Re: Flood of bad DNS queries

From: Mike Lyman (mlyman-security_at_comcast.net)
Date: 12/04/03

  • Next message: Mike Lyman: "Re: Flood of bad DNS queries"
    To: incidents@securityfocus.com
    Date: Wed, 03 Dec 2003 19:49:54 -0600
    
    
    

    On Wed, 2003-12-03 at 14:41, Brett Glass wrote:
    > What worm or Trojan is causing this? What vulnerability is being attacked here?

    My guess is a newly installed 3DNS load balancer from F5. Back at
    Microsoft we used to get lots of reports of this. So much so that we
    contemplated many a late night mission into the data centers with wire
    cutters :-) (As the former abuse@microsoft.com, I got quite a few of
    the reports peronsally.)

    3DNS is fairly intrusive in its default configuration and uses DNS like
    traffic to try to determine which data center you are logically closest
    to and route you there. It also periodically retests even if no client
    in your network is currently connecting to the systems using 3DNS. Sets
    off lots of IDS and firewall alarms. It can be configured so that it
    does not set of so many alarms.

    -- 
    Mike Lyman
    pgp keyid 0xAB7F35DA
    
    



  • Next message: Mike Lyman: "Re: Flood of bad DNS queries"

    Relevant Pages

    • [Full-disclosure] Cisco Security Advisory: Cisco IOS Software Multiple Features IP Sockets Vulne
      ... Cisco IOS Software Multiple Features IP ... A vulnerability in the handling of IP sockets can cause devices to be ... The following example shows a vulnerable CAPF server configuration: ...
      (Full-Disclosure)
    • [NEWS] CBOS Web-based Configuration Utility Vulnerability
      ... CBOS Web-based Configuration Utility Vulnerability ... Multiple vulnerabilities have been identified and fixed in the Cisco ... No other releases of CBOS software are affected by this vulnerability. ... When the Cisco 600 series router is accessed via telnet via multiple ...
      (Securiteam)
    • RE: SecureIIS - protecting IIS
      ... How would you patch/harden your server ... Subject: SecureIIS - protecting IIS ... >::$DATA .asp file view source vulnerability. ... Actually a good configuration would have performed very well here. ...
      (Focus-Microsoft)
    • [NEWS] D-Link Access Point DWL-900AP+ TFTP Vulnerability
      ... The following security advisory is sent to the securiteam mailing list, and can be found at the SecuriTeam web site: http://www.securiteam.com ... vulnerability that could be exploited by a potential intruder to gain full ... - The network configuration data. ... the critical data) could be accessed world-wide. ...
      (Securiteam)
    • Re: Spyware and Adware affect every internet user
      ... removes the offending code. ... vulnerability is discovered. ... IE is 100% insecure, independent of configuration, without a new ... functionality or security requirements must be very low. ...
      (comp.security.misc)