 Originally Posted by c10ck3r Rec'd this from the ABA, thought I'd warn the powers that be.
I'm not entirely sure that's true. But then again, I wouldn't be surprised.

I personally do not trust OpenDNS. I don't like the fact they answer authoratively for domains which don't exist; covered with ads.

Google's DNS servers at least will say when they don't know the answer. 8.8.8.8 and 8.8.4.4.

Or, you can simply run your own DNS servers, and talk to the root servers.

 Originally Posted by chalsall I'm not entirely sure that's true. But then again, I wouldn't be surprised. (Snip snip)
Well, I assure you it was from the American Banking Association, who forwarded it to my employer (a member bank).
The FBI link is legit, and I made sure by accessing via the generic fbi.gov site before posting.

 Originally Posted by c10ck3r Well, I assure you it was from the American Banking Association, who forwarded it to my employer (a member bank). The FBI link is legit, and I made sure by accessing via the generic fbi.gov site before posting.
OK.

My issue is I don't like how OpenDNS deals with resolution of domains which don't exist. According to RFC 2606, when a domain name server doesn't know the answer to a question, it should say so.

OpenDNS answers all DNS queries; those it doesn't know about it answers with the IP of a web server which starts with ads.

For example, from the Unix, first quering OpenDNS:

[chalsall@burrow ~]$dig @208.67.220.220 thisshouldnotresolve.com ; <<>> DiG 9.8.2-RedHat-9.8.2-1.fc15 <<>> @208.67.220.220 thisshouldnotresolve.com ; (1 server found) ;; global options: +cmd ;; Got answer: ;; ->>HEADER<<- opcode: QUERY, status: NOERROR, id: 16219 ;; flags: qr rd ra; QUERY: 1, ANSWER: 1, AUTHORITY: 0, ADDITIONAL: 0 ;; QUESTION SECTION: ;thisshouldnotresolve.com. IN A ;; ANSWER SECTION: thisshouldnotresolve.com. 0 IN A 67.215.65.132 Then, asking Google's DNS: Code: [chalsall@burrow ~]$ dig @8.8.8.8 thisshouldnotresolve.com

; <<>> DiG 9.8.2-RedHat-9.8.2-1.fc15 <<>> @8.8.8.8 thisshouldnotresolve.com
; (1 server found)
;; global options: +cmd
;; ->>HEADER<<- opcode: QUERY, status: NXDOMAIN, id: 34873
;; flags: qr rd ra; QUERY: 1, ANSWER: 0, AUTHORITY: 1, ADDITIONAL: 0

;; QUESTION SECTION:
;thisshouldnotresolve.com.	IN	A

;; AUTHORITY SECTION:
com.			819	IN	SOA	a.gtld-servers.net. nstld.verisign-grs.com. 1337294775 1800 900 604800 86400

 Originally Posted by Dubslow This isn't the first time I've heard about this; the FBI has been issuing warnings via various methods (including the news, I believe) for at least 6 months now. That's why I had no trouble believing this.
I read something on this quite a while back, but it seemed most people didn't want to trust the FBI link, mainly due to paranoia about them finding stuff on their systems lol.

 Originally Posted by bcp19 I read something on this quite a while back, but it seemed most people didn't want to trust the FBI link, mainly due to paranoia about them finding stuff on their systems lol.
That, and I have gotten quite a few phishing-type emails which claim to be from the FBI, as well as from Hillary Clinton, and the usual Russian Oil Tycoons' Widows, HRM The Queen of England, and Nigerian Bankers. And besides, c10ck3r did verify the source. That does leave aside the question of how much faith you want to put into government pronouncements of the scary sort.

I'll try to gather some of my collection of amusing bogus emails and post them over at The Lounge, or wherever that thread is.

 Originally Posted by kladner That, and I have gotten quite a few phishing-type emails which claim to be from the FBI, as well as from Hillary Clinton, and the usual Russian Oil Tycoons' Widows, HRM The Queen of England, and Nigerian Bankers. And besides, c10ck3r did verify the source. That does leave aside the question of how much faith you want to put into government pronouncements of the scary sort. I'll try to gather some of my collection of amusing bogus emails and post them over at The Lounge, or wherever that thread is.
If I were in the affected group, I would not hesitate to use the FBI assist as I would simply go to the FBI website and look it up there rather than use an email link. Since I get dozens of paypal alerts a month telling me that if I don't respond my account will be locked, I am used to not clicking email links(Unless I am feeling ornery then I use a username like ^$()*&#(^$ or @^$^@$^@ and the email stickit@yourrear.com). Then there's the millions I fail to collect from all my little known relatives who have died in Africa and I've probably lost over a billion dollars so far. God, I must be crazy ;)

