Skip to Content.
Sympa Menu

discuss - Re: [opennic-discuss] Sharp increase in DNS traffic.

discuss AT lists.opennicproject.org

Subject: Discuss mailing list

List archive

Re: [opennic-discuss] Sharp increase in DNS traffic.


Chronological Thread 
  • From: Lars <jochimsen AT net4media.de>
  • To: discuss AT lists.opennicproject.org
  • Subject: Re: [opennic-discuss] Sharp increase in DNS traffic.
  • Date: Fri, 20 Jul 2012 13:52:43 +0000 (UTC)

Hi Jeff, hi Mike,

after fighting exactly this kind of traffic on one of our machines, I'm glad
to
see, that others fight with this trouble as well.

Here currently the traffic is (I think) spoofed to come from about 10-15
different IP-Adresses. Actually the queries are:

20-Jul-2012 15:37:26.063 client 81.218.214.225#80: query: li.mm.am IN TXT +E

I manually black-hole the IPs regularly, but this is a really boring job to do
and I am searching for a way, to limit this kind of traffic. As I can decrease
outgoing traffic by black-holing, I cannot really decrease the incoming
traffic.
I thought about using the /etc/hosts.deny file, but I haven't had the time to
dig deeper into the syntax.

Every hint is welcome - but up to now, I just wanted to let you know, that you
are not alone.

Best regards,
Lars




Archive powered by MHonArc 2.6.19.

Top of Page