Re: Odd source IP for a scan

From: David Goddard (dmg@procopia.com)
Date: 06/13/01


Date: Wed, 13 Jun 2001 20:47:30 +0100
From: David Goddard <dmg@procopia.com>
To: Alex Holst <a@area51.dk>

Alex Holst wrote:

> What's spoofed? Whoever owns 66.22.30.76 has told their DNS server to return
> "host.domain.com" when asked for a hostname.
> Query about 66.22.30.76 for record types PTR
> Name: host.domain.com
> Address: 66.22.30.76

Doh. Right - didn't occur to me. Should have done a whois first I
guess. Looks like these guys have that for the entire netblock. My
assumption was that host.domain.com really did exist and its IP was
chosen to be the default in some tool. Better mail them and let them
know they have a possible problem :-)

Thanks (and sorry for the b/w wastage),

Dave

To Unsubscribe: send mail to majordomo@FreeBSD.org
with "unsubscribe freebsd-security" in the body of the message



Relevant Pages

  • Re: Occassional/Unpredictable DNS Lookup failure
    ... program uses Windows Sockets to query the DNS for an A record of the ... hostname. ... The main point of the problem is that the DNS server will occassionally ...
    (microsoft.public.win2000.dns)
  • Re: Help w/ Not-booting Problem
    ... > To someone who has not encountered a door before it could be daunting. ... >>that you arrive at a shell or login prompt containing the hostname, ... >>inverse DNS resolution over the net from an external dns server. ... Tell us about your networking. ...
    (comp.os.linux.misc)
  • Re: Query ACL
    ... > query" statement available since bind 8... ... However there's a netmask feature ... ... the DNS Server service uses local subnet priority. ... Manage the discretionary access control list on DNS servers running ...
    (microsoft.public.win2000.dns)
  • Re: Netbios name resolves to "wrong domain"
    ... domain name gets automatically appended to the query and the preferred DNS ... how does it know how to reach all the other child domains? ... DNS server would return a FQDN that doesn't exist. ... > I've checked the domains that it's resolving to to make sure there's not a ...
    (microsoft.public.windows.server.dns)
  • Re: nslookup fails
    ... Does this DNS server have a Forwarder configured? ... > run a query to the forwarders IP address using ... > first query is making sure your DNS server can resolve the root servers to ...
    (microsoft.public.windows.server.dns)