Malicious DNS request?

Joe Shen joe_hznm at yahoo.com.sg
Thu May 12 08:11:35 UTC 2005


Hi,

In past days I noticed the nxdomain statistics in
named.stats keeps increasing.( I run it every 5 min)

By tcpdump, it's found a remote computer keep asking
address for record like
999d38e693b9e6293b450.0existence.com,
60d38e693b9e6293b450.0be6c1xfa.net. 

is that a virus affacted computer? 

How could such request be filtered or minimize its
affaction on DNS server?

regards

Joe

__________________________________________________
Do You Yahoo!?
Log on to Messenger with your mobile phone!
http://sg.messenger.yahoo.com



More information about the NANOG mailing list