Anyone else notice that name resolution doesn't appear to be working right? In other words, bogus / incorrect host names for IP's? I've noticed a number of IP's that don't resolve using nslookup, dig, whois, etc. - yet nTop somehow reports them as; for example: www.bob.com. I have no idea how nTop is able to determine this? Does it look into the http request to map these?
What alerted me to this is a number of me local systems receiving a large amount of data from "www.bob.com" When I try to find out what www.bob.com is, that's when the usual tools fail to return anything. Thoughts? Gary =========================================================================== "This email is intended to be reviewed by only the intended recipient and may contain information that is privileged and/or confidential. If you are not the intended recipient, you are hereby notified that any review, use, dissemination, disclosure or copying of this email and its attachments, if any, is strictly prohibited. If you have received this email in error, please immediately notify the sender by return email and delete this email from your system." _______________________________________________ Ntop mailing list [email protected] http://listgateway.unipi.it/mailman/listinfo/ntop
