[28310] in North American Network Operators' Group
dns hits / 212.5.128/19 going wild
daemon@ATHENA.MIT.EDU (JP Donnio)
Tue Apr 25 08:44:45 2000
Message-ID: <00f301bfaeb3$b21d58f0$018227d4@cpod.fr>
From: "JP Donnio" <ml-nanog@TBS-internet.com>
To: <nanog@merit.edu>
Date: Tue, 25 Apr 2000 14:41:40 +0200
MIME-Version: 1.0
Content-Type: multipart/signed;
protocol="application/x-pkcs7-signature";
micalg=SHA1;
boundary="----=_NextPart_000_00EF_01BFAEC4.5F284180"
Errors-To: owner-nanog-outgoing@merit.edu
This is a multi-part message in MIME format.
------=_NextPart_000_00EF_01BFAEC4.5F284180
Content-Type: text/plain;
charset="iso-8859-1"
Content-Transfer-Encoding: 7bit
I am seeing a somewhat similar problem with my name server. It is configured
not to recurse queries except for our network. Since I enabled this feature,
I noticed we receive numerous requests from unauthorized hosts. It seems all
the unauthorized queries are MX requests for AOL.COM. Here's a sample
rejection log:
25-Apr-2000 12:21:48.647 security: unapproved recursive query from
[212.5.135.39].2091 for aol.com
and below the number of his for the last 4 days. Notice the 250,000 requests
from 212.5.135.39 That's really abusive and I have blackholed 212.5.128/19
for the moment.
1424 192.92.129.3
1332 193.200.17.87
516 193.68.3.250
399 208.226.167.19
70 212.5.133.129
635 212.5.135.16
250292 212.5.135.39
57 212.5.139.65
1286 212.5.159.42
28 212.5.159.53
71 212.56.18.66
58 212.91.173.60
1992 63.192.247.53
Now I do not understand why we are getting those hits. Our nameserver
(207.153.200.35) is not an aol.com secondary and has never been.
Does anyone have a clue?
JP
------=_NextPart_000_00EF_01BFAEC4.5F284180
Content-Type: application/x-pkcs7-signature;
name="smime.p7s"
Content-Transfer-Encoding: base64
Content-Disposition: attachment;
filename="smime.p7s"
MIAGCSqGSIb3DQEHAqCAMIACAQExCzAJBgUrDgMCGgUAMIAGCSqGSIb3DQEHAQAAoIIJVzCCAuUw
ggJOoAMCAQICAwDwMjANBgkqhkiG9w0BAQQFADCBuTELMAkGA1UEBhMCWkExFTATBgNVBAgTDFdl
c3Rlcm4gQ2FwZTEUMBIGA1UEBxMLRHVyYmFudmlsbGUxGjAYBgNVBAoTEVRoYXd0ZSBDb25zdWx0
aW5nMSkwJwYDVQQLEyBUaGF3dGUgUEYgUlNBIElLIDE5OTguOS4xNiAxNzo1NTE2MDQGA1UEAxMt
VGhhd3RlIFBlcnNvbmFsIEZyZWVtYWlsIFJTQSBJc3N1ZXIgMTk5OC45LjE2MB4XDTk5MDUyOTEw
MDEyOVoXDTAwMDUyODEwMDEyOVowcjEdMBsGA1UEAxMUSmVhbi1QaGlsaXBwZSBEb25uaW8xDzAN
BgNVBAQTBkRvbm5pbzEWMBQGA1UEKhMNSmVhbi1QaGlsaXBwZTEoMCYGCSqGSIb3DQEJARYZbWwt
bmFub2dAdGJzLWludGVybmV0LmNvbTCBnzANBgkqhkiG9w0BAQEFAAOBjQAwgYkCgYEAth+raFi/
30TSbMfYOUPRyafmxd4D7guuq9WYfoUIAnt/YFdbNrB79RVqZh0k4pjX8kMl3/C01nlguIBDdvUR
39N/D4ZL2EvAL0MY5A4FzJEFTYLaIWcceVqP03oqfRyamroN3G85HX696LMD08hEp8vUTQnEZ+Uq
wu6I1OF/px8CAwEAAaNBMD8wDgYDVR0PAQH/BAQDAgWgMAwGA1UdEwEB/wQCMAAwHwYDVR0jBBgw
FoAU/j5gnGuMD7DYM8bKxh5YsHE4teAwDQYJKoZIhvcNAQEEBQADgYEAT/U2w3E8KQENb/nshfB7
sIDdZvGJol6YF0CSQlS57+A+guNZH8Iv5SjAbJ0z6ahKzd2rnxcMTxpWI7dLwE5eKi7HOmy5smK2
XMCVdtKTNtXEafyaXY5/daJD4nP7kh3vtJQA/BSvSh4vAT4uydpcnZctGjC4bV/Og94rZMMYj8Uw
ggMtMIIClqADAgECAgEAMA0GCSqGSIb3DQEBBAUAMIHRMQswCQYDVQQGEwJaQTEVMBMGA1UECBMM
V2VzdGVybiBDYXBlMRIwEAYDVQQHEwlDYXBlIFRvd24xGjAYBgNVBAoTEVRoYXd0ZSBDb25zdWx0
aW5nMSgwJgYDVQQLEx9DZXJ0aWZpY2F0aW9uIFNlcnZpY2VzIERpdmlzaW9uMSQwIgYDVQQDExtU
aGF3dGUgUGVyc29uYWwgRnJlZW1haWwgQ0ExKzApBgkqhkiG9w0BCQEWHHBlcnNvbmFsLWZyZWVt
YWlsQHRoYXd0ZS5jb20wHhcNOTYwMTAxMDAwMDAwWhcNMjAxMjMxMjM1OTU5WjCB0TELMAkGA1UE
BhMCWkExFTATBgNVBAgTDFdlc3Rlcm4gQ2FwZTESMBAGA1UEBxMJQ2FwZSBUb3duMRowGAYDVQQK
ExFUaGF3dGUgQ29uc3VsdGluZzEoMCYGA1UECxMfQ2VydGlmaWNhdGlvbiBTZXJ2aWNlcyBEaXZp
c2lvbjEkMCIGA1UEAxMbVGhhd3RlIFBlcnNvbmFsIEZyZWVtYWlsIENBMSswKQYJKoZIhvcNAQkB
FhxwZXJzb25hbC1mcmVlbWFpbEB0aGF3dGUuY29tMIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKB
gQDUadfUsJRkW3HpR9gMUbbqcpGwhF59LQ2PexLfhSV1KHQ6QixjJ5+Ve0vvfhmHHYbqo925zpZk
GsIUbkSsfOaP6E0PcR9AOKYAo4d49vmUhl6t6sBeduvZFKNdbnp8DKVLVX8GGSl/npom1Wq7OCQI
apjHsdqjmJH9edvlWsQcuQIDAQABoxMwETAPBgNVHRMBAf8EBTADAQH/MA0GCSqGSIb3DQEBBAUA
A4GBAMfskn5O+PWWpWdiKqTwTRFg0G+NYFhhrCa7UjVcCM8w+6hKloofYkIjjBcP9LpknBesRynf
nZhe0mxgcVyirNx54+duAEcftQ0o6AKd5Jr9E/Sm2Xyx+NxfIyYJkYBz0BQb3kOpgyXy5pwvFcr+
pquKB3WLDN1RhGvk+NHOd6KBMIIDOTCCAqKgAwIBAgIBCjANBgkqhkiG9w0BAQQFADCB0TELMAkG
A1UEBhMCWkExFTATBgNVBAgTDFdlc3Rlcm4gQ2FwZTESMBAGA1UEBxMJQ2FwZSBUb3duMRowGAYD
VQQKExFUaGF3dGUgQ29uc3VsdGluZzEoMCYGA1UECxMfQ2VydGlmaWNhdGlvbiBTZXJ2aWNlcyBE
aXZpc2lvbjEkMCIGA1UEAxMbVGhhd3RlIFBlcnNvbmFsIEZyZWVtYWlsIENBMSswKQYJKoZIhvcN
AQkBFhxwZXJzb25hbC1mcmVlbWFpbEB0aGF3dGUuY29tMB4XDTk4MDkxNjE3NTUzNFoXDTAwMDkx
NTE3NTUzNFowgbkxCzAJBgNVBAYTAlpBMRUwEwYDVQQIEwxXZXN0ZXJuIENhcGUxFDASBgNVBAcT
C0R1cmJhbnZpbGxlMRowGAYDVQQKExFUaGF3dGUgQ29uc3VsdGluZzEpMCcGA1UECxMgVGhhd3Rl
IFBGIFJTQSBJSyAxOTk4LjkuMTYgMTc6NTUxNjA0BgNVBAMTLVRoYXd0ZSBQZXJzb25hbCBGcmVl
bWFpbCBSU0EgSXNzdWVyIDE5OTguOS4xNjCBnzANBgkqhkiG9w0BAQEFAAOBjQAwgYkCgYEAxKXl
1NTQXwgC7gchfSS/q2uOHusgBwIVhGuP0JMkHxud7miyuSxP6ZNnFxAXHqH5Q0EjuTCqdpe78+f9
gcC1MYv2plAmVPKVKOsZpB6XHrDiuJvBBJoy0DwJbE/kNU/wdr8AEwNPRQhg8/y00JABihLJnLp/
UuoqkzU2PDzkNS8CAwEAAaM3MDUwEgYDVR0TAQH/BAgwBgEB/wIBADAfBgNVHSMEGDAWgBRyScJz
NMZV9At2coF+d/SH58ayDjANBgkqhkiG9w0BAQQFAAOBgQAsx4IfAUM+B4/uaVypZIL4wJatkyvL
m1DXQJqBwrqmdp08lUDcVcHhVYJ5qwopptUM4VcoPo/5u9XfDZNYqlsti48z5N1YFTV2chUpvUL0
WpILd1+dJ9uaLU4bggaO0o1Wu5Xe2wxlBd6VngLdUxe+vvxrwxoiehQrYb3Cn156WjGCAiUwggIh
AgEBMIHBMIG5MQswCQYDVQQGEwJaQTEVMBMGA1UECBMMV2VzdGVybiBDYXBlMRQwEgYDVQQHEwtE
dXJiYW52aWxsZTEaMBgGA1UEChMRVGhhd3RlIENvbnN1bHRpbmcxKTAnBgNVBAsTIFRoYXd0ZSBQ
RiBSU0EgSUsgMTk5OC45LjE2IDE3OjU1MTYwNAYDVQQDEy1UaGF3dGUgUGVyc29uYWwgRnJlZW1h
aWwgUlNBIElzc3VlciAxOTk4LjkuMTYCAwDwMjAJBgUrDgMCGgUAoIG6MBgGCSqGSIb3DQEJAzEL
BgkqhkiG9w0BBwEwHAYJKoZIhvcNAQkFMQ8XDTAwMDQyNTEyNDE0MFowIwYJKoZIhvcNAQkEMRYE
FFO8vgSByB3zg3zj+QyLQo/h+J2nMFsGCSqGSIb3DQEJDzFOMEwwCgYIKoZIhvcNAwcwDgYIKoZI
hvcNAwICAgCAMA0GCCqGSIb3DQMCAgFAMAcGBSsOAwIHMA0GCCqGSIb3DQMCAgEoMAcGBSsOAwId
MA0GCSqGSIb3DQEBAQUABIGAfDf8c4gCnsDt2Km5yr1CzNLBVHcoezfUntDWRZVVQ6eg+8LeDj6m
JQsYWyvjIBrQgrrCYixz1kI4Wmb+Cj9bp2QkAnpd1lX+6orGeI6f/rCQS16ntJX6zMhteb/Upbn0
GdK6p5UsNSlWnRBRCQvyfUoYl/w1XTH2NlcnvkDtxw4AAAAAAAA=
------=_NextPart_000_00EF_01BFAEC4.5F284180--