Skip site navigation (1)Skip section navigation (2)
Date:      Tue, 06 Jun 2000 15:07:49 EDT
From:      "first name" <ejsilver49@hotmail.com>
To:        freebsd-questions@freebsd.org
Subject:   DNS DOS attack?  Probably not....
Message-ID:  <20000606190749.7705.qmail@hotmail.com>

next in thread | raw e-mail | index | archive | help

I run a DNS server for a small ISP.  In the middle of the night, our DNS 
server gets repeated requests for lookups from a small number of users.  One 
user might generate 100 to 150 DNS requests each minute.  Others might send 
50 to 75 requests per minute.

There is a core group that does this every night.  And an equal number of 
people send the repeated DNS requests off and on.  Most are forward lookups, 
but about 25% are reverse lookups.

Any idea what the hell they are doing?  DOS?  Cracking?  Trying to keep the 
connection nailed up?  Why would any program need to do 100 DNS lookups in a 
minute?  Could I have set up something wrong? Can't imagine what.

Thanks for any ideas or information.

EJ
________________________________________________________________________
Get Your Private, Free E-mail from MSN Hotmail at http://www.hotmail.com



To Unsubscribe: send mail to majordomo@FreeBSD.org
with "unsubscribe freebsd-questions" in the body of the message




Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?20000606190749.7705.qmail>