Search Again:

Re: Spoofing (newbie needs help)

From: f.frassy
Date: Thursday, April 3, 2003
Time: 2:58:25 am

Thanks len, so as also a newbie, what is the difference between the two
querries below ?



Apr 3 12:35:38 Querying "192.26.92.30:53" about
"www.innocientmodels.com."
Apr 3 12:35:38 Reply: "www.innocientmodels.com." - from "192.26.92.30:53"


Apr 3 12:36:36 Query: "prv.endlessav.adultbouncer.com." - requested from
"mywebserverIP:49152"
Apr 3 12:36:36 Reply: "prv.endlessav.adultbouncer.com." - from
"64.237.38.105:53"

Do restricting zone transfert by ip will solve both ?
Using version 2, I have to had only the ip address of my secondary server ?
Thanks
FF






On 3/04/03 0:11, "Len Conrad" <LenConrad@MenAndMice.com> wrote:

>
>> As soon as I restricted ips it all stopped and went back to normal.
>
> If the attacker was trying to DoS you by sending lots of zone transfer
> requests that your unrestricted DNS was executing (which has nothing to do
> with "spoofing" of whatever), then restricting zone transfers by ip or by
> TSIG key would remove the DoS vulnerability.
>
> Len
>
>




Messages In This Thread:



Return to Digital Point Solutions' Home Page