From owner-freebsd-questions@FreeBSD.ORG Thu Jun 4 01:59:35 2015 Return-Path: Delivered-To: freebsd-questions@freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2001:1900:2254:206a::19:1]) (using TLSv1.2 with cipher AECDH-AES256-SHA (256/256 bits)) (No client certificate requested) by hub.freebsd.org (Postfix) with ESMTPS id D8D5B3F6 for ; Thu, 4 Jun 2015 01:59:35 +0000 (UTC) (envelope-from bferrell@baywinds.org) Received: from rr-v.baywinds.org (50-196-187-248-static.hfc.comcastbusiness.net [50.196.187.248]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (Client did not present a certificate) by mx1.freebsd.org (Postfix) with ESMTPS id BF3AE1D87 for ; Thu, 4 Jun 2015 01:59:34 +0000 (UTC) (envelope-from bferrell@baywinds.org) Received: from [50.196.187.252] (50-196-187-252-static.hfc.comcastbusiness.net [50.196.187.252]) by rr-v.baywinds.org (8.14.4/8.14.4) with ESMTP id t5412qK1006139 for ; Wed, 3 Jun 2015 18:02:52 -0700 Message-ID: <556FA3BC.7010801@baywinds.org> Date: Wed, 03 Jun 2015 18:02:52 -0700 From: Bruce Ferrell User-Agent: Mozilla/5.0 (X11; Linux x86_64; rv:31.0) Gecko/20100101 Thunderbird/31.4.0 MIME-Version: 1.0 To: freebsd-questions@freebsd.org Subject: Re: port 53 under attack References: <556F87A6.8090105@a1poweruser.com> <1433375821.72071.40.camel@pki2.com> In-Reply-To: <1433375821.72071.40.camel@pki2.com> Content-Type: text/plain; charset=utf-8 Content-Transfer-Encoding: 7bit X-BeenThere: freebsd-questions@freebsd.org X-Mailman-Version: 2.1.20 Precedence: list List-Id: User questions List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Thu, 04 Jun 2015 01:59:35 -0000 On 06/03/2015 04:57 PM, Dennis Glatting wrote: > On Wed, 2015-06-03 at 19:03 -0400, joeb1 wrote: >> Hello list >> : >> My firewall blocks unsolicited inbound traffic on port 53. I realize >> this is the DNS port. But I am getting over 200K hits per day from ip >> addresses from all over the world. My host has a dynamic ip address. Is >> there any valid reason for this to be happening? > You could be used as a DOS amplifier. > > > > > _______________________________________________ > freebsd-questions@freebsd.org mailing list > http://lists.freebsd.org/mailman/listinfo/freebsd-questions > To unsubscribe, send any mail to "freebsd-questions-unsubscribe@freebsd.org" > Are you running an open DNS server?