Re: Strange DNS queries



I am totally amazed at the number of email bounces I received from my single post to the list. I hardly post to large mailing lists anymore because I spend the next week deleting bounces.

A lot of lists have moved to trolling for bounces, is anyone doing that for this list?

Jason Lewis wrote:
This link has info.

http://deluvian.doxpara.com/


Alexander Klimov wrote:

We see some random DNS queries: 209.200.168.66 routinely asks us about

license.sunncomm2.com
connected.sonymusic.com
updates.xcp-aurora.com
r1x.myz.info
a.botdot.tk
brandonsisco.com
<some-base64-like-here>.deluvian.doxpara.com
<some-base64-like-here>.<digits-here>.maddns.net
etc.

And it looks like we are not the only target:
<http://www.google.com/search?q=%22209.200.168.66%22>

There are only few requests per hour, but this is a steady stream
since the beginning of the month (plus there was some portscan with
even slower rate).  We can easily block them by firewall, but it is
interesting what they actually try to acheive?

I know about sonymusic rootkit search, but what about the other sites?





Relevant Pages

  • Re: Is predictable spam filtering a vulnerability?
    ... Reasonably intelligent folk can manage with an archive-and-report mechanism ... if the RECIPIENT has opted to silently ... totally bogus addresses won't get bounces (not that the mail system won't ... As an administrator of several mailing lists, ...
    (Bugtraq)
  • Re: (1) OE msgs stuck -again- in outboxs! (2) How to reduce or compress photo msgs?
    ... Thank you very much, Brian. ... The following bounces also come with the same attachment which I quoted ... upper limit on the number of recipients an individual message can have ... into smaller mailing lists. ...
    (microsoft.public.windows.inetexplorer.ie6.outlookexpress)
  • Re: [Full-Disclosure] defamatory joe job attack by botnet
    ... I can only second Charles' and Isi's statements.... ... >> several bounces indicating that my email address is being used as the ... > and other security lists also. ... > and not their spoofed victims. ...
    (Full-Disclosure)
  • Re: Kernel list rejecting my email - braindead list
    ... We're not talking about isolated bounces. ... I am part of a lot of lists and I ... has as uch spam as this list does. ... Everyone is raving about the all-new Yahoo! ...
    (Linux-Kernel)
  • Re: OT: regex to find email
    ... >> all these regexes catch is unlikely to be exactly the set of all valid RFC ... > the perl faq is also required reading: ... September has dozens of bounces from no-longer-valid addresses that ... individually from the email containing big lists of bounced addresses. ...
    (comp.lang.python)