Is Mercury retrograde or something?
Oct. 27th, 2009 07:25 amThis seems to be shaping up as a week of technology failure. First yesterday's mess at work, which is nowhere near resolved and will have library users throwing rocks through our windows soon because their free internet service is down, and now more this morning.
Mate's computer is in some sort of CHKDSK loop it seems. When booted, it announces that the hard drive is "dirty" and runs CHKDSK which reports no errors but when it gets to "verifying free space" it just seems to stop at 5%. Reboot and the cycle repeats itself.
Google seems to be utterly trashed this morning. Nothing Google related is accessible here. I've poked through DNS and found various apparent referral loops and dead ends. Were they hacked or did they do something to cause a massive failure? Hard to tell, since so much depends on them now. Everything is down.
Ever look at the results for "whois google.com" ?? What's with that? I dunno if you normally get such gibberish as GOOGLE.COM.ZZZZZ.GET.LAID.AT.WWW.SWINGINGCOMMUNITY.COM and GOOGLE.COM.ZOMBIED.AND.HACKED.BY.WWW.WEB-HACK.COM and many other such obnoxious entries or if this is a symptom of what's going on. Way down at the bottom you still find what should be the normal entry for google.com, though. Their own name servers are up, but all the public name servers I tried this morning couldn't locate www.google.com or mail.google.com or anything else in their domain.
Mate's computer is in some sort of CHKDSK loop it seems. When booted, it announces that the hard drive is "dirty" and runs CHKDSK which reports no errors but when it gets to "verifying free space" it just seems to stop at 5%. Reboot and the cycle repeats itself.
Google seems to be utterly trashed this morning. Nothing Google related is accessible here. I've poked through DNS and found various apparent referral loops and dead ends. Were they hacked or did they do something to cause a massive failure? Hard to tell, since so much depends on them now. Everything is down.
Ever look at the results for "whois google.com" ?? What's with that? I dunno if you normally get such gibberish as GOOGLE.COM.ZZZZZ.GET.LAID.AT.WWW.SWINGINGCOMMUNITY.COM and GOOGLE.COM.ZOMBIED.AND.HACKED.BY.WWW.WEB-HACK.COM and many other such obnoxious entries or if this is a symptom of what's going on. Way down at the bottom you still find what should be the normal entry for google.com, though. Their own name servers are up, but all the public name servers I tried this morning couldn't locate www.google.com or mail.google.com or anything else in their domain.
no subject
Date: 2009-10-27 12:43 pm (UTC)[Insert disclaimer here]
Registrant: Dns Admin Google Inc. Please contact contact-admin@google.com 1600 Amphitheatre Parkway Mountain View CA 94043 US dns-admin@google.com +1.6502530000 Fax: +1.6506188571 Domain Name: google.com Registrar Name: Markmonitor.com Registrar Whois: whois.markmonitor.com Registrar Homepage: http://www.markmonitor.com Administrative Contact: DNS Admin Google Inc. 1600 Amphitheatre Parkway Mountain View CA 94043 US dns-admin@google.com +1.6506234000 Fax: +1.6506188571 Technical Contact, Zone Contact: DNS Admin Google Inc. 2400 E. Bayshore Pkwy Mountain View CA 94043 US dns-admin@google.com +1.6503300100 Fax: +1.6506181499 Created on..............: 1997-09-15. Expires on..............: 2011-09-13. Record last updated on..: 2009-06-21. Domain servers in listed order: ns1.google.com ns2.google.com ns4.google.com ns3.google.comno subject
Date: 2009-10-27 12:52 pm (UTC); <<>> DiG 9.5.1-P2 <<>> www.google.com
;; global options: printcmd
;; Got answer:
;; ->>HEADER<<- opcode: QUERY, status: NOERROR, id: 63992
;; flags: qr rd ra; QUERY: 1, ANSWER: 7, AUTHORITY: 0, ADDITIONAL: 0
;; QUESTION SECTION:
;www.google.com. IN A
;; ANSWER SECTION:
www.google.com. 84987 IN CNAME www.l.google.com.
www.l.google.com. 479 IN A 64.233.169.147
www.l.google.com. 479 IN A 64.233.169.106
www.l.google.com. 479 IN A 64.233.169.104
www.l.google.com. 479 IN A 64.233.169.105
www.l.google.com. 479 IN A 64.233.169.103
www.l.google.com. 479 IN A 64.233.169.99
;; Query time: 1 msec
;; SERVER: 127.0.0.1#53(127.0.0.1)
;; WHEN: Tue Oct 27 08:46:54 2009
;; MSG SIZE rcvd: 148
jbadger@jbadger-08:46-~$ dig txt google.com
; <<>> DiG 9.5.1-P2 <<>> txt google.com
;; global options: printcmd
;; Got answer:
;; ->>HEADER<<- opcode: QUERY, status: NOERROR, id: 27602
;; flags: qr rd ra; QUERY: 1, ANSWER: 1, AUTHORITY: 0, ADDITIONAL: 0
;; QUESTION SECTION:
;google.com. IN TXT
;; ANSWER SECTION:
google.com. 3249 IN TXT "v=spf1 include:_netblocks.google.com ip4:216.73.93.70/31 ip4:216.73.93.72/31 ~all"
;; Query time: 22 msec
;; SERVER: 127.0.0.1#53(127.0.0.1)
;; WHEN: Tue Oct 27 08:49:13 2009
;; MSG SIZE rcvd: 122
jbadger@jbadger-08:49-~$ dig mx google.com
; <<>> DiG 9.5.1-P2 <<>> mx google.com
;; global options: printcmd
;; Got answer:
;; ->>HEADER<<- opcode: QUERY, status: NOERROR, id: 65265
;; flags: qr rd ra; QUERY: 1, ANSWER: 4, AUTHORITY: 0, ADDITIONAL: 0
;; QUESTION SECTION:
;google.com. IN MX
;; ANSWER SECTION:
google.com. 823 IN MX 10 google.com.s9b2.psmtp.com.
google.com. 823 IN MX 10 google.com.s9b1.psmtp.com.
google.com. 823 IN MX 10 google.com.s9a2.psmtp.com.
google.com. 823 IN MX 10 google.com.s9a1.psmtp.com.
;; Query time: 78 msec
;; SERVER: 127.0.0.1#53(127.0.0.1)
;; WHEN: Tue Oct 27 08:49:30 2009
;; MSG SIZE rcvd: 162
jbadger@jbadger-08:49-~$
no subject
Date: 2009-10-27 01:10 pm (UTC)Could it be your system (or your ISP's DNS server) is suffering some sort of DNS poisoning or malicious DNS-redirection?
no subject
Date: 2009-10-27 01:12 pm (UTC)no subject
Date: 2009-10-27 01:26 pm (UTC)no subject
Date: 2009-10-27 01:32 pm (UTC)For DNS, Google is resolving normally for me. I use OpenDNS, which I've always found reliable and simple. You don't have to sign up for an account unless you want to customize your DNS responses for stuff like typo correction and phish blocking. If you just use their servers with no account (208.67.222.222 and 208.67.220.220), you get your bog-standard DNS responses, quick and reliable. Which is why I memorized their servers. :) Always handy to have a known-good DNS server around.
no subject
Date: 2009-10-27 02:19 pm (UTC)no subject
Date: 2009-10-27 03:35 pm (UTC)Server Name: GOOGLE.COM.ZZZZZ.GET.LAID.AT.WWW.SWINGINGCOMMUNITY.COM
IP Address: 69.41.185.195
Registrar: TUCOWS INC.
Whois Server: whois.tucows.com
Referral URL: http://domainhelp.opensrs.net
Server Name: GOOGLE.COM.ZZZZZ.DOWNLOAD.MOVIE.ONLINE.ZML2.COM
IP Address: 64.28.187.63
Registrar: DIRECTI INTERNET SOLUTIONS PVT. LTD. D/B/A PUBLICDOMAINREGISTRY.COM
Whois Server: whois.PublicDomainRegistry.com
Referral URL: http://www.PublicDomainRegistry.com
Server Name: GOOGLE.COM.ZOMBIED.AND.HACKED.BY.WWW.WEB-HACK.COM
IP Address: 217.107.217.167
Registrar: DOMAINCONTEXT, INC.
Whois Server: whois.domaincontext.com
Referral URL: http://www.domaincontext.com
Server Name: GOOGLE.COM.ZNAET.PRODOMEN.COM
IP Address: 62.149.23.126
Registrar: DIRECTI INTERNET SOLUTIONS PVT. LTD. D/B/A PUBLICDOMAINREGISTRY.COM
Whois Server: whois.PublicDomainRegistry.com
Referral URL: http://www.PublicDomainRegistry.com
Server Name: GOOGLE.COM.WORDT.DOOR.VEEL.WHTERS.GEBRUIKT.SERVERTJE.NET
IP Address: 62.41.27.144
Registrar: KEY-SYSTEMS GMBH
Whois Server: whois.rrpproxy.net
Referral URL: http://www.key-systems.net
Server Name: GOOGLE.COM.VN
Registrar: ONLINENIC, INC.
Whois Server: whois.onlinenic.com
Referral URL: http://www.OnlineNIC.com
Server Name: GOOGLE.COM.UY
Registrar: DIRECTI INTERNET SOLUTIONS PVT. LTD. D/B/A PUBLICDOMAINREGISTRY.COM
Whois Server: whois.PublicDomainRegistry.com
Referral URL: http://www.PublicDomainRegistry.com
Server Name: GOOGLE.COM.UA
Registrar: DIRECTI INTERNET SOLUTIONS PVT. LTD. D/B/A PUBLICDOMAINREGISTRY.COM
Whois Server: whois.PublicDomainRegistry.com
Referral URL: http://www.PublicDomainRegistry.com
Server Name: GOOGLE.COM.TW
Registrar: WEB COMMERCE COMMUNICATIONS LIMITED DBA WEBNIC.CC
Whois Server: whois.webnic.cc
Referral URL: http://www.webnic.cc
Server Name: GOOGLE.COM.TR
Registrar: DIRECTI INTERNET SOLUTIONS PVT. LTD. D/B/A PUBLICDOMAINREGISTRY.COM
Whois Server: whois.PublicDomainRegistry.com
Referral URL: http://www.PublicDomainRegistry.com
Server Name: GOOGLE.COM.SUCKS.FIND.CRACKZ.WITH.SEARCH.GULLI.COM
IP Address: 80.190.192.24
Registrar: EPAG DOMAINSERVICES GMBH
Whois Server: whois.enterprice.net
Referral URL: http://www.enterprice.net
Server Name: GOOGLE.COM.SPROSIUYANDEKSA.RU
Registrar: MELBOURNE IT, LTD. D/B/A INTERNET NAMES WORLDWIDE
Whois Server: whois.melbourneit.com
Referral URL: http://www.melbourneit.com
Server Name: GOOGLE.COM.SERVES.PR0N.FOR.ALLIYAH.NET
IP Address: 84.255.209.69
Registrar: GODADDY.COM, INC.
Whois Server: whois.godaddy.com
Referral URL: http://registrar.godaddy.com
Server Name: GOOGLE.COM.IS.SHIT.SQUAREBOARDS.COM
IP Address: 203.170.84.81
Registrar: AUST DOMAINS INTERNATIONAL PTY LTD DBA AUST DOMAINS, INC.
Whois Server: whois.syra.com.au
Referral URL: http://www.syra.com.au
Server Name: GOOGLE.COM.IS.NOT.HOSTED.BY.ACTIVEDOMAINDNS.NET
IP Address: 217.148.161.5
Registrar: ENOM, INC.
Whois Server: whois.enom.com
Referral URL: http://www.enom.com
Server Name: GOOGLE.COM.IS.HOSTED.ON.PROFITHOSTING.NET
IP Address: 66.49.213.213
Registrar: NAME.COM LLC
Whois Server: whois.name.com
Referral URL: http://www.name.com
Server Name: GOOGLE.COM.IS.APPROVED.BY.NUMEA.COM
IP Address: 213.228.0.43
Registrar: GANDI SAS
Whois Server: whois.gandi.net
Referral URL: http://www.gandi.net
Server Name: GOOGLE.COM.HAS.LESS.FREE.PORN.IN.ITS.SEARCH.ENGINE.THAN.SECZY.COM
IP Address: 209.187.114.130
Registrar: TUCOWS INC.
Whois Server: whois.tucows.com
Referral URL: http://domainhelp.opensrs.net
...and more of the same
no subject
Date: 2009-10-27 03:37 pm (UTC)Google did come back up shortly after 8 am local time, and the problem was clearly DNS related.
no subject
Date: 2009-10-27 03:40 pm (UTC)I tried changing to half a dozen different DNS sources with the same results prior to that. It looked like it was internal to Google, where the generic names redirect to nodes at "l.google.com" and those addresses were not responding or redirecting back to the generic name.
At work now, and I still see the garbage in the whois response. I copied part of it above. See first reply.
no subject
Date: 2009-10-27 03:41 pm (UTC)no subject
Date: 2009-10-27 03:43 pm (UTC)no subject
Date: 2009-10-27 03:47 pm (UTC)Gary's machine seems to be running fine now. We went through [un]safe mode and it booted fine on the "use previous working configuration" option.
My suspicion is that Microsoft CHKDSK can't handle a primary drive the size of the one he's got in there now.
no subject
Date: 2009-10-27 03:49 pm (UTC)WHOIS is still full of garbage, but I think that's a separate issue since it doesn't directly affect the resolution. I quoted some of the trash above.
no subject
Date: 2009-10-27 04:08 pm (UTC)One explanation was that the query returns all domains with google.com in them, making it some sort of lame spamming attempt, but why is it that it only works some of the time...?
no subject
Date: 2009-10-27 04:10 pm (UTC)no subject
Date: 2009-10-27 05:44 pm (UTC)no subject
Date: 2009-10-27 06:02 pm (UTC)Unfortunately for the astrologers, that doesn't explain the current spate of failures here. Mercury turned back on September 17 and switched back to forward motion at the end of September. The period of "retrograde" ended on October 18 when the planet reached the same point in the zodiac at which its apparent motion reversed back in September. I went and checked this morning because there was so much coincidence of this stuff.
no subject
Date: 2009-10-27 06:17 pm (UTC)no subject
Date: 2009-10-27 06:24 pm (UTC)Very confusing.
no subject
Date: 2009-10-27 06:24 pm (UTC)no subject
Date: 2009-10-27 06:37 pm (UTC)no subject
Date: 2009-10-27 09:20 pm (UTC)no subject
Date: 2009-11-04 11:56 am (UTC)no subject
Date: 2009-11-04 12:06 pm (UTC)