Hurricane Electric's IPv6 Tunnel Broker Forums
May 25, 2013, 09:52:19 am *
Welcome, Guest. Please login or register.

Login with username, password and session length
News: Welcome to Hurricane Electric's Tunnelbroker.net forums!
 
   Home   Help Search Login Register  
Pages: [1]
  Print  
Author Topic: Zone failed validation test. Wildcarding has been disabled due to abuse.  (Read 5564 times)
CrunkBass
Newbie
*
Posts: 7


View Profile
« on: September 08, 2011, 04:20:11 pm »

I am using the free DNS service from HE with the domain crunkbass.net and can't set a wildcard.

The nameservers are set correctly but i could only add 4 NS entrys at my domain registrar.
Code:
root@Vmware-Debian:~# dig crunkbass.net NS

; <<>> DiG 9.7.3 <<>> crunkbass.net NS
;; global options: +cmd
;; Got answer:
;; ->>HEADER<<- opcode: QUERY, status: NOERROR, id: 43446
;; flags: qr rd ra; QUERY: 1, ANSWER: 4, AUTHORITY: 0, ADDITIONAL: 4

;; QUESTION SECTION:
;crunkbass.net.                 IN      NS

;; ANSWER SECTION:
crunkbass.net.          86378   IN      NS      ns1.he.net.
crunkbass.net.          86378   IN      NS      ns3.he.net.
crunkbass.net.          86378   IN      NS      ns2.he.net.
crunkbass.net.          86378   IN      NS      ns4.he.net.

;; ADDITIONAL SECTION:
ns3.he.net.             86378   IN      A       216.218.132.2
ns4.he.net.             86378   IN      A       216.66.1.2
ns2.he.net.             86378   IN      A       216.218.131.2
ns1.he.net.             86378   IN      A       216.218.130.2

;; Query time: 23 msec
;; SERVER: 192.168.158.1#53(192.168.158.1)
;; WHEN: Fri Sep  9 01:23:03 2011
;; MSG SIZE  rcvd: 170

Does anyone know what could be the problem?
Logged
broquea
Senior Network Engineer, SEVEN Networks (AS19733)
Hero Member
*****
Posts: 1379



View Profile WWW
« Reply #1 on: September 08, 2011, 05:28:57 pm »

Were you...trying to create a wildcard entry? I think the reporting error sums it up if you were.
Wildcarding has been disabled due to abuse.
Not you specifically, this is a global setting. Cheesy
« Last Edit: September 08, 2011, 05:38:42 pm by broquea » Logged
CrunkBass
Newbie
*
Posts: 7


View Profile
« Reply #2 on: September 09, 2011, 06:00:27 am »

Thank you for your answer. Are there any plans to enabled wildcarding again or do i have to use an other dns service?
Logged
broquea
Senior Network Engineer, SEVEN Networks (AS19733)
Hero Member
*****
Posts: 1379



View Profile WWW
« Reply #3 on: September 09, 2011, 06:04:23 am »

You would need to email dnsadmin@he.net for that answer.
Logged
ionvz
Newbie
*
Posts: 2


View Profile
« Reply #4 on: October 30, 2011, 11:39:48 pm »

I wonder what kind of abuse they speak of? It's rather disappointing though when it comes to dynamic applications to not have wildcard DNS available (and I'd prefer not to go back to using something like namecheap's DNS etc).
Logged
chaz6
Newbie
*
Posts: 8


View Profile
« Reply #5 on: October 31, 2011, 01:50:12 am »

Is wildcarding still available to paying customers?
Logged
jrocha
Network Engineer, Hurricane Electric
Administrator
Jr. Member
*****
Posts: 66



View Profile WWW
« Reply #6 on: November 03, 2011, 03:56:09 pm »

You will have to email dnsadmin@he.net.
Logged
mralexgray
Newbie
*
Posts: 5


View Profile
« Reply #7 on: November 12, 2011, 01:07:09 am »

Managing zone: XXXXXX.com.  Zone failed validation test.
Wildcarding has been disabled due to abuse.


My note to support:

Quote
Is this error specific to my account - or is this a site-wide change (as is being reported in the forums)?

Is this feature going to be re-enabled? Is it up for discussion?  Was it going to be mentioned?

I hope so…  I would consider wildcards - an "essential feature".

Seems a less drastic a solution would be to simply disable it for those who are abusing it, no?


Maybe dnsadmin@he.net can post a sticky or something - that explains this policy shift, more clearly?   Huh

Logged
jschv6
Newbie
*
Posts: 4


View Profile
« Reply #8 on: March 03, 2012, 06:27:57 am »

Hi,
I just noticed, that it is no longer possible to add wildcard domains.
I found them very handy, because I want people to see a custom error page when mistyping a part of the domain.
Also I have several services behind my home-IP. This IP changes sometimes and with a wildcard subdomain I only have to set the new IP at two places (IPv6 Tunnel Endpoint and Wildcard Subdomain A entry).

I can understand that HE has to disable features that are commonly abused on their free service, but I would be very happy if there would be some way to enable this again.
Maybe only for Sages like the IRC connections at the tunnel.
Are there any plans for this?

I am not going to abuse that, at least not willingly, because I can not even imagine how to abuse wildcard subdomains Huh
Maybe someone can enlighten me, just out of curiosity (only if it is not tempting people to do it)
You even know my address, because you kindly sent me a free t-shirt, so if I ever abuse a wildcard subdomain you can send a SWAT team to get me Wink
Logged
DAR2133576
readonly_member
Newbie
*
Posts: 3


View Profile WWW
« Reply #9 on: April 17, 2012, 01:36:51 am »

Hi,
I just noticed, that it is no longer possible to add wildcard domains.
I found them very handy, because I want people to see a custom error page when mistyping a part of the domain.
Also I have several services behind my home-IP. This IP changes sometimes and with a wildcard subdomain I only have to set the new IP at two places (IPv6 Tunnel Endpoint and Wildcard Subdomain A entry).

I can understand that HE has to disable features that are commonly abused on their free service, but I would be very happy if there would be some way to enable this again.
Maybe only for Sages like the IRC connections at the tunnel.
Are there any plans for this?

I am not going to abuse that, at least not willingly, because I can not even imagine how to abuse wildcard subdomains Huh
Maybe someone can enlighten me, just out of curiosity (only if it is not tempting people to do it)
You even know my address, because you kindly sent me a free t-shirt, so if I ever abuse a wildcard subdomain you can send a SWAT team to get me Wink

Since their used to redirect nonexistent DNS Records it can be used in whats called Session fixation exploiting. Wildcard cookies can be set by one subdomain that will effect other subdomains. Their is also DNS hijacks and scripting exploits which can be used with that feature. This is why I doubt you would be able to get use of wildcards unfortunately because there will always be evil people who use features to harm others.
Logged
jschv6
Newbie
*
Posts: 4


View Profile
« Reply #10 on: May 21, 2012, 04:04:48 am »

Since their used to redirect nonexistent DNS Records it can be used in whats called Session fixation exploiting. Wildcard cookies can be set by one subdomain that will effect other subdomains. Their is also DNS hijacks and scripting exploits which can be used with that feature. This is why I doubt you would be able to get use of wildcards unfortunately because there will always be evil people who use features to harm others.
Thanks for the answer! I don't really understand how this can be used if I "own" tho whole second level domain, but I will try and google a bit more with that keywords.
Sad, that some people abusing this take a usefull feature away from all people Sad
Logged
ionvz
Newbie
*
Posts: 2


View Profile
« Reply #11 on: May 20, 2013, 05:39:37 pm »

I know this is a necro bump. But... others may see it from google searches. 

Thanks for the answer! I don't really understand how this can be used if I "own" tho whole second level domain, but I will try and google a bit more with that keywords.

Don't think the abuse in question is much about people attacking someone else's domains, but rather people using their own domains with the intent of abuse. For example phishing scams could dynamically respond to hundreds of different possible aliases, with a legit looking domain in the front of the alias.

Sad, that some people abusing this take a usefull feature away from all people Sad

They didn't remove the feature, they just put the feature into the hands of the DNS admins, which you'll need to email  dnsadmin@he.net in order to request it's addition or modification.
Logged
Pages: [1]
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.18 | SMF © 2013, Simple Machines Valid XHTML 1.0! Valid CSS!