Skip to Content.
Sympa Menu

discuss - Re: [opennic-discuss] New domain to watch out for abuse - ddostheinter.net

discuss AT lists.opennicproject.org

Subject: Discuss mailing list

List archive

Re: [opennic-discuss] New domain to watch out for abuse - ddostheinter.net


Chronological Thread 
  • From: Bersl <bersl2 AT bersl2.info>
  • To: discuss AT lists.opennicproject.org
  • Subject: Re: [opennic-discuss] New domain to watch out for abuse - ddostheinter.net
  • Date: Mon, 10 Jun 2013 12:03:03 -0500

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

On 06/10/2013 11:51 AM, Alex Hanselka wrote:
> Interesting. Since this is unlikely to be used for any real dns
> info there is likely a way to just kill any packets requesting that
> (I suck at iptables). Or perhaps just putting up an empty dummy
> zone.
>

I'm matching that domain with the following iptables rule fragment:

- -m string --hex-string "|0c64646f73746865696e746572036e657400|" --algo
kmp --to 65535 -j DROP

Since it might cause problems even over TCP/IP, I'm blocking both TCP
and UDP, as opposed to isc.org/IN/ANY.
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.12 (GNU/Linux)
Comment: Using GnuPG with Thunderbird - http://www.enigmail.net/

iQEcBAEBAgAGBQJRtgbAAAoJEKDJEQNczrCUkZ4H/A+ifkkwRrGHx4xltKWJGWW+
L0I79DIhcGiNADrxVz79fRkmv4IRfSKS3pjqZBsM1fFM336A6L/zUTlv7Vi2geCq
YmE4gCFDU9yz6BazW4jMf2V0CiaLAAQkLY/Hdy5In0aWYav+3Cpt2YvfbmN2zQ/F
R2J3SltGDUQ07xxgqr32zeH3t9VrEiY1yIXtbjO0UB2JCR9HZ+migrPmeQw6MZOy
H4DkdCIKYnMkpAVkAsDSkgU05zO0+ikFTNq7TISklUKBNrp1YhAvMZ70X7yr2E0S
NqgmO4vOXzRpGvlLnFLI3EcYy6vymUs7sOlrHNFiSqNE2UZD/h9ig07clHfOEHw=
=XAF/
-----END PGP SIGNATURE-----



Archive powered by MHonArc 2.6.19.

Top of Page