<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Six impossible things &#187; networking</title>
	<atom:link href="http://www.milliways.fr/tag/networking/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.milliways.fr</link>
	<description>Obey Arthur Liu . blog()</description>
	<lastBuildDate>Mon, 26 Apr 2010 19:25:37 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.9.2</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>debian.org domainsquatted ? (1)</title>
		<link>http://www.milliways.fr/2008/06/11/debianorg-websquatted-1/</link>
		<comments>http://www.milliways.fr/2008/06/11/debianorg-websquatted-1/#comments</comments>
		<pubDate>Wed, 11 Jun 2008 16:56:23 +0000</pubDate>
		<dc:creator>Obey Arthur Liu</dc:creator>
				<category><![CDATA[debian]]></category>
		<category><![CDATA[networking]]></category>
		<category><![CDATA[request]]></category>

		<guid isPermaLink="false">http://www.milliways.fr/?p=20</guid>
		<description><![CDATA[
I was like &#8220;wtf?!&#8221;. Debian.org replaced by a link farm ?
debian.org being actually domainsquatted is highly unlikely, so I started searching how this could happen.
First, a little explanation of the setup :

I&#8217;m on a bullet train on my laptop, up-to-date Debian Lenny, 2.6.24
My laptop is connected to a 3G+ (HSDPA in the US) PDA phone [...]]]></description>
			<content:encoded><![CDATA[<p style="text-align: center;"><a title="debian.org domain squatted" rel="lightbox[pics20]" href="http://www.milliways.fr/wp-content/uploads/2008/06/debianorg.png"><img class="attachment wp-att-22 aligncenter" src="http://www.milliways.fr/wp-content/uploads/2008/06/debianorg.thumbnail.png" alt="debian.org domain squatted" width="480" height="341" /></a></p>
<p style="text-align: left;">I was like &#8220;wtf?!&#8221;. Debian.org replaced by a link farm ?</p>
<p style="text-align: left;">debian.org being actually domainsquatted is highly unlikely, so I started searching how this could happen.</p>
<p style="text-align: left;">First, a little explanation of the setup :</p>
<ul>
<li>I&#8217;m on a bullet train on my laptop, up-to-date Debian Lenny, 2.6.24</li>
<li>My laptop is connected to a 3G+ (HSDPA in the US) PDA phone with a USB cable</li>
<li>The phone appears to the computer as a network interface thanks to the usb-rndis-lite kernel module</li>
<li>The phone does NAT routing between my computer (192.168.0.100), himself (192.168.0.1) and a restricted network from my phone operator</li>
<li>The only host visible on this restricted network is a HTTP only proxy server that checks the user agent (Nokia is OK, Firefox means GO AWAY)</li>
<li>I connect through this proxy to a dedicated host through a OpenVPN tunnel masquerading as HTTP with a Nokia user agent</li>
<li>The dedicated host at the other side has special iptables rules to redirect requests coming from my mobile phone operator netblock on port 80 to the regular OpenVPN port.</li>
<li>The dedicated host does NAT for my computer to the <em>real </em>Internet.</li>
<li>The total latency varies from 120ms to 30 secs and the bandwidth from 2mbps to 8kbps depending on the coverage</li>
<li>The only DNS server on my laptop is set in resolv.conf to 192.168.5.1, the remote OpenVPN endpoint, the dedicated server</li>
<li>The dedicated server runs Bind and provides recursive resolution</li>
</ul>
<p>Now there are some peculiarities to the situation :</p>
<ul>
<li>It happens exactely once a week on the train from my home in Paris to the campus in Grenoble</li>
<li>It doesn&#8217;t happen the other way around or at any other time for that matter</li>
</ul>
<p>Some hints :</p>
<ul>
<li>My hostname at home is aeris.home.eu</li>
<li>My hostname on campus is aeris.liuo.res.rhb</li>
<li>I almost never shut down my computer, only hibernate</li>
<li>Jonathan Roes</li>
</ul>
<p>Now for the challenge : how could this happen ?</p>
]]></content:encoded>
			<wfw:commentRss>http://www.milliways.fr/2008/06/11/debianorg-websquatted-1/feed/</wfw:commentRss>
		<slash:comments>11</slash:comments>
		</item>
	</channel>
</rss>
