[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
RE: [cobalt-users] Possible DoS attack?
- Subject: RE: [cobalt-users] Possible DoS attack?
- From: cobalt@xxxxxxxxxxxxx
- Date: Mon Sep 29 09:12:00 2003
- List-id: Mailing list for users to share thoughts on Sun Cobalt products. <cobalt-users.list.cobalt.com>
> Sep 28 04:14:13 ns named[382]: Lame server on
'158.131.160.215.in-addr.arpa'
> (in '215.in-addr.arpa'?): [199.252.154.251].53 'aaa-vaihingen.nipr.mil':
> learnt (A=199.252.175.234,NS=193.0.14.129)
> i had loads of these entries in my logs from sunday morning. was this a
DoS
> attack?
> can anyone fill me in? i didn't seem to take my box down but is there
> anything i can do to prevent this?
Hi Andy,
I seem to be getting the same problem. Started a few days ago (26th
September).
My logs are usually very clean with the occasional "Lame Server" entry, but
now I'm getting 30 per hour.
I'm also getting the same entries as you, which seems to be more than a
coincidence.
---
Sep 29 07:52:23 ns named[9503]: Lame server on
'228.230.223.214.in-addr.arpa' (in '214.in-addr.arpa'?): [207.132.116.60].53
'aaa-vienna.nipr.mil'
---
This is occurring on 2 servers that are located at the same provider (Host
Europe), but not on other servers located elsewhere.
Regards
Andy