gist.github.com 无法访问,疑似被 DNS 污染

2014-11-01 21:09:11 +08:00
 ehs2013
北京联通今晚突然就无法访问 GitHub Gist 了,但是 GitHub 主站能正常访问,你们那也有这种现象吗?

使用 V2EX DNS 解析的结果
➜ ~ dig gist.github.com @178.79.131.110 +tcp +trace

; <<>> DiG 9.8.3-P1 <<>> gist.github.com @178.79.131.110 +tcp +trace
;; global options: +cmd
. 11145 IN NS a.root-servers.net.
. 11145 IN NS b.root-servers.net.
. 11145 IN NS c.root-servers.net.
. 11145 IN NS d.root-servers.net.
. 11145 IN NS e.root-servers.net.
. 11145 IN NS f.root-servers.net.
. 11145 IN NS g.root-servers.net.
. 11145 IN NS h.root-servers.net.
. 11145 IN NS i.root-servers.net.
. 11145 IN NS j.root-servers.net.
. 11145 IN NS k.root-servers.net.
. 11145 IN NS l.root-servers.net.
. 11145 IN NS m.root-servers.net.
;; Received 228 bytes from 178.79.131.110#53(178.79.131.110) in 465 ms

com. 172800 IN NS a.gtld-servers.net.
com. 172800 IN NS b.gtld-servers.net.
com. 172800 IN NS c.gtld-servers.net.
com. 172800 IN NS d.gtld-servers.net.
com. 172800 IN NS e.gtld-servers.net.
com. 172800 IN NS f.gtld-servers.net.
com. 172800 IN NS g.gtld-servers.net.
com. 172800 IN NS h.gtld-servers.net.
com. 172800 IN NS i.gtld-servers.net.
com. 172800 IN NS j.gtld-servers.net.
com. 172800 IN NS k.gtld-servers.net.
com. 172800 IN NS l.gtld-servers.net.
com. 172800 IN NS m.gtld-servers.net.
;; Received 521 bytes from 192.203.230.10#53(192.203.230.10) in 253 ms

github.com. 172800 IN NS ns1.p16.dynect.net.
github.com. 172800 IN NS ns3.p16.dynect.net.
github.com. 172800 IN NS ns2.p16.dynect.net.
github.com. 172800 IN NS ns4.p16.dynect.net.
;; Received 183 bytes from 192.52.178.30#53(192.52.178.30) in 435 ms

gist.github.com. 30 IN A 192.30.252.142
github.com. 86400 IN NS ns4.p16.dynect.net.
github.com. 86400 IN NS ns3.p16.dynect.net.
github.com. 86400 IN NS ns1.p16.dynect.net.
github.com. 86400 IN NS ns2.p16.dynect.net.
;; Received 135 bytes from 208.78.71.16#53(208.78.71.16) in 142 ms

使用运营商 DNS 的解析结果

➜ ~ dig gist.github.com +trace

; <<>> DiG 9.8.3-P1 <<>> gist.github.com +trace
;; global options: +cmd
. 460374 IN NS l.root-servers.net.
. 460374 IN NS h.root-servers.net.
. 460374 IN NS j.root-servers.net.
. 460374 IN NS k.root-servers.net.
. 460374 IN NS e.root-servers.net.
. 460374 IN NS b.root-servers.net.
. 460374 IN NS m.root-servers.net.
. 460374 IN NS a.root-servers.net.
. 460374 IN NS i.root-servers.net.
. 460374 IN NS c.root-servers.net.
. 460374 IN NS d.root-servers.net.
. 460374 IN NS g.root-servers.net.
. 460374 IN NS f.root-servers.net.
;; Received 228 bytes from 202.106.195.68#53(202.106.195.68) in 13 ms

com. 172800 IN NS m.gtld-servers.net.
com. 172800 IN NS b.gtld-servers.net.
com. 172800 IN NS g.gtld-servers.net.
com. 172800 IN NS l.gtld-servers.net.
com. 172800 IN NS e.gtld-servers.net.
com. 172800 IN NS c.gtld-servers.net.
com. 172800 IN NS h.gtld-servers.net.
com. 172800 IN NS a.gtld-servers.net.
com. 172800 IN NS k.gtld-servers.net.
com. 172800 IN NS d.gtld-servers.net.
com. 172800 IN NS i.gtld-servers.net.
com. 172800 IN NS j.gtld-servers.net.
com. 172800 IN NS f.gtld-servers.net.
;; Received 505 bytes from 192.36.148.17#53(192.36.148.17) in 91 ms

gist.github.com. 15180 IN A 202.181.7.85
;; Received 49 bytes from 192.35.51.30#53(192.35.51.30) in 45 ms

➜ ~ dig gist.github.com +trace

; <<>> DiG 9.8.3-P1 <<>> gist.github.com +trace
;; global options: +cmd
. 379892 IN NS j.root-servers.net.
. 379892 IN NS k.root-servers.net.
. 379892 IN NS a.root-servers.net.
. 379892 IN NS m.root-servers.net.
. 379892 IN NS f.root-servers.net.
. 379892 IN NS g.root-servers.net.
. 379892 IN NS i.root-servers.net.
. 379892 IN NS b.root-servers.net.
. 379892 IN NS c.root-servers.net.
. 379892 IN NS h.root-servers.net.
. 379892 IN NS l.root-servers.net.
. 379892 IN NS d.root-servers.net.
. 379892 IN NS e.root-servers.net.
;; Received 228 bytes from 202.106.195.68#53(202.106.195.68) in 14 ms

gist.github.com. 10328 IN A 209.145.54.50
;; Received 49 bytes from 192.112.36.4#53(192.112.36.4) in 92 ms
9357 次点击
所在节点    问与答
12 条回复
tayuo
2014-11-01 21:11:09 +08:00
难道还没有全程出墙....
fengyuwujian
2014-11-01 21:59:54 +08:00
nslookup gist.github.com 114.114.114.114
服务器: public1.114dns.com
Address: 114.114.114.114

非权威应答:
名称: gist.github.com
Address: 202.181.7.85

http://zh.wikipedia.org/wiki/DNS%E6%B1%A1%E6%9F%93

已确认dns污染
RoshanWu
2014-11-01 22:07:19 +08:00
桑心,gist 也墙,丧心病狂
mocha
2014-11-01 22:51:13 +08:00
该来的还是来了
hx1997
2014-11-01 23:11:22 +08:00
是的,刚才看一个帖子里边嵌了 Github Gist 结果接下来的页面内容都卡住不加载了。。。
sincway
2014-11-01 23:49:16 +08:00
难道是因为 imouto.hosts 那些。。
0x142857
2014-11-02 00:23:05 +08:00
果然打不开了。。
TrustyWolf
2014-11-02 00:36:47 +08:00
丧心病狂啊...DNS真是太脆弱了,目前DNSSEC不会普及的情况下几乎没有什么可以正面对抗高墙的方法。
Viztor
2014-11-02 02:31:50 +08:00
@TrustyWolf 说起来,阿里DNS之类的 DNSSEC 似乎没有设置啊?
TrustyWolf
2014-11-02 09:04:46 +08:00
@Viztor 国内目前还没有一家DNS服务商能提供DNSSEC的支持。DNSPOD在10年的时候曾经部署过,但目前只有企业版的付费DNS支持该功能。国外的DNS服务商也是这样,基本上都是付费的DNS才支持这个功能,有些域名注册商自己的DNS免费提供这项功能,但是对国内线路优化不好,查询需要很长时间。
bitweaver
2014-11-02 12:50:00 +08:00
墙外IP查询114DNS获得正确地址
nslookup gist.github.com 114.114.114.114
Server: 114.114.114.114
Address: 114.114.114.114#53

Non-authoritative answer:
Name: gist.github.com
Address: 192.30.252.142

墙内IP查询114DNS获得了错误地址
nslookup gist.github.com 114.114.114.114
Server: 114.114.114.114
Address: 114.114.114.114#53

Non-authoritative answer:
Name: gist.github.com
Address: 4.36.66.178

再换一个墙内ISP的DNS,依然错误
nslookup gist.github.com 61.132.163.68
Server: 61.132.163.68
Address: 61.132.163.68#53

Non-authoritative answer:
Name: gist.github.com
Address: 202.106.1.2
dongzeamoy
2018-03-22 10:48:00 +08:00
哎,好失望啊

这是一个专为移动设备优化的页面(即为了让你能够在 Google 搜索结果里秒开这个页面),如果你希望参与 V2EX 社区的讨论,你可以继续到 V2EX 上打开本讨论主题的完整版本。

https://www.v2ex.com/t/143257

V2EX 是创意工作者们的社区,是一个分享自己正在做的有趣事物、交流想法,可以遇见新朋友甚至新机会的地方。

V2EX is a community of developers, designers and creative people.

© 2021 V2EX