Re: Strange DNS packets

From: Gianni Bragante (gbragante_at_libero.it)
Date: 01/10/04


Date: Sat, 10 Jan 2004 18:16:32 GMT

Thanks you for your message.
Yes I query several DNSRBL but incoming mail is handled by another SMTP
server at another address.
The packet in provided log are destined to the outgoing SMTP server.
Please also notice that those packet where discarded by the firewall, they
are not responses to outgoing queries.

Gianni Bragante

"Jem Berkes" <jb@users.pc9.org> ha scritto nel messaggio
news:Xns946C790218757jbuserspc9org@130.179.16.24...
> > Sometimes I find my iptables based firewall discards a large number of
> > DNS packet directed to the IP address of our mail server. This occurs
> > several times per day.
> > Sources are different IP addresses, each having at the same time the
> > same idea to query a non existent DNS. Anybody could explain that?
> > Does this happens to anybody else? Is this an attempted exploit of
> > something? Of what?
>
> Do you query DNSBLs (DNS blocklist) on your mail server? If so, I could
> imagine your mail server sending a DNS request to a number of RBL servers
> and getting the reply at pretty much the same time.
>
> --
> Jem Berkes
> http://www.sysdesign.ca/



Relevant Pages

  • Re: Rephrasing my UDP question
    ... DNS requests through TCP port 4242 on localhost which is tunneled through SSH ... to TCP port 4242 on the localhost of your shell server. ... When `server` gets a response from the real DNS server it forwards that packet through ... > I'm just really confused as to how these UDP-over-TCP tunnel programs know ...
    (comp.unix.programmer)
  • NT DNS forward server can not find 163.coms MX record in the cache.
    ... I am using a NT DNS server in my internal network, the query to DNS server ... "Standard query MX 163.com", then HQ's DNS returned "Standard query response ...
    (microsoft.public.windows.server.dns)
  • Re: SBS 2003 R2 MX and A records
    ... Now's about the time I'd be assuming control of the DNS records for the ... Query: stetsonbaptistchurch.org. ... The name server "ns2.siteprotect.com" refused to answer a query ... I am afraid the IT Lady just called the old hosting company ...
    (microsoft.public.windows.server.sbs)
  • Re: DNS
    ... If there is no name server at address $FOO, sending a DNS query will ... the resolver waits for a response ...
    (linux.redhat)
  • Re: DNS
    ... If there is no name server at address $FOO, sending a DNS query will ... the resolver waits for a response ...
    (linux.redhat)