|
|
 |  |
Re: Spoofing (newbie needs help)From: f.frassy Date: Thursday, April 3, 2003
Time: 2:58:25 amThanks len, so as also a newbie, what is the difference between the two
querries below ?
Apr 3 12:35:38 Querying "192.26.92.30:53" about
"www.innocientmodels.com."
Apr 3 12:35:38 Reply: "www.innocientmodels.com." - from "192.26.92.30:53"
Apr 3 12:36:36 Query: "prv.endlessav.adultbouncer.com." - requested from
"mywebserverIP:49152"
Apr 3 12:36:36 Reply: "prv.endlessav.adultbouncer.com." - from
"64.237.38.105:53"
Do restricting zone transfert by ip will solve both ?
Using version 2, I have to had only the ip address of my secondary server ?
Thanks
FF
On 3/04/03 0:11, "Len Conrad" <LenConrad@MenAndMice.com> wrote:
>
>> As soon as I restricted ips it all stopped and went back to normal.
>
> If the attacker was trying to DoS you by sending lots of zone transfer
> requests that your unrestricted DNS was executing (which has nothing to do
> with "spoofing" of whatever), then restricting zone transfers by ip or by
> TSIG key would remove the DoS vulnerability.
>
> Len
>
>
|

Return to Digital Point Solutions' Home Page |