ºìÁªLinuxÃÅ»§
Linux°ïÖú

¶¯ÊÖÑéÖ¤µçÐÅDNS½Ù³Ö¶ÔRBLµÄÓ°Ïì

·¢²¼Ê±¼ä:2007-08-01 13:54:55À´Ô´:ºìÁª×÷Õß:xuejin38
¶¯ÊÖÑéÖ¤µçÐÅDNS½Ù³Ö¶ÔRBLµÄÓ°Ïì


ǰ¶Îʱ¼äËó×ÓÓã·À»ðǽµÄRBLÅжϳöÏÖÒì³££¬Ëü½«ËùÓеÄIP£¨°×Ãûµ¥IP³ýÍ⣩¶¼ÅжϳÉÔÚºÚÃûµ¥ÄÚ£¬ÎÒÃÇʹÓõÄÊÇsbl.spamhaus.orgºÍxbl.spamhaus.org¡£Æð³õ»³ÒÉÊÇÆä·þÎñ³öÏÖÎÊÌ⣬ºóÀ´Ç¡·êDNS¸ùÓò·þÎñÆ÷ÔâÊܹ¥»÷£¬¶¼ÒÔΪÊǸùÓò·þÎñÆ÷µÄÓ°Ï죬¾ÍÔÝʱͣÓÃÁËrbl¹¦ÄÜ¡£µ«×î½ü·¢ÏÖÀ¬»øÓʼþÁ¿ÓÐËùÔö¼Ó£¬ºÍËó×ÓÓãÊۺ󹤳ÌʦÁªÏµºó£¬¸æÖªÊǵçÐÅdns½Ù³ÖµÄÔ­Òò¡£¸ü»»ÎªÎ´±»½Ù³ÖµÄDNSºóÎÊÌâ½â¾ö¡£ÓÉÓÚÒ»Ö±¶ÔrblµÄ¹¤×÷Ô­ÀíÀí½â²»ÊÇÌØ±ð͸³¹£¬ËùÒÔ¾öÐĸãÇå³þһϵ½µ×ÊÇÔõôӰÏìµÄ¡£
Ò»¡¢RBLµÄ¹¤×÷Ô­Àí£º¾Ýhttp://www.anti-spam.org.cn/refe ... ction=Show&ID=1µÄÃèÊö£¬rbl¹¤×÷²½ÖèΪ£º


QUOTE:
Èç¹ûÒªÅжÏÒ»¸öµØÖ·11.22.33.44ÊÇ·ñ±»ÁÐÈëÁ˺ÚÃûµ¥£¬ÄÇôʹÓúÚÃûµ¥·þÎñµÄÈí¼þ»á·¢³öÒ»¸öDNS²éѯµ½ºÚÃûµ¥·þÎñÆ÷£¨Èçcbl.anti-spam.org.cn£©£¬¸Ã²éѯÊÇÕâÑùµÄ£º²éÕÒ 44.33.22.11.cbl.anti-spam.org.cn ÊÇ·ñ´æÔÚA¼Ç¼£¿Èç¹û¸ÃµØÖ·±»ÁÐÈëÁ˺ÚÃûµ¥£¬ÄÇô·þÎñÆ÷»á·µ»ØÒ»¸öÓÐЧµØÖ·µÄ´ð°¸¡£°´ÕÕ¹ßÀý£¬Õâ¸öµØÖ·ÊÇ127.0.0.0/8ÄڵĵØÖ·Èç127.0.0.2£¨Ö®ËùÒÔʹÓÃÕâ¸öµØÖ·ÊÇÒòΪ127/8Õâ¸öµØÖ·¶Î±»±£ÁôÓÃÓÚ´ò»·²âÊÔ£¬³ýÁË127.0.0.1ÓÃÓÚ´ò»·µØÖ·£¬ÆäËüµÄµØÖ·¶¼¿ÉÒÔ±»ÓÃÀ´×öÕâ¸öʹÓ㬱ÈÈçÓÐʱºò»¹ÓÃ127.0.0.3µÈ¡££©¡£Èç¹ûûÓÐÁÐÈëºÚÃûµ¥£¬ÄÇô²éѯ»áµÃµ½Ò»¸ö·ñ¶¨»Ø´ð£¨NXDOMAIN£©¡£
ÀïÃæÓиö¹Ø¼üÎÊÌ⣨ºìÉ«×ÖÌ壩£º
1¡¢rbl²éѯµÄ½á¹ûÊÇÒ»¶¨ÒªÔÚ127.0.0.0/8ÄÚÂð£¿Èç¹û·µ»ØÀ´Ò»¸öÓÐЧµÄinternetµØÖ·»áÔõÑù£¨DNS½Ù³Ö·¢Éúʱ£©£¿
ÁíÍâÔö¼Ó¼¸¸öÐèҪŪÇå³þµÄÎÊÌ⣺
2¡¢µçÐŽٳÖdnsµÄÐÐΪ£¬ÔÚʲôÇé¿öϲŻᷢÉú£¿
3¡¢½Ù³ÖµÄÄ¿µÄIPÊÇʲô£¿IPµÄÊôÖ÷ÊÇË­£¿

¶þ¡¢×ÊÔ´ÐèÇó
Ê×ÏÈÐèÒªÕâÑùһЩ×ÊÔ´£º
»³Òɱ»½Ù³ÖµÄDNS IP: 202.96.209.6
δ±»½Ù³ÖµÄDNS IP: 202.96.199.133
ÔÚxbl.spamhaus.org»òsbl.spamhaus.orgµÄRBLÄÚµÄIP: 61.83.209.40
²»ÔÚxbl.spamhaus.org»òsbl.spamhaus.orgµÄRBLÄÚµÄIP: 219.239.89.18£¬211.150.96.22
¶ÔÕý³£ÓòÃûµÄ½âÎö: www.163.com

Èý¡¢¿ªÊ¼¶Ô±ÈÑéÖ¤£ºÓÉÓÚwindowsµÄnslookupʹÓò»Ì«·½±ã£¬ËùÒÔÔÚlinuxÖ÷»úÉÏʹÓÃdig£¬hostµÈÃüÁîÀ´²éѯ¡£
1¡¢ ÔÚδ±»½Ù³ÖµÄDNSÉÏ£¬¶ÔRBLÄÚµÄIP×öRBL²éѯ£¬Õý³£Çé¿öÏÂÓ¦¸Ã·µ»Ø127.0.0.0/8ÄڵĵØÖ·£º


QUOTE:
[root@mailtest2 tmp]# cat /etc/resolv.conf
nameserver 202.96.199.133

[root@mailtest2 tmp]# host 40.209.83.61.xbl.spamhaus.org
40.209.83.61.xbl.spamhaus.org has address 127.0.0.4

[root@mailtest2 tmp]# dig @202.96.199.133 40.209.83.61.xbl.spamhaus.org
¡­¡­¡­¡­¡­¡­¡­¡­¡­¡­ #Ê¡ÂÔ²¿·ÖÊä³ö
;; QUESTION SECTION:
;40.209.83.61.xbl.spamhaus.org. IN A

;; ANSWER SECTION:
40.209.83.61.xbl.spamhaus.org. 1758 IN A 127.0.0.4
¡­¡­¡­¡­¡­¡­¡­¡­¡­¡­ #Ê¡ÂÔ²¿·ÖÊä³ö
;; Query time: 10 msec
;; SERVER: 202.96.199.133#53(202.96.199.133)
;; WHEN: Wed Feb 28 11:42:34 2007
;; MSG SIZE rcvd: 466
·µ»ØÖµÕý³£¡£
2¡¢ ÔÚδ±»½Ù³ÖµÄDNSÉÏ£¬¶Ô²»ÔÚRBLÄÚµÄIP×öRBL²éѯ£¬Õý³£Çé¿öÏÂÓ¦¸Ã·µ»ØNXDOMAIN£»


QUOTE:
[root@mailtest2 tmp]# cat /etc/resolv.conf
nameserver 202.96.199.133

[root@mailtest2 tmp]# host 18.89.239.219.xbl.spamhaus.org
Host 18.89.239.219.xbl.spamhaus.org not found: 3(NXDOMAIN)
[root@mailtest2 tmp]# dig @202.96.199.133 18.89.239.219.xbl.spamhaus.org

; <<>> DiG 9.2.4rc6 <<>> @202.96.199.133 18.89.239.219.xbl.spamhaus.org
;; global options: printcmd
;; Got answer:
;; ->>HEADER<<- opcode: QUERY, status: NXDOMAIN, id: 48464
;; flags: qr rd ra; QUERY: 1, ANSWER: 0, AUTHORITY: 1, ADDITIONAL: 0

;; QUESTION SECTION:
;18.89.239.219.xbl.spamhaus.org. IN A

;; AUTHORITY SECTION:
xbl.spamhaus.org. 878 IN SOA need.to.know.only. hostmaster.spamhaus.org. 2007022814 3600 600 432000 900

;; Query time: 21 msec
;; SERVER: 202.96.199.133#53(202.96.199.133)
;; WHEN: Wed Feb 28 11:53:36 2007
;; MSG SIZE rcvd: 112


[root@mailtest2 tmp]# host 22.96.150.211.xbl.spamhaus.org
Host 22.96.150.211.xbl.spamhaus.org not found: 3(NXDOMAIN)
[root@mailtest2 tmp]# dig @202.96.199.133 22.96.150.211.xbl.spamhaus.org

; <<>> DiG 9.2.4rc6 <<>> @202.96.199.133 22.96.150.211.xbl.spamhaus.org
;; global options: printcmd
;; Got answer:
;; ->>HEADER<<- opcode: QUERY, status: NXDOMAIN, id: 27365
;; flags: qr rd ra; QUERY: 1, ANSWER: 0, AUTHORITY: 1, ADDITIONAL: 0

;; QUESTION SECTION:
;22.96.150.211.xbl.spamhaus.org. IN A

;; AUTHORITY SECTION:
xbl.spamhaus.org. 878 IN SOA need.to.know.only. hostmaster.spamhaus.org. 2007022823 3600 600 432000 900

;; Query time: 39 msec
;; SERVER: 202.96.199.133#53(202.96.199.133)
;; WHEN: Wed Feb 28 14:13:06 2007
;; MSG SIZE rcvd: 112
·µ»ØÕý³£¡£
3¡¢ ÔÚδ±»½Ù³ÖµÄDNSÉÏ£¬½âÎöÕý³£ÓòÃû£º


QUOTE:
[root@mailtest2 tmp]# cat /etc/resolv.conf
nameserver 202.96.199.133

[root@mailtest2 tmp]# host www.163.com
www.163.com is an alias for www.cache.split.netease.com.
www.cache.split.netease.com has address 220.181.31.184
www.cache.split.netease.com has address 220.181.28.50
www.cache.split.netease.com has address 220.181.28.51
www.cache.split.netease.com has address 220.181.28.52
www.cache.split.netease.com has address 220.181.28.53
www.cache.split.netease.com has address 220.181.28.54
www.cache.split.netease.com has address 220.181.31.182
www.cache.split.netease.com has address 220.181.31.183
[root@mailtest2 tmp]# dig @202.96.199.133 www.163.com
¡­¡­¡­¡­¡­¡­¡­¡­¡­¡­ #Ê¡ÂÔ²¿·ÖÊä³ö
;; QUESTION SECTION:
;www.163.com. IN A

;; ANSWER SECTION:
www.163.com. 11544 IN CNAME www.cache.split.netease.com.
www.cache.split.netease.com. 296 IN A 220.181.28.50
www.cache.split.netease.com. 296 IN A 220.181.28.51
www.cache.split.netease.com. 296 IN A 220.181.28.52
www.cache.split.netease.com. 296 IN A 220.181.28.53
www.cache.split.netease.com. 296 IN A 220.181.28.54
www.cache.split.netease.com. 296 IN A 220.181.31.182
www.cache.split.netease.com. 296 IN A 220.181.31.183
www.cache.split.netease.com. 296 IN A 220.181.31.184
¡­¡­¡­¡­¡­¡­¡­¡­¡­¡­ #Ê¡ÂÔ²¿·ÖÊä³ö

;; Query time: 6 msec
;; SERVER: 202.96.199.133#53(202.96.199.133)
;; WHEN: Wed Feb 28 11:58:23 2007
;; MSG SIZE rcvd: 127
·µ»ØÖµÕý³£¡£
4¡¢ ÔÚ»³Òɱ»½Ù³ÖµÄDNSÉÏ£¬¶ÔRBLÄÚµÄIP×öRBL²éѯ£¬Õý³£Çé¿öÏÂÓ¦¸Ã·µ»Ø127.0.0.0/8ÄڵĵØÖ·£º
[/quote]
[root@mailtest2 tmp]# cat /etc/resolv.conf
nameserver 202.96.209.6
[root@mailtest2 tmp]# host 40.209.83.61.xbl.spamhaus.org
40.209.83.61.xbl.spamhaus.org has address 127.0.0.4
[root@mailtest2 tmp]# dig @202.96.209.6 40.209.83.61.xbl.spamhaus.org
¡­¡­¡­¡­¡­¡­¡­¡­¡­¡­ #Ê¡ÂÔ²¿·ÖÊä³ö
;; QUESTION SECTION:
;40.209.83.61.xbl.spamhaus.org. IN A

;; ANSWER SECTION:
40.209.83.61.xbl.spamhaus.org. 839 IN A 127.0.0.4
¡­¡­¡­¡­¡­¡­¡­¡­¡­¡­ #Ê¡ÂÔ²¿·ÖÊä³ö

;; Query time: 7 msec
;; SERVER: 202.96.209.6#53(202.96.209.6)
;; WHEN: Wed Feb 28 13:35:13 2007
;; MSG SIZE rcvd: 466
[/quote]
·µ»ØÕý³£¡£
5¡¢ ÔÚ»³Òɱ»½Ù³ÖµÄDNSÉÏ£¬¶Ô²»ÔÚRBLÄÚµÄIP×öRBL²éѯ£¬Õý³£Çé¿öÏÂÓ¦¸Ã·µ»ØNXDOMAIN£»Öصã¾ÍÔÚÕâ¸öµØ·½ÁË


QUOTE:
[root@mailtest2 tmp]# host 18.89.239.219.xbl.spamhaus.org
18.89.239.219.xbl.spamhaus.org has address 218.83.175.154
[root@mailtest2 tmp]# dig @202.96.209.6 18.89.239.219.xbl.spamhaus.org

; <<>> DiG 9.2.4rc6 <<>> @202.96.209.6 18.89.239.219.xbl.spamhaus.org
;; global options: printcmd
;; Got answer:
;; ->>HEADER<<- opcode: QUERY, status: NOERROR, id: 54440
;; flags: qr rd ra; QUERY: 1, ANSWER: 1, AUTHORITY: 0, ADDITIONAL: 0

;; QUESTION SECTION:
;18.89.239.219.xbl.spamhaus.org. IN A

;; ANSWER SECTION:
18.89.239.219.xbl.spamhaus.org. 1800 IN A 218.83.175.154

;; Query time: 539 msec
;; SERVER: 202.96.209.6#53(202.96.209.6)
;; WHEN: Wed Feb 28 14:14:43 2007
;; MSG SIZE rcvd: 64


[root@mailtest2 tmp]# host 22.96.150.211.xbl.spamhaus.org
22.96.150.211.xbl.spamhaus.org has address 218.83.175.154
[root@mailtest2 tmp]# dig @202.96.209.6 22.96.150.211.xbl.spamhaus.org

; <<>> DiG 9.2.4rc6 <<>> @202.96.209.6 22.96.150.211.xbl.spamhaus.org
;; global options: printcmd
;; Got answer:
;; ->>HEADER<<- opcode: QUERY, status: NOERROR, id: 21397
;; flags: qr rd ra; QUERY: 1, ANSWER: 1, AUTHORITY: 0, ADDITIONAL: 0

;; QUESTION SECTION:
;22.96.150.211.xbl.spamhaus.org. IN A

;; ANSWER SECTION:
22.96.150.211.xbl.spamhaus.org. 1800 IN A 218.83.175.154

;; Query time: 831 msec
;; SERVER: 202.96.209.6#53(202.96.209.6)
;; WHEN: Wed Feb 28 14:16:24 2007
;; MSG SIZE rcvd: 64
¹ÖÁË£¬Ôõô½âÎö³öÀ´Ò»¸öÕý³£IPÁË£¿°ÑÕâ¸öIPÊäÈëµ½IEµØÖ·À¸£¬´ò¿ªÁËÕâ¸öÍøÒ³£º





¶øÇÒÔÙ¿ªÒ»¸ö´°¿ÚÔÙ´ò¿ªÒ»´Î£¬Ò³ÃæÓÖ»á±ä»¯£¡






6¡¢ ÔÚ»³Òɱ»½Ù³ÖµÄDNSÉϽâÎöÒ»¸öÕý³£µÄÓòÃû£º


QUOTE:
[root@mailtest2 tmp]# dig www.163.com

; <<>> DiG 9.2.4rc6 <<>> www.163.com
;; global options: printcmd
;; Got answer:
;; ->>HEADER<<- opcode: QUERY, status: NOERROR, id: 28059
;; flags: qr rd ra; QUERY: 1, ANSWER: 9, AUTHORITY: 2, ADDITIONAL: 2

;; QUESTION SECTION:
;www.163.com. IN A

;; ANSWER SECTION:
www.163.com. 11544 IN CNAME www.cache.split.netease.com.
www.cache.split.netease.com. 296 IN A 220.181.28.50
www.cache.split.netease.com. 296 IN A 220.181.28.51
www.cache.split.netease.com. 296 IN A 220.181.28.52
www.cache.split.netease.com. 296 IN A 220.181.28.53
www.cache.split.netease.com. 296 IN A 220.181.28.54
www.cache.split.netease.com. 296 IN A 220.181.31.182
www.cache.split.netease.com. 296 IN A 220.181.31.183
www.cache.split.netease.com. 296 IN A 220.181.31.184

;; AUTHORITY SECTION:
split.netease.com. 1196 IN NS ns-split1.netease.com.
split.netease.com. 1196 IN NS ns-split2.netease.com.

;; ADDITIONAL SECTION:
ns-split1.netease.com. 6260 IN A 202.106.168.79
ns-split2.netease.com. 5748 IN A 220.181.28.4

;; Query time: 6 msec
;; SERVER: 202.96.209.6#53(202.96.209.6)
;; WHEN: Fri Mar 2 10:17:55 2007
;; MSG SIZE rcvd: 275
½âÎöÕý³££»ÄѵÀÕâ¸öDNS°ÑËùÓнâÎö²»µ½µÄÓòÃû¶¼½Ù³Öµ½218.83.175.154£¿ÏÂÃæÑé֤һϣº
7¡¢ ÔÚ»³Òɱ»½Ù³ÖµÄDNSÉϽâÎöÒ»¸öαÔìµÄÓòÃû£º


QUOTE:
[root@mailtest2 tmp]# dig @202.96.209.6 false.163.com

; <<>> DiG 9.2.4rc6 <<>> @202.96.209.6 false.163.com
;; global options: printcmd
;; Got answer:
;; ->>HEADER<<- opcode: QUERY, status: NOERROR, id: 37904
;; flags: qr rd ra; QUERY: 1, ANSWER: 1, AUTHORITY: 0, ADDITIONAL: 0

;; QUESTION SECTION:
;false.163.com. IN A

;; ANSWER SECTION:
false.163.com. 1800 IN A 218.83.175.154

;; Query time: 263 msec
;; SERVER: 202.96.209.6#53(202.96.209.6)
;; WHEN: Wed Feb 28 14:33:41 2007
;; MSG SIZE rcvd: 47
8¡¢ 218.83.175.154Õâ¸öIPÊÇË­µÄ£¿


QUOTE:
[root@mailtest2 tmp]# whois 218.83.175.154
[Querying whois.apnic.net]
[whois.apnic.net]
% [whois.apnic.net node-1]
% Whois data copyright terms http://www.apnic.net/db/dbcopyright.html

inetnum: 218.78.0.0 - 218.83.255.255
netname: CHINANET-SH
descr: CHINANET Shanghai province network
descr: Data Communication Division
descr: China Telecom
country: CN
admin-c: CH93-AP
tech-c: XI5-AP
mnt-by: APNIC-HM
mnt-lower: MAINT-CHINANET-SH
mnt-routes: MAINT-CHINANET-SH
status: ALLOCATED PORTABLE
changed: hm-changed@apnic.net 20060427
source: APNIC

person: Chinanet Hostmaster
nic-hdl: CH93-AP
e-mail: anti-spam@ns.chinanet.cn.net
address: No.31 ,jingrong street,beijing
address: 100032
phone: +86-10-58501724
fax-no: +86-10-58501724
country: CN
changed: lqing@chinatelecom.com.cn 20051212
mnt-by: MAINT-CHINANET
source: APNIC

person: Wu Xiao Li
address: Room 805,61 North Si Chuan Road,Shanghai,200085,PRC
country: CN
phone: +86-21-63630562
fax-no: +86-21-63630566
e-mail: ip-admin@mail.online.sh.cn
nic-hdl: XI5-AP
mnt-by: MAINT-CHINANET-SH
changed: ip-admin@mail.online.sh.cn 20010510
source: APNIC
IPÊôÓÚÖйúµçÐÅ£¬ÏÔÈ»ÖØ¶¨Ïò³öÀ´µÄÍøÒ³Ò²ÊôÓÚÖйúµçÐÅ¡­¡­¡­¡­

ËÄ¡¢×ܽ᣺
¿ÉÒԵóö½áÂÛ£º¿É¶ñµÄµçÐÅÔÚÆä²¿·ÖDNSÉÏÉèÖÃÁ˹æÔò£ºËùÓнâÎö²»µ½µÄÓòÃû£¬¶¼·µ»Ø218.83.175.154Õâ¸öIP
Îå¡¢µçÐŵÄDNS½Ù³ÖÐÐΪ£¬ÔõÑùÓ°Ïìµ½RBLµÄ£¿
ÏÔ¶øÒ×¼û£¬ËùÓнâÎö²»µ½µÄÓòÃû£¬¶¼Óзµ»ØÖµ¡£ËäÈ»²»ÊÇ127.0.0.0/8Íø¶Î£¬µ«ÊÇÎÒµÄËó×ÓÓã·Å»ðǽÏÔȻûÓÐÀí»áÆäÖеÄÄÚÈÝ£¬ËùÒÔ×ÔÈ»¶øÈ»°ÑËùÓеÄIP¶¼ÅжÏΪºÚÃûµ¥ÁË£¨ÒòΪûÓÐÊÕµ½£¨NXDOMAIN£©£©£¡
ÎÄÕÂÆÀÂÛ

¹²ÓÐ 0 ÌõÆÀÂÛ