Flood of bad DNS queries

From: Brett Glass (brett_at_lariat.org)
Date: 12/03/03

  • Next message: David Moisan: "RE: Anyone seen tgcmd.exe before?"
    Date: Wed, 03 Dec 2003 13:41:51 -0700
    To: incidents@securityfocus.com
    
    

    Our logs are filling with reports of bogus queries which ask machines to do reverse lookups on their own IP addresses (backwards, with .in-addr.arpa appended, as is the usual convention). The queries are being addressed to machines which are not domain name servers and/or are not intended to serve queries from the outside world.

    We're also seeing large numbers of requests to resolve ".".

    Ironically, many of these requests are coming from addresses such as 207.46.49.152,
    which belongs to MSN. (It's unclear whether machines at Microsoft have been
    infected, or if the queries are coming from a user logged into MSN.)

    What worm or Trojan is causing this? What vulnerability is being attacked here?

    --Brett Glass

    ---------------------------------------------------------------------------
    ----------------------------------------------------------------------------


  • Next message: David Moisan: "RE: Anyone seen tgcmd.exe before?"

    Relevant Pages

    • Re: Connection Filtering rejects all of the mail as on the Block list
      ... It's the DNS you're using that's different. ... resolve get filtered and ones that don't resolve go through. ... requests all returned requests, all of the mail was rejected. ... The DNS servers I had specified on the server having the issue ...
      (microsoft.public.exchange.admin)
    • Re: Confused.com
      ... period I've put in 3 requests for information and the 1st 2 resulted in no response at all, the last one was a bug/feature in Visual Studio 2003 a couple of years ago and was successfully resolved. ... MS was giving just about everyone with the problem a different way to resolve it, ...
      (uk.rec.cars.modifications)
    • Re: Suddenly Emails Bouncing
      ... > at msn.com and hotmail.com are bouncing with the error message "550 ... we are still working with the MSN team to resolve this error. ... source of spam and this being an action MSN is taking to reduce spam. ...
      (comp.os.linux.misc)
    • Re: Very Critical issue
      ... I would suggest you disable one of them and even if this doesn't resolve the issue I wouldn't ever have them setup on a dc. ... create forwarders in DNS so that requests for the a.com domain will be forwarded to the a.com DNS servers and b.com requests to the b.com forwarders. ...
      (microsoft.public.windows.server.active_directory)
    • RE: Hotmail Corruption
      ... resolve the issue? ... I've contacted my ISP, as well as MSN. ... but could not open any of my e-mails and could not navigate the page to ...
      (microsoft.public.security)