also @ TechSpot: Leaked next generation iPhone casing photos validate multiple rumors

TechSpot

Cannot access one website

Discussion in 'Virus and Malware Removal' started by annamarie, Mar 11, 2008.

Thread Status:
Not open for further replies.
  1. jobeard TechSpot Ambassador

    I'm interested! please show me the URL :)

    You know out of all the Hardware/Software/Windows/Spyware; IP configuration interests me the most (possible because I have so much to learn)

    But back to my point. Isn't this router issue, locally ?[/QUOTE]

    tracert uses the ping technique. The firewall or router ALLOWS or DENYS ping
    data, regardless of the IP address. Therefore, if you can get a ping reply with
    timing from one site, you can get it from ALL sites :)

    Getting a ping reply only says that a) the system is running,
    b) the interface is allowing ping replies. It does not say that the webserver is running
    and serving webpages on port 80.

    Sometimes our browsers get fouled up and misbehave -- so I'll show you how to
    prove a webserver IS serving pages.

    (for concrete, repeatable results, let's use www.google.com as the target site)
    1- find out if the system is running; ping www.google.com
    you should get four replies with timing info:
    Code:
    Reply from 74.125.19.99: bytes=32 time=40ms TTL=243
    2- access the site without a browser
    Code:
    get a command prompt (run->cmd)
    (blue lines are what you enter and green lines are what you get back)
    enter the following exactly
    [INDENT]
    [COLOR="Blue"]telnet www.google.com 80[/COLOR]
    [COLOR="Green"]Trying 74.125.19.103...
    Connected to www.l.google.com.
    Escape character is '^]'.[/COLOR]
    [COLOR="Blue"]GET / HTTP/1.0
    <enter key without any data>[/COLOR]
    
    [COLOR="Green"]HTTP/1.0 200 OK   [COLOR="DarkOrchid"]<<< the server produced a page[/COLOR]
    Cache-Control: private
    Content-Type: text/html; charset=ISO-8859-1
    Set-Cookie: PREF=ID=f3d4254c98c805c7:TM=1205352574:LM=1205352574:S=dH-5lezK1Lm0t
    KWm; expires=Fri, 12-Mar-2010 20:09:34 GMT; path=/; domain=.google.com
    Server: gws
    Date: Wed, 12 Mar 2008 20:09:34 GMT
    Connection: Close
    
    (and a bunch of html deleted for brevity)
    [/COLOR]
    [/INDENT]
    [/CODE]
    [/INDENT]
    
    so I attempted to access your site:
    [CODE]
    $[COLOR="Blue"] telnet 208.65.158.130 80[/COLOR]
    [COLOR="Green"]Trying 208.65.158.130...
    telnet: Unable to connect to remote host: [COLOR="Red"]Connection refused[/COLOR][/COLOR]
    [/CODE]
    [COLOR="Red"]The server located at 208.65.158.130 is not running![/COLOR]
    My firewall shows the access to the site (so it's not blocking port 80)
    
    Test#2
    [B]I forced the firewall to block this IP address on port 80[/B]
    [CODE]$ telnet 74.125.19.99 80
    Trying 74.125.19.99...
    telnet: Unable to connect to remote host: [COLOR="Red"]Connection timed out[/COLOR][/CODE]
    [B]Notice a blocked site gets a timeout, a non-running site gets Connection Refused[/B]
  2. Blind Dragon Newcomer, in training

    So like I was saying, shouldn't they try a different browser, I never got a response if this was in Internet Explorer
  3. jobeard TechSpot Ambassador

    from the above analysis, the specific browser is irrelevant -- the site is not reliable
    (ie comes and goes).

    as of 3/13/2008 15:44 PDT, the system is up (ie can be pinged)
    but the server is down (can't connect, connection refused)
  4. kimsland Ex-TechSpotter

    No it's not a browser issue (that's why it was not answered)

    Regarding 208.65.158.130
    http://www.lunarforums.com/lunarpages_webhosting_help/no_access_to_web-t46599.0.html

    OK so it must be blocked

    So is this a port 80 block? Actually I can't see that, because other sites work.

    Therefore this must be a site block, within the firewall (or maybe router, if individual sites can be blocked)

    So Jobeard what was your recommendation again?
    Why is 209.200.238.175:80 blocked here?

    It's up at the moment!
  5. jobeard TechSpot Ambassador

    Unable to connect to remote host: Connection refused
    server is not running

    Unable to connect to remote host: Connection timed out
    site is not running


    btw: Looks as if the IP address has changed
    ping www.designerdigitals.com

    Pinging www.designerdigitals.com [209.200.238.175] with 32
    Reply from 209.200.238.175: bytes=32 time=36ms TTL=50

    I was testing 208.65.158.130 which is now bogus :( sorry

    retesting on www.designerdigitals.com (209.200.238.175)
    works correctly today using the Telnet approach, IE url and FF as well

    I corrected the test as shown. However, the issue of
    blocking by a local firewall was addressed here
  6. kimsland Ex-TechSpotter

    I see

    annamarie please try tracert to 209.200.238.175 again, and post here
    I want to re-confirm your computer does not time out on any hop

    Start-->Run-->CMD
    tracert 209.200.238.175 <enter>

    Please paste the results back again
  7. LookinAround TechSpot Chancellor

    not sure it will give you the answer but try pathping instead of tracert to see both the route and check the "lossiness" between routers along the way (how many packets are typically being lost at each point)

    /** Edit **/
    Can give you a hint if you're actually just timing out due to a bad route

    /* Edit again lol.. */
    Actually, should have said it hints at bad router(s) along a good or bad route
  8. jobeard TechSpot Ambassador

    this site: 14 80 ms 80 ms 79 ms cust-lunarpages.marquisnet.com [208.65.158.130]
    is the last one in both your path and mine to the actual website at
    dlv00039.lunarservers.com [209.200.238.175]

    it is timing out

    1- if you can ping 209.200.238.175, the system is running
    2- if you can not fetch pages for any reason, the problem is the webserver and
    you can't do anything else

    having said that, I can ping AND fetch pages on 3/14/2008 @ 8:56 PDT

    apparently you have a persistent issue with the timeout???

    did you try the TELNET TRICK? this will eliminate all browser issues and leave
    only a question for your firewall blocking the specific site, ie
    209.200.238.175 on port 90

    Beyond that, I'm at a loss! :(
  9. LookinAround TechSpot Chancellor

    Well, below is the result of pathping. You'll find you have (well, i have) excellent connectivity with 0% packet loss between routers until point 9. Then 100% blockage between 9 <-> 10 which also means 10 <-> 11. I would read this as the problem with the router at 9 which, maybe not coincidentally, is the entry point to marquis.net. Why would the blockage indicate a problem with annamarie's firewall? For that matter, BOTH annamarie's AND MY firewalls vs. blockage at point 9?

    >pathping 209.200.238.175

    Code:
    Tracing route to dlv00039.lunarservers.com [209.200.238.175]
    over a maximum of 30 hops:
      0  DELL-600.cable.rcn.com [192.168.0.2]
      1  172.30.72.1
      2  vl2.aggr1.chgo.il.rcn.net [207.229.191.130]
      3  ge0-0-2.core1.chsl.il.rcn.net [207.172.19.41]
      4  ge3-0.border1.eqnx.il.rcn.net [207.172.19.39]
      5  equinixexchange-chi.cox.net [206.223.119.42]
      6  nwstdsrj02-ge710.rd.lv.cox.net [68.1.0.91]
      7  24-234-18-130.ptp.lvcm.net [24.234.18.130]
      8  24-234-18-130.ptp.lvcm.net [24.234.18.130]
      9  ge0502-csr1.lv1.marquisnet.com [208.110.166.6]
     10  cust-lunarpages.marquisnet.com [208.65.158.130]
     11  dlv00039.lunarservers.com [209.200.238.175]
    
    Computing statistics for 275 seconds...
                Source to Here   This Node/Link
    Hop  RTT    Lost/Sent = Pct  Lost/Sent = Pct  Address
      0                                           DELL-600.cable.rcn.com [192.168.0.2]
                                    0/ 100 =  0%   |
      1   12ms     0/ 100 =  0%     0/ 100 =  0%  172.30.72.1
                                    0/ 100 =  0%   |
      2   18ms     0/ 100 =  0%     0/ 100 =  0%  vl2.aggr1.chgo.il.rcn.net [207.229.191.130]
                                    0/ 100 =  0%   |
      3   13ms     0/ 100 =  0%     0/ 100 =  0%  ge0-0-2.core1.chsl.il.rcn.net [207.172.19.41]
                                    0/ 100 =  0%   |
      4   12ms     0/ 100 =  0%     0/ 100 =  0%  ge3-0.border1.eqnx.il.rcn.net [207.172.19.39]
                                    0/ 100 =  0%   |
      5   14ms     0/ 100 =  0%     0/ 100 =  0%  equinixexchange-chi.cox.net [206.223.119.42]
                                    0/ 100 =  0%   |
      6   72ms     0/ 100 =  0%     0/ 100 =  0%  nwstdsrj02-ge710.rd.lv.cox.net [68.1.0.91]
                                    0/ 100 =  0%   |
      7   73ms     0/ 100 =  0%     0/ 100 =  0%  24-234-18-130.ptp.lvcm.net [24.234.18.130]
                                    0/ 100 =  0%   |
      8   73ms     0/ 100 =  0%     0/ 100 =  0%  24-234-18-130.ptp.lvcm.net [24.234.18.130]
                                    0/ 100 =  0%   |
      9  ---     100/ 100 =100%   100/ 100 =100%  ge0502-csr1.lv1.marquisnet.com [208.110.166.6]
                                    0/ 100 =  0%   |
     10  ---     100/ 100 =100%   100/ 100 =100%  cust-lunarpages.marquisnet.com [208.65.158.130]
                                    0/ 100 =  0%   |
     11   75ms     0/ 100 =  0%     0/ 100 =  0%  dlv00039.lunarservers.com [209.200.238.175]
    
    Trace complete.
  10. jobeard TechSpot Ambassador

    my point has always been it is NOT a firewall issue but bad servers in the path.

    I give up!
  11. LookinAround TechSpot Chancellor

    OK.. So you and i are in violent agreement :grinthumb

    Had limited time and, admittedly, just skimmed through the thread without close attention to just who said what. Intent was to take a quick minute to gather and interpret the data from pingpath . (Have often found pingpath quite helpful when trying to figure out connectivity issues)

    Didn't mean to direct (or misdirect) my comments towards you (or anyone in particular) vs just drive home how I interpreted the data.
  12. jobeard TechSpot Ambassador

    I didn't take your comments personally :wave:

    read carefully the difference twix a blocked site and one that is not and respond with your opinion please :)
  13. LookinAround TechSpot Chancellor

    Responding to a few different things in the thread.

    joebeard
    To answer, i'll summarize my comments on your comments about differences when a site is blocked vs. not.

    For the most part I agree except for one part where i don't take "exception" with your statement so much as perhaps want to make a "clarification"
    • If a site’s not blocked, agreed, one would expect a data response to an http request (i.e. one sees a return http stream if both the site and web server are running vs. a “Connection Refused” message if the site is running but nothing is listening on port 80 to issue a reply.
    • If a site is blocked, agree again, one would expect a timeout. However, the reverse isn't true. If there’s no response (i.e. timeout) , it doesn't necessarily mean the site is blocked. While I would guess a blocked site is the most frequent/probable cause there are still other not-that-infrequent-to-be-overlooked reasons to consider as well.
    annamarie
    I believe you have an actionable item to get your problem resolved. But first, I’m gonna present some background/context of the business relationships involved (as I see it).. I think this will help you if you choose to report your problem for tech support. I think will also help provide context for some questions I’ll post to this thread later.

    Looking at the last 3 route hops (and associated hostnames) imply a relationship between the 3 companies. That relationship is clearer after some onine searching and, uhhhhh, lookin around.
    • www.digitaldesigners.com is web hosted by lunarpages.com. Lunarpages assigns the IP address to digitaldesigners’ web site. They also notify the Internet’s Domain Name System (DNS) upon assigning or changeing the IP address for digitaldesigner’s’ website. DNS is sort of the Internet’s phone book/directory assistance type-of-system.
    • lunarpages.com leases the servers it needs for its web hosting business. These servers are distributed across 3 physically separate data centers (see Data Center Information as described in link). Marquisnet.com owns and runs 2 of the centers.
    • annamarie your own business relationship would, of course, be as a user of digitaldesigns.com.
    I'm going to ask you to do one more thing first (instructions for it below) but at this point I think it’s reasonable to take your problem to digitaldesigners. (Others agree?) They, in turn, should be going to lunarpages and marquisnet. Provide digitaldesigners (a) Problem description (b) Copies of result of your ping, tracert and web site connect attempt. You can use their general “Contact us” form but probably best to try standard email address for a site's webmaster, in this case: webmaster@designerdigitals.com. Given info at hand, I also don’t see how the problem is your firewall or how it might be caused by a simple home router. (kimsland: I think i found the post you referred to. And altho i see what's said, i'm guessing the user either got a stock answer from tech support (which didn't apply to him) or he misunderstood an answer. But most important, it appears he posted his comment BEFORE trying to fix his problem. That was the end of the thread. No posts to indicate if the problem was actually fixed.)

    And finally (as this has become a loooong post and will followup later with some curiousities i saw maybe others can explain) before you contact webmaster, just to be certain to have all the right info/data for your problem, would appreciate if you could copy/paste all the error messages you receive when you try going to digitaldesign.com website. BETTER YET, could you capture your full screen and post it? Here's instructions if you don't know how.
    1. Start->All Programs->Accessories->Paint to open the Paint application
    2. Now, bring up the window with the error message when you try goint to digitaldesigns url.
    3. Press the Print Screen key on your keyboard (which might also be labled something like Prt Scr). This will copies an image of your computer screen onto the Windows clipboard.
    4. Now go back to the Paint window. Hit Edit->Paste to paste the screen image into Paint
    5. Hit File->Save As to get the SaveAs dialogue box. Fill in a filename. Click the down caret to get the Save As Type pull down menu and select JPEG then click Save.
    6. Post a reply to your TechSpot thread. When creating your TechSpot reply, insert the .jpeg file by clicking on the icon above message area second from right, looks like a postcard.

    /*** Edit ***/
    But maybe not so long i can't add one edit. annamarie, if only to be sure and remove any doubt (and is not difficult) is your router seperate hardware from your cable/dsl modem? can you plug the ethernet cable directly from computer to modem? One fyi gotcha.. some ISP will see the device change (your computer and router each have a unique ID your ISP can see) of what's connected to their modem and may stop communicating. If u see this problem, leave the modem disconnected for 5mins before reconnecting it to a different device. This should cause them to reset and accept the new device)
  14. LookinAround TechSpot Chancellor

    If annamarie doesn't mind me stealing some bandwith from the thread, I have a question i post for comments (joebeard: seems you have a networking background and appreciate your comment as well as appreciate comments from anyone else reading this).

    I posted my result for >pathping 209.200.238.175 a couple days ago. I've run it a couple times since and it continues to show 100% packet loss for the routers on marquisnet.com. ??Continued/repeatable 100% packet loss at these network routers?? No, not likely. So figured more likely the marquisnet routers are suppressing ICMP echo requests and just not sending a reply.

    But i see i can ping both marquisnet routers: 208.110.166.6 and 208.65.158.130.
    So, next step. I attach a network sniffer to capture/filter the packet data to maybe see what the heck is going on. I ran >pathping 209.200.238.175 and filtered the data to only display the ICMP packets. Attached files pingpath209.200.238.175.p1.txt and pingpath209.200.238.175.p2.txt are parts you should merge (I had to split due to size constraints). They're a comma delimited text file with one summary line per ICMP packet in my trace data. I believe you’ll find packet #18 is the first and only reply packet from 208.110.166.6 and #20 is the first and only from 208.65.158.130. Each one of these is a “Time to live exceeded in traffic” ICMP message.

    But if I run tracert I see each of marquisnet's routers sending back 3 ICMP time-to-live expired packets.. same as every other router on the path. I don’t get the difference between marquisnet’s response to the ICMP packets from pathping vs tracert and ping.

    Btw… I see ping generate a 74 byte ICMP packet including the Ethernet header. I see tracert and pathping both generate 106 byte ICMP packet with difference being all due to a larger 32 bytes for data in tracert and pathping.

    I think my question is independent of the original problem posted as I have no problem with ping or http connect to the website. What are the marquisnet routers doing? And, i just noticed, why does the returned route show the same IP at hop 7 and 8? (Tho at least the delay shown, if any, is equal or less then 0ms) Will have to see if this happened before and/or keeps happening.

    Here;s a pathping response again fyi
    Tracing route to dlv00039.lunarservers.com [209.200.238.175]
    over a maximum of 30 hops:
    0 DELL-600.cable.rcn.com [192.168.0.2]
    1 172.30.72.1
    2 vl2.aggr1.chgo.il.rcn.net [207.229.191.130]
    3 ge0-0-2.core1.chsl.il.rcn.net [207.172.19.41]
    4 ge3-0.border1.eqnx.il.rcn.net [207.172.19.39]
    5 equinixexchange-chi.cox.net [206.223.119.42]
    6 nwstdsrj02-ge710.rd.lv.cox.net [68.1.0.91]
    7 24-234-18-130.ptp.lvcm.net [24.234.18.130]
    8 24-234-18-130.ptp.lvcm.net [24.234.18.130]
    9 ge0502-csr1.lv1.marquisnet.com [208.110.166.6]
    10 cust-lunarpages.marquisnet.com [208.65.158.130]
    11 dlv00039.lunarservers.com [209.200.238.175]

    Computing statistics for 275 seconds...
    Source to Here This Node/Link
    Hop RTT Lost/Sent = Pct Lost/Sent = Pct Address
    0 DELL-600.cable.rcn.com [192.168.0.2]
    0/ 100 = 0% |
    1 12ms 1/ 100 = 1% 1/ 100 = 1% 172.30.72.1
    0/ 100 = 0% |
    2 19ms 0/ 100 = 0% 0/ 100 = 0% vl2.aggr1.chgo.il.rcn.net [207.229.191.130]
    0/ 100 = 0% |
    3 13ms 0/ 100 = 0% 0/ 100 = 0% ge0-0-2.core1.chsl.il.rcn.net [207.172.19.41]
    0/ 100 = 0% |
    4 13ms 0/ 100 = 0% 0/ 100 = 0% ge3-0.border1.eqnx.il.rcn.net [207.172.19.39]
    0/ 100 = 0% |
    5 15ms 1/ 100 = 1% 1/ 100 = 1% equinixexchange-chi.cox.net [206.223.119.42]
    0/ 100 = 0% |
    6 74ms 0/ 100 = 0% 0/ 100 = 0% nwstdsrj02-ge710.rd.lv.cox.net [68.1.0.91]
    0/ 100 = 0% |
    7 74ms 0/ 100 = 0% 0/ 100 = 0% 24-234-18-130.ptp.lvcm.net [24.234.18.130]
    0/ 100 = 0% |
    8 74ms 0/ 100 = 0% 0/ 100 = 0% 24-234-18-130.ptp.lvcm.net [24.234.18.130]
    1/ 100 = 1% |
    9 --- 100/ 100 =100% 99/ 100 = 99% ge0502-csr1.lv1.marquisnet.com [208.110.166.6]
    0/ 100 = 0% |
    10 --- 100/ 100 =100% 99/ 100 = 99% cust-lunarpages.marquisnet.com [208.65.158.130]
    0/ 100 = 0% |
    11 76ms 1/ 100 = 1% 0/ 100 = 0% dlv00039.lunarservers.com [209.200.238.175]
  15. jobeard TechSpot Ambassador

    actually we agree :)
Thread Status:
Not open for further replies.