Google Groups no longer supports new Usenet posts or subscriptions. Historical content remains viewable.
Dismiss

default page lost forever

2 views
Skip to first unread message

daugavpils

unread,
Jul 23, 2001, 5:24:12 AM7/23/01
to
Hello ,
We ve got about 20 Windiws NT 4.0 computers on the site connected to
internet through ADSL modem .Linux Mandrake 7.2 box is used as gateway
and for NAT.
One sunny day all machines instead of standard server replay ("Page
cannot be displayed , blah-blah-blah") began to redirect browser to a
certain site , I will not name it ( it 's not a porn ).All this
process is combined with a bunch of bloody annoying popup windows.
First thought was cleaning all Temporary IE files, cookies , setting
up IE settings to default- no way.And damn site pops up on all
machines, which is quite strange.When you traceroute nonexisting
address , packet goes straight to that company's server.So.. I called
our provider and very politely asked them to find out whats going on
..The answer was the problem is in our machines - cookies, Temp IE
files, and that kind of staff.
Who's stupid now, can anybody tell me?...
Thank you for any ideas.

Eric A. Hall

unread,
Jul 23, 2001, 6:16:08 AM7/23/01
to
> We ve got about 20 Windiws NT 4.0 computers on the site connected to
> internet through ADSL modem .Linux Mandrake 7.2 box is used as gateway
> and for NAT.
> One sunny day all machines instead of standard server replay ("Page
> cannot be displayed , blah-blah-blah") began to redirect browser to a
> certain site , I will not name it ( it 's not a porn ).All this
> process is combined with a bunch of bloody annoying popup windows.

Sounds to me like the bigred DNS cache poisoning. Is your DNS server a
Win2k box? If so, you fix it by activating the "protect against cache
poisoning" checkbox on the DNS server control widget.

daugavpils

unread,
Jul 23, 2001, 12:49:41 PM7/23/01
to
Thank you for replay:)
Linux box is used as a gateway (samba server& firewall)only for all
those machines and it is not a DNS server - we use our ADSL provider's
DNS server..However on Linux, Netscape 4.7 doesnt send back that
stupid page (www.netidentity.com) , but on client computers it keeps
popping up in all browsers ...I deleted and disabled all possible
cookies , temp files , and so on , created new user profile ,still no
success. Other thing is that we dont have this problem in other
branches, while using the same systems and same DNS servers.
If you traceroute nonexisting address (e.g.
www.damnpopupsaremakingmesick.com) from NT Command prompt, packet gets
sent straight to that bloody server sd2.mailbank.com , which is hosted
by the same company as www.netidentity.com...
If you do it from other branches , it just says that address doesnt
exist (fare enough , huh?).You can call me paranoid , I try to install
new system from scratch now .
Any advice from clever people?...

Wojtek Zlobicki

unread,
Jul 24, 2001, 1:44:06 PM7/24/01
to
Have you checked the LMHOSTS file ? There may be a rouge entry there!


"daugavpils" <ser...@nextlife.co.uk> wrote in message
news:3678f30e.01072...@posting.google.com...

0 new messages