Anyone else notice that name resolution doesn't appear to be working
right?  In other words, bogus / incorrect host names for IP's?  I've
noticed a number of IP's that don't resolve using nslookup, dig, whois,
etc. - yet nTop somehow reports them as; for example: www.bob.com.    I
have no idea how nTop is able to determine this?  Does it look into the
http request to map these?

What alerted me to this is a number of me local systems receiving a
large amount of data from "www.bob.com"  When I try to find out what
www.bob.com is, that's when the usual tools fail to return anything.

Thoughts?

Gary


===========================================================================





"This email is intended to be reviewed by only the intended recipient
 and may contain information that is privileged and/or confidential.
 If you are not the intended recipient, you are hereby notified that
 any review, use, dissemination, disclosure or copying of this email
 and its attachments, if any, is strictly prohibited.  If you have
 received this email in error, please immediately notify the sender by
 return email and delete this email from your system."

_______________________________________________
Ntop mailing list
[email protected]
http://listgateway.unipi.it/mailman/listinfo/ntop

Reply via email to