[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: [cobalt-users] namedp1028] Denied Update from



We'll,

I have never used another DNS server. And this is one of my domain names
not a clients. Also this domain has three A records ns1.my domain.com,
ns2.my domain .com and www. my domain .com. I am also hosting
the DNS for this name. And I just noticed another one of my
domain names is starting to get a denied update from 162.40.174.159

Do you think this is a DoS attack?

Aug 22 11:11:30 ns4 named[1028]: denied update from [24.147.35.186].13980 for " My Domain .COM" Aug 22 11:11:31 ns4 named[1028]: denied update from [24.147.35.186].13986 for " My Domain .COM" Aug 22 11:11:31 ns4 named[1028]: denied update from [24.147.35.186].13992 for " My Domain .COM" Aug 22 11:11:35 ns4 named[1028]: denied update from [24.147.35.186].13998 for " My Domain .COM" Aug 22 11:11:35 ns4 named[1028]: denied update from [24.147.35.186].14004 for " My Domain .COM" Aug 22 11:11:36 ns4 named[1028]: denied update from [24.147.35.186].14010 for " My Domain .COM" Aug 22 11:11:36 ns4 named[1028]: denied update from [24.147.35.186].14016 for " My Domain .COM" Aug 22 11:11:37 ns4 named[1028]: denied update from [24.147.35.186].14022 for " My Domain .COM" Aug 22 11:11:37 ns4 named[1028]: denied update from [24.147.35.186].14028 for " My Domain .COM" Aug 21 17:26:45 ns4 named[1028]: denied update from [24.147.32.137].1036 for " My Domain .COM" Aug 21 18:26:47 ns4 named[1028]: denied update from [24.147.32.137].1202 for " My Domain .COM" Aug 21 19:26:48 ns4 named[1028]: denied update from [24.147.32.137].1245 for " My Domain .COM" Aug 21 20:26:50 ns4 named[1028]: denied update from [24.147.32.137].1286 for " My Domain .COM" Aug 21 21:26:52 ns4 named[1028]: denied update from [24.147.32.137].1327 for " My Domain .COM" Aug 21 22:26:53 ns4 named[1028]: denied update from [24.147.32.137].1358 for " My Domain .COM" Aug 22 10:19:44 ns4 named[1028]: denied update from [162.40.174.159].60527 for " My Other Domain.com" Aug 22 10:21:21 ns4 named[1028]: denied update from [162.40.174.159].60538 for " My Other Domain.com" Aug 22 10:21:53 ns4 named[1028]: denied update from [162.40.174.159].60553 for " My Other Domain.com" Aug 22 10:31:23 ns4 named[1028]: denied update from [162.40.174.159].60579 for " My Other Domain.com" Aug 22 10:31:54 ns4 named[1028]: denied update from [162.40.174.159].60591 for " My Other Domain.com" Aug 22 10:53:26 ns4 named[1028]: denied update from [162.40.174.159].60767 for " My Other Domain.com" Aug 22 10:58:28 ns4 named[1028]: denied update from [162.40.174.159].60824 for " My Other Domain.com"

Bill

At 01:11 PM 08/22/2002 -0400, you wrote:
The DNS server your were using before is attempting to update your current
DNS server..  This happens to us all the time when a client transfers from
another host to us..  Usually only if the last box was an MS box..  We have
that appearing in our logs right now because one of our clients had someone
else setup their intranet at their office and they setup the W2K DNS for
their local network with the same domain name as their website..  And we've
been trying for weeks now to tell them to change it, but you know how that
can be..  Tell your previous host to remove the DNS entry for the site if
you are now handling DNS...
-Jamie-