Search Again:

Re: Spoofing (newbie needs help)

From: Kerry Brys
Date: Wednesday, April 2, 2003
Time: 2:03:52 pm


>
>> I had an issue where the DNS servers I run were being attacked
>
> how?
My logs were going nuts with requests and no one inside or outside could
access any server that were being served by our DNS servers.
>
>> and after
>> talking to my ISP they called it "spoofing".
>
> spoofing the source address in UDP packets, DNS queries, is trivial.
>
>> I don't know if the term is
>> correct but I went into the "Access Restrictions" and clicked on "Restrict
>> Zone Transfers to" and typed in my secondary DNS servers name and did the
>> same for my Primary. Is this the correct thing to do?
>
> It is "a" correct thing to do, but it may or may not have anything to do
> with your attack.

As soon as I restricted ips it all stopped and went back to normal.
>
> Len
>
>




Messages In This Thread:



Return to Digital Point Solutions' Home Page