this VeriSign website. However, as of this writing the "VeriSign Site Finder" site is not responding, and the result for most users is that any web-request for a un-registered ".com" or ".net" domain name just takes forever to timeout in the browser.
Some have suggested that this might be because they got a lot more traffic than expected, and so in effect they initiated a big DDOS attack on themselves.
For more information about this new VeriSign "service" and some of the problems it has caused, please see http://slashdot.org/article.pl?sid=03/09/16/0034210&mode=thread&tid=126&tid=95&tid=98&tid=99
We are currently in the final stages of beta testing the next version 3.50 of Simple DNS Plus. For more information about the new version and to download the beta, please see http://www.jhsoft.com/beta350.htm
However because of all these user requests, we have now re-opened the program code and added a new option to deal with this.
The "sdnsplus.ini" file will have a new setting "VSSiteFinder=<ip-address>". Any DNS response with an IP address listed in this setting will be converted back into a "name does not exist" (NXDomain) response as it was before.
The default is "VSSiteFinder=64.94.110.11". If VeriSign starts using other IP addresses for this, those can be added to this setting.
If you do not wish to use this feature (you want to use the VeriSign Site
Finder service) make sure to make this setting empty ("VSSiteFinder=").To try the updated Simple DNS Plus version 3.50 beta 3 with this new feature:
- Make sure you have 3.50 beta 3 installed - available for download at http://www.jhsoft.com/beta350.htm - Then download http://www.jhsoft.com/outbox/vssf/sdnsmain.exe to the Simple DNS Plus directory (replacing the original).
Please let us know if you have any questions or comments.
Sincerely, JH Software http://www.jhsoft.com
At 02:13 PM 9/17/2003, you wrote:
To make things worse, if you attempt to open an smtp connection to the helo host to verify they are at least a real mail server, you get a valid response.
try telneting to port 25 of any bogus .com or .net - you will see...
220 snubby1-wceast Snubby Mail Rejector Daemon v1.3 ready
this is a real bummer :)
We have an interim release that takes care of this problem, so that MAILFROM test will indeed fail on these bogus domains. Also, if you use anti-spam software that allows for RHSBL tests, you can set up a test named VERISCAM that uses the zone "." and a lookup IP of 64.94.110.11 ("VERISCAM rhsbl . 64.94.110.11 10 0" in Declude JunkMail).
-Scott
---
Declude JunkMail: The advanced anti-spam solution for IMail mailservers.
Declude Virus: Catches known viruses and is the leader in mailserver vulnerability detection.
Find out what you've been missing: Ask about our free 30-day evaluation.
---
[This E-mail was scanned for viruses by Declude Virus (http://www.declude.com)]
To Unsubscribe: http://www.ipswitch.com/support/mailing-lists.html List Archive: http://www.mail-archive.com/imail_forum%40list.ipswitch.com/ Knowledge Base/FAQ: http://www.ipswitch.com/support/IMail/
Gary Brumm ComsecNet Dedicated Data Services Stockton, CA Phone: 209-609-9495 Fax: 209-938-0481 Email: [EMAIL PROTECTED] Web: http://www.comsec.net
This message is intended for the use of the individual or entity to which it is addressed and may contain information that is privileged, confidential, and exempt from disclosure under applicable law. If the reader of this message is not the intended recipient or an employee or agent responsible for delivering to the intended recipient, you are hereby notified that any dissemination, distribution or copying of this communication is strictly prohibited. If you have received this communication in error please destroy this message and notify the sender by reply email.
To Unsubscribe: http://www.ipswitch.com/support/mailing-lists.html List Archive: http://www.mail-archive.com/imail_forum%40list.ipswitch.com/ Knowledge Base/FAQ: http://www.ipswitch.com/support/IMail/
