ML
    • Recent
    • Categories
    • Tags
    • Popular
    • Users
    • Groups
    • Register
    • Login

    CloudatCost OpenDNS Issue

    IT Discussion
    dns cloudatcost
    15
    184
    67.4k
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • ?
      A Former User
      last edited by

      OpenDNS and Open DNS aren't the same. Do a port scan on port 53. Lock down Port 53 via the firewall.

      1 Reply Last reply Reply Quote 1
      • ?
        A Former User @scottalanmiller
        last edited by

        @scottalanmiller said:

        And you definitely are running public DNS servers. I can use you as my DNS source.

        nslookup yahoo.com 104.167.117.250
        Server:         104.167.117.250
        Address:        104.167.117.250#53
        
        Non-authoritative answer:
        Name:   yahoo.com
        Address: 98.138.253.109
        Name:   yahoo.com
        Address: 98.139.183.24
        Name:   yahoo.com
        Address: 206.190.36.45
        

        Oh wow. Did you install Bind?

        1 Reply Last reply Reply Quote 0
        • ?
          A Former User
          last edited by A Former User

          Also, why is your firewall off?

          1 Reply Last reply Reply Quote 0
          • S
            scottalanmiller
            last edited by

            He must have! Or MaraDNS or whatever that competitor is called.

            1 Reply Last reply Reply Quote 0
            • T
              thanksajdotcom
              last edited by

              It's a DC. It's my failover. What do I need to change?

              S ? 2 Replies Last reply Reply Quote -1
              • S
                scottalanmiller @thanksajdotcom
                last edited by

                @thanksajdotcom said:

                It's a DC. It's my failover. What do I need to change?

                OH! He publicly exposed a Domain Controller!!!

                You have it wide open, like it is sitting on a LAN. You have DNS, DHCP, AD, etc. open to the world because your "LAN" is the Internet!!

                1 Reply Last reply Reply Quote 0
                • ?
                  A Former User @thanksajdotcom
                  last edited by

                  @thanksajdotcom said:

                  It's a DC. It's my failover. What do I need to change?

                  Change the Zone's the ports are allowed on. Only allow it on the VPN Zone. Aka Not Public.

                  T 1 Reply Last reply Reply Quote 1
                  • T
                    thanksajdotcom
                    last edited by

                    Just lock down DNS to internal only or what?

                    1 Reply Last reply Reply Quote -1
                    • ?
                      A Former User
                      last edited by

                      I would never trust that DC again. Time to rebuild.

                      T 1 Reply Last reply Reply Quote 1
                      • T
                        thanksajdotcom @A Former User
                        last edited by thanksajdotcom

                        @Aaron-Studer said:

                        I would never trust that DC again. Time to rebuild.

                        It's secured with Webroot. Also, there's been no indication of an attack. I'm not decomming it without a good reason.

                        S 1 Reply Last reply Reply Quote -1
                        • T
                          thanksajdotcom @A Former User
                          last edited by

                          @thecreativeone91 said:

                          @thanksajdotcom said:

                          It's a DC. It's my failover. What do I need to change?

                          Change the Zone's the ports are allowed on. Only allow it on the VPN Zone. Aka Not Public.

                          Ok, so in Windows Firewall?

                          1 Reply Last reply Reply Quote 0
                          • S
                            scottalanmiller @thanksajdotcom
                            last edited by

                            @thanksajdotcom said:

                            @Aaron-Studer said:

                            I would never trust that DC again. Time to rebuild.

                            It's secured with Webroot. Also, there's been no indication of an attack. I'm not decomming it without a good reason.

                            It's not like he'll have it for long anyway. He doesn't have a datacenter license for every CPU in the cloud so he can't run anything but a demo license that expires in 90 days there.

                            ? T 2 Replies Last reply Reply Quote 0
                            • ?
                              A Former User
                              last edited by

                              At least you don't have any open SMB shares.

                              ? T 2 Replies Last reply Reply Quote 0
                              • ?
                                A Former User @A Former User
                                last edited by A Former User

                                @thecreativeone91 How do you know this? I bet he did it is a domain controller after all.

                                S 1 Reply Last reply Reply Quote 0
                                • S
                                  scottalanmiller @A Former User
                                  last edited by

                                  @Aaron-Studer said:

                                  @thecreativeone91 How do you know this?

                                  You can just attempt to connect 🙂

                                  1 Reply Last reply Reply Quote 1
                                  • ?
                                    A Former User
                                    last edited by

                                    I am using AJ as my DNS server now! THANKSAJ! =P

                                    1 Reply Last reply Reply Quote 2
                                    • ?
                                      A Former User @scottalanmiller
                                      last edited by

                                      @scottalanmiller said:

                                      @thanksajdotcom said:

                                      @Aaron-Studer said:

                                      I would never trust that DC again. Time to rebuild.

                                      It's secured with Webroot. Also, there's been no indication of an attack. I'm not decomming it without a good reason.

                                      It's not like he'll have it for long anyway. He doesn't have a datacenter license for every CPU in the cloud so he can't run anything but a demo license that expires in 90 days there.

                                      Why don't you just run the Standard version. Granted Cloud@Cloud not having a infrastructure based firewall option is not really the place for something like a DC.

                                      S 1 Reply Last reply Reply Quote 0
                                      • ?
                                        A Former User
                                        last edited by

                                        DNS is working great for me.

                                        ? 1 Reply Last reply Reply Quote 1
                                        • ?
                                          A Former User @A Former User
                                          last edited by

                                          @thecreativeone91 Me too. Super Fast! So much better then OpenDNS!

                                          1 Reply Last reply Reply Quote 0
                                          • ?
                                            A Former User
                                            last edited by

                                            Your firewall should be blocking everything on your public connection except RDP.

                                            ? 1 Reply Last reply Reply Quote 0
                                            • 1
                                            • 2
                                            • 3
                                            • 4
                                            • 5
                                            • 6
                                            • 7
                                            • 8
                                            • 9
                                            • 10
                                            • 6 / 10
                                            • First post
                                              Last post