[169207] in North American Network Operators' Group
Re: random dns queries with random sources
daemon@ATHENA.MIT.EDU (Joe Maimon)
Tue Feb 18 22:32:49 2014
Date: Tue, 18 Feb 2014 22:32:03 -0500
From: Joe Maimon <jmaimon@ttec.com>
To: Mark Andrews <marka@isc.org>
In-Reply-To: <20140219031740.06107FAB251@rock.dv.isc.org>
Cc: North American Networking and Offtopic Gripes List <nanog@nanog.org>
Errors-To: nanog-bounces+nanog.discuss=bloom-picayune.mit.edu@nanog.org
Mark Andrews wrote:
>> What is the purpose of this?
>
> Indirect attack on the 5kkx.com servers?
>
>> 18-Feb-2014 21:45:24.982 queries: info: client 38.89.3.12#19391: query:
>> swe.5kkx.com IN A + (66.199.132.5)
I have seen dozens of different second level parts.
How is this any more effective then sending it direct?