Difference between revisions of "Denied DNS Requests"
From James Dooley's Wiki
(→Get all denied domains) |
|||
| Line 4: | Line 4: | ||
==Get top denied domains== | ==Get top denied domains== | ||
| − | < | + | <source lang='bash'> |
cat /var/log/messages | grep named | grep denied | cut -d "'" -f2 | cut -d "/" -f1 | sort | uniq -ci | sort -nr | head | cat /var/log/messages | grep named | grep denied | cut -d "'" -f2 | cut -d "/" -f1 | sort | uniq -ci | sort -nr | head | ||
| − | </ | + | </source> |
==Get all denied domains== | ==Get all denied domains== | ||
| − | < | + | <source lang='bash'> |
cat /var/log/messages | grep named | grep denied | cut -d "'" -f2 | cut -d "/" -f1 | sort | uniq -ci | sort -nr > /root/denied_dns.txt | cat /var/log/messages | grep named | grep denied | cut -d "'" -f2 | cut -d "/" -f1 | sort | uniq -ci | sort -nr > /root/denied_dns.txt | ||
| − | </ | + | </source> |
==Create dummy zone for top 10 domains== | ==Create dummy zone for top 10 domains== | ||
| Line 17: | Line 17: | ||
This will create a zone file using cPanels add_dns script and point it to 127.0.0.1 for the top 10 domains. | This will create a zone file using cPanels add_dns script and point it to 127.0.0.1 for the top 10 domains. | ||
| − | < | + | <source lang='bash'> |
cp -r /var/named /var/named.bak | cp -r /var/named /var/named.bak | ||
for domain in $(head /root/denied_dns.txt | awk '{print $2}' | sed 's/www\.//'); do echo "Adding $domain"; /scripts/add_dns --domain $domain --ip 127.0.0.1; done | for domain in $(head /root/denied_dns.txt | awk '{print $2}' | sed 's/www\.//'); do echo "Adding $domain"; /scripts/add_dns --domain $domain --ip 127.0.0.1; done | ||
| − | </ | + | </source> |
Revision as of 14:24, 25 March 2014
Contents
Overview
Find denied queries against DNS, good for finding sites that are no longer hosted or do not have valid DNS records.
Get top denied domains
cat /var/log/messages | grep named | grep denied | cut -d "'" -f2 | cut -d "/" -f1 | sort | uniq -ci | sort -nr | head
Get all denied domains
cat /var/log/messages | grep named | grep denied | cut -d "'" -f2 | cut -d "/" -f1 | sort | uniq -ci | sort -nr > /root/denied_dns.txt
Create dummy zone for top 10 domains
This will create a zone file using cPanels add_dns script and point it to 127.0.0.1 for the top 10 domains.
cp -r /var/named /var/named.bak
for domain in $(head /root/denied_dns.txt | awk '{print $2}' | sed 's/www\.//'); do echo "Adding $domain"; /scripts/add_dns --domain $domain --ip 127.0.0.1; done