Malicious DNS request?
Joe Shen
joe_hznm at yahoo.com.sg
Thu May 12 08:11:35 UTC 2005
Hi,
In past days I noticed the nxdomain statistics in
named.stats keeps increasing.( I run it every 5 min)
By tcpdump, it's found a remote computer keep asking
address for record like
999d38e693b9e6293b450.0existence.com,
60d38e693b9e6293b450.0be6c1xfa.net.
is that a virus affacted computer?
How could such request be filtered or minimize its
affaction on DNS server?
regards
Joe
__________________________________________________
Do You Yahoo!?
Log on to Messenger with your mobile phone!
http://sg.messenger.yahoo.com
More information about the NANOG
mailing list