We've discovered two or three domain names that are configured to have OUR name 
servers as the SOA, but we don't know these people at all.

The three we know about are:

aim-leads.com
aimmailinglists.com
brickshirthouse.com

The only reason we discovered these is because of the errors in our DNS log that 
contain these names:

"The DNS server encountered a packet addressed to itself on IP address 69.59.142.6. 
The packet is for the DNS name "aim-leads.com.". The packet will be discarded. This 
condition usually indicates a configuration error." [snip]

My understanding is, this was most likely an attempt to hijack our DNS servers using 
cache corruption techniques -- techniques for which I believe we are protected and 
therefore not vulnerable.  These are obviously some sort of marketing names, for sales 
and/or email lists.

My two questions are:

1.  Do any of you have tests that you run on your DNS servers to verify they are not 
vulnerable to cache corruption?  If there are tests I can run to be sure we're okay, 
I'd love to hear about them.  We're running MS-DNS, with all service packs/patches 
applied, and proper settings in the DNS server.  From my tests using NSLOOKUP, our 
servers don't respond in any way to those names.

2.  Is there any course of action I can pursue to get these names to not point traffic 
to our name servers for their zone information, since we'll never have their zone info?

Thanks in advance for any input you offer.  This is off-topic from the standard iMail 
questions, so please feel free to contact me off-list.

Marc






To Unsubscribe: http://www.ipswitch.com/support/mailing-lists.html
List Archive: http://www.mail-archive.com/imail_forum%40list.ipswitch.com/
Knowledge Base/FAQ: http://www.ipswitch.com/support/IMail/

Reply via email to