<?xml version="1.0" encoding="utf-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Dropping spurious ./NS/IN recursive queries</title>
	<atom:link href="http://www.stupendous.net/archives/2009/01/24/dropping-spurious-nsin-recursive-queries/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.stupendous.net/archives/2009/01/24/dropping-spurious-nsin-recursive-queries/</link>
	<description>ramblings of a caffeinated discombobulated mind</description>
	<lastBuildDate>Fri, 30 Jul 2010 18:55:45 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=abc</generator>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<item>
		<title>By: Mickey Mouse</title>
		<link>http://www.stupendous.net/archives/2009/01/24/dropping-spurious-nsin-recursive-queries/comment-page-1/#comment-9606</link>
		<dc:creator>Mickey Mouse</dc:creator>
		<pubDate>Mon, 23 Feb 2009 22:35:45 +0000</pubDate>
		<guid isPermaLink="false">http://www.stupendous.net/?p=309#comment-9606</guid>
		<description>&lt;p&gt;Thanks so much.  I don&#039;t want to contribute either and I&#039;m not any longer&lt;/p&gt;
</description>
		<content:encoded><![CDATA[<p>Thanks so much.  I don&#8217;t want to contribute either and I&#8217;m not any longer</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: chrome</title>
		<link>http://www.stupendous.net/archives/2009/01/24/dropping-spurious-nsin-recursive-queries/comment-page-1/#comment-9486</link>
		<dc:creator>chrome</dc:creator>
		<pubDate>Tue, 03 Feb 2009 23:05:37 +0000</pubDate>
		<guid isPermaLink="false">http://www.stupendous.net/?p=309#comment-9486</guid>
		<description>&lt;p&gt;Not here. May be something else going on? Run a packet capture?&lt;/p&gt;
</description>
		<content:encoded><![CDATA[<p>Not here. May be something else going on? Run a packet capture?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: sov</title>
		<link>http://www.stupendous.net/archives/2009/01/24/dropping-spurious-nsin-recursive-queries/comment-page-1/#comment-9485</link>
		<dc:creator>sov</dc:creator>
		<pubDate>Tue, 03 Feb 2009 14:00:44 +0000</pubDate>
		<guid isPermaLink="false">http://www.stupendous.net/?p=309#comment-9485</guid>
		<description>&lt;p&gt;Hi and thank you for this very usefull snippet :)
Since about one day now I&#039;m using it, but I&#039;ve noticed that my DNS server is now beeing flood by request for my reverse DNS (on wich I do &lt;em&gt;not&lt;/em&gt; have control, that&#039;s why i&#039;ve noticed it).
It started just right after I started using the iptables snippet above.
Does anybody else noticed something like that on his server ?&lt;/p&gt;
</description>
		<content:encoded><![CDATA[<p>Hi and thank you for this very usefull snippet :)<br />
Since about one day now I&#8217;m using it, but I&#8217;ve noticed that my DNS server is now beeing flood by request for my reverse DNS (on wich I do <em>not</em> have control, that&#8217;s why i&#8217;ve noticed it).<br />
It started just right after I started using the iptables snippet above.<br />
Does anybody else noticed something like that on his server ?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Glen Combe</title>
		<link>http://www.stupendous.net/archives/2009/01/24/dropping-spurious-nsin-recursive-queries/comment-page-1/#comment-9482</link>
		<dc:creator>Glen Combe</dc:creator>
		<pubDate>Fri, 30 Jan 2009 17:39:51 +0000</pubDate>
		<guid isPermaLink="false">http://www.stupendous.net/?p=309#comment-9482</guid>
		<description>&lt;p&gt;Thanks for posting this.. been getting hammered with..just had re compile my kenrel with the u32 support!  thnx!&lt;/p&gt;
</description>
		<content:encoded><![CDATA[<p>Thanks for posting this.. been getting hammered with..just had re compile my kenrel with the u32 support!  thnx!</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Darryl</title>
		<link>http://www.stupendous.net/archives/2009/01/24/dropping-spurious-nsin-recursive-queries/comment-page-1/#comment-9481</link>
		<dc:creator>Darryl</dc:creator>
		<pubDate>Wed, 28 Jan 2009 14:22:35 +0000</pubDate>
		<guid isPermaLink="false">http://www.stupendous.net/?p=309#comment-9481</guid>
		<description>&lt;p&gt;When I paste the iptables command you have, I get:&lt;/p&gt;

&lt;p&gt;iptables: Invalid argument&lt;/p&gt;

&lt;p&gt;and in dmesg:&lt;/p&gt;

&lt;p&gt;ip_tables: u32 match: invalid size 1984 != 2028&lt;/p&gt;

&lt;p&gt;This is on a 2.6.23 debian machine. Any ideas?&lt;/p&gt;
</description>
		<content:encoded><![CDATA[<p>When I paste the iptables command you have, I get:</p>
<p>iptables: Invalid argument</p>
<p>and in dmesg:</p>
<p>ip_tables: u32 match: invalid size 1984 != 2028</p>
<p>This is on a 2.6.23 debian machine. Any ideas?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Curtis Maurand</title>
		<link>http://www.stupendous.net/archives/2009/01/24/dropping-spurious-nsin-recursive-queries/comment-page-1/#comment-9480</link>
		<dc:creator>Curtis Maurand</dc:creator>
		<pubDate>Wed, 28 Jan 2009 13:49:00 +0000</pubDate>
		<guid isPermaLink="false">http://www.stupendous.net/?p=309#comment-9480</guid>
		<description>&lt;p&gt;modprobe xt_u32&lt;/p&gt;

&lt;p&gt;should load it.&lt;/p&gt;
</description>
		<content:encoded><![CDATA[<p>modprobe xt_u32</p>
<p>should load it.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: chrome</title>
		<link>http://www.stupendous.net/archives/2009/01/24/dropping-spurious-nsin-recursive-queries/comment-page-1/#comment-9475</link>
		<dc:creator>chrome</dc:creator>
		<pubDate>Sat, 24 Jan 2009 22:54:51 +0000</pubDate>
		<guid isPermaLink="false">http://www.stupendous.net/?p=309#comment-9475</guid>
		<description>&lt;p&gt;Debian lenny packages it with the kernel package:&lt;/p&gt;

&lt;p&gt;&lt;code&gt;linux-image-2.6.26-1-686: /lib/modules/2.6.26-1-686/kernel/net/netfilter/xt_u32.ko&lt;/code&gt;&lt;/p&gt;

&lt;p&gt;You might have to build a custom kernel, or alternatively, build the kernel module separately.&lt;/p&gt;
</description>
		<content:encoded><![CDATA[<p>Debian lenny packages it with the kernel package:</p>
<p><div class="codecolorer-container text vibrant" style="overflow:auto;white-space:nowrap;border: 1px solid #9F9F9F;width:435px;"><div class="text codecolorer" style="padding:5px;font:normal 12px/1.4em Monaco, Lucida Console, monospace;white-space:nowrap">linux-image-2.6.26-1-686: /lib/modules/2.6.26-1-686/kernel/net/netfilter/xt_u32.ko</div></div>
</p>
<p>You might have to build a custom kernel, or alternatively, build the kernel module separately.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Cezar RO</title>
		<link>http://www.stupendous.net/archives/2009/01/24/dropping-spurious-nsin-recursive-queries/comment-page-1/#comment-9473</link>
		<dc:creator>Cezar RO</dc:creator>
		<pubDate>Sat, 24 Jan 2009 19:55:49 +0000</pubDate>
		<guid isPermaLink="false">http://www.stupendous.net/?p=309#comment-9473</guid>
		<description>&lt;p&gt;Yes, maybe cool, maybe it&#039;s work... Same problem to me ... iptables v1.3.6: Couldn’t load match ... bla bla bla ...&lt;/p&gt;

&lt;p&gt;Other idea?&lt;/p&gt;
</description>
		<content:encoded><![CDATA[<p>Yes, maybe cool, maybe it&#8217;s work&#8230; Same problem to me &#8230; iptables v1.3.6: Couldn’t load match &#8230; bla bla bla &#8230;</p>
<p>Other idea?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Fredrick</title>
		<link>http://www.stupendous.net/archives/2009/01/24/dropping-spurious-nsin-recursive-queries/comment-page-1/#comment-9472</link>
		<dc:creator>Fredrick</dc:creator>
		<pubDate>Sat, 24 Jan 2009 12:34:25 +0000</pubDate>
		<guid isPermaLink="false">http://www.stupendous.net/?p=309#comment-9472</guid>
		<description>&lt;p&gt;OK, so I think, &quot;Great, I&#039;ll just add the iptables rule and have blessed silence in the logs!&quot;&lt;/p&gt;

&lt;p&gt;Not so fast, &quot;iptables v1.3.6: Couldn&#039;t load match `u32&#039;:/lib/iptables/libipt_u32.so: cannot open shared object file: No such file or directory.&quot;&lt;/p&gt;

&lt;p&gt;Grrrr.  OK, gonna have to do some work.  What is u32, hmmm aahhhh does byte comparison on IP headers.  Brilliant!  OK, now how do I get it....Doh!  Gotta patch the kernel and recompile!  From a ease of maintenance and repository management perspective, I don&#039;t want to build a custom kernel.&lt;/p&gt;

&lt;p&gt;Now what?!?  My logs are filling with this crap.  I guess I can just purge the logs, but would rather drop the DNS requests than handle them after the fact.&lt;/p&gt;

&lt;p&gt;I&#039;m running ubuntu Gutsy.  How did you get u32 working?&lt;/p&gt;
</description>
		<content:encoded><![CDATA[<p>OK, so I think, &#8220;Great, I&#8217;ll just add the iptables rule and have blessed silence in the logs!&#8221;</p>
<p>Not so fast, &#8220;iptables v1.3.6: Couldn&#8217;t load match `u32&#8242;:/lib/iptables/libipt_u32.so: cannot open shared object file: No such file or directory.&#8221;</p>
<p>Grrrr.  OK, gonna have to do some work.  What is u32, hmmm aahhhh does byte comparison on IP headers.  Brilliant!  OK, now how do I get it&#8230;.Doh!  Gotta patch the kernel and recompile!  From a ease of maintenance and repository management perspective, I don&#8217;t want to build a custom kernel.</p>
<p>Now what?!?  My logs are filling with this crap.  I guess I can just purge the logs, but would rather drop the DNS requests than handle them after the fact.</p>
<p>I&#8217;m running ubuntu Gutsy.  How did you get u32 working?</p>
]]></content:encoded>
	</item>
</channel>
</rss>
