Skip to Content.
Sympa Menu

discuss - Re: [opennic-discuss] New domain to watch out for abuse - ddostheinter.net

discuss AT lists.opennicproject.org

Subject: Discuss mailing list

List archive

Re: [opennic-discuss] New domain to watch out for abuse - ddostheinter.net


Chronological Thread 
  • From: Alex Hanselka <alex AT opennicproject.org>
  • To: discuss AT lists.opennicproject.org
  • Subject: Re: [opennic-discuss] New domain to watch out for abuse - ddostheinter.net
  • Date: Mon, 10 Jun 2013 11:51:15 -0500

Interesting. Since this is unlikely to be used for any real dns info
there is likely a way to just kill any packets requesting that (I suck
at iptables). Or perhaps just putting up an empty dummy zone.

On 6/10/2013 11:29 AM, staticsafe wrote:
> Hi all,
>
> Today I noticed an interesting query on my personal closed resolver:
>
> 12:15:25.224 client 89.248.172.173#52741: query: ddostheinter.net IN ANY
> +E
>
> As usual the reply to that ANY query is quite large, dig in fact
> truncated it and tried in TCP mode. I'm attaching the output from dig.
>
> Also note, that the domain was registered today:
> Date Registered: 2013-6-9
> Expiry Date: 2014-6-9
>




Archive powered by MHonArc 2.6.19.

Top of Page