Re: Script-kiddie / client IP query (cache) 'host/MX/IN' denied

2010-08-11 Thread Barry Margolin
In article mailman.245.1280910538.15649.bind-us...@lists.isc.org, Matus UHLAR - fantomas uh...@fantomas.sk wrote: On 03.08.10 18:01, Denis BUCHER wrote: I have a question, it's not really a big problem, but it's annoying. In the logs I get plenty of lines like : client 202.152.172.4

Re: Script-kiddie / client IP query (cache) 'host/MX/IN' denied

2010-08-05 Thread Denis BUCHER
Yes I have a wonderful script doing that for SSH but not for iptables. For Bind, I must say that this problem appears 2-3 times a month, I can therefore manage it manually for the moment... Denis Le 04.08.2010 14:36, Sten Carlsen a écrit : You may want to consider how to trigger removal

Re: Script-kiddie / client IP query (cache) 'host/MX/IN' denied

2010-08-04 Thread Matus UHLAR - fantomas
On 03.08.10 18:01, Denis BUCHER wrote: I have a question, it's not really a big problem, but it's annoying. In the logs I get plenty of lines like : client 202.152.172.4 query (cache) 'denkstelle.de/MX/IN' denied: 1 Time(s) client 202.152.172.4 query (cache) 'denkstunde.de/MX/IN' denied: 2

Re: Script-kiddie / client IP query (cache) 'host/MX/IN' denied

2010-08-04 Thread Denis BUCHER
Le 03.08.2010 21:25, Kevin Darcy a écrit : I would like to know if I can block hosts doing that at the level of /etc/hosts.allow or should I do it at the level of Bind itself ? Use IPTables or add rules to your firewall. I don't believe that BIND pays any attention to /etc/hosts.allow Yes I

Re: Script-kiddie / client IP query (cache) 'host/MX/IN' denied

2010-08-04 Thread Sten Carlsen
You may want to consider how to trigger removal of this blocking when the problem has gone away and the address is again used responsibly. Maybe add a log statement with a limitation of one per day and checking that this is no longer seen for some time? IPTABLES can do the logging. On 04/08/10

Script-kiddie / client IP query (cache) 'host/MX/IN' denied

2010-08-03 Thread Denis BUCHER
Dear all, I have a question, it's not really a big problem, but it's annoying. In the logs I get plenty of lines like : client 202.152.172.4 query (cache) 'denkstelle.de/MX/IN' denied: 1 Time(s) client 202.152.172.4 query (cache) 'denkstunde.de/MX/IN' denied: 2 Time(s) client 202.152.172.4

Re: Script-kiddie / client IP query (cache) 'host/MX/IN' denied

2010-08-03 Thread Lyle Giese
Denis BUCHER wrote: Dear all, I have a question, it's not really a big problem, but it's annoying. In the logs I get plenty of lines like : client 202.152.172.4 query (cache) 'denkstelle.de/MX/IN' denied: 1 Time(s) client 202.152.172.4 query (cache) 'denkstunde.de/MX/IN' denied: 2 Time(s)

Re: Script-kiddie / client IP query (cache) 'host/MX/IN' denied

2010-08-03 Thread wllarso
On Tue, 03 Aug 2010 18:01:27 +0200, Denis BUCHER dbuche...@hsolutions.ch wrote: Dear all, I have a question, it's not really a big problem, but it's annoying. In the logs I get plenty of lines like : client 202.152.172.4 query (cache) 'denkstelle.de/MX/IN' denied: 1 Time(s) client

Script-kiddie : client IP query (cache) 'host/MX/IN' denied

2010-08-03 Thread Denis BUCHER
Dear all, I have a question, it's not really a big problem, but it's annoying. In the logs I get plenty of lines like : client 202.152.172.4 query (cache) 'denkstelle.de/MX/IN' denied: 1 Time(s) client 202.152.172.4 query (cache) 'denkstunde.de/MX/IN' denied: 2 Time(s) client 202.152.172.4

Re: Script-kiddie / client IP query (cache) 'host/MX/IN' denied

2010-08-03 Thread Denis BUCHER
Dear Lyle, Le 03.08.2010 18:17, Lyle Giese a écrit : I would like to know if I can block hosts doing that at the level of /etc/hosts.allow or should I do it at the level of Bind itself ? Use IPTables or add rules to your firewall. I don't believe that BIND pays any attention to

Re: Script-kiddie / client IP query (cache) 'host/MX/IN' denied

2010-08-03 Thread Denis BUCHER
Le 03.08.2010 18:28, wllarso a écrit : This seems to be due to a script-kiddie. I would like to know if I can block hosts doing that at the level of /etc/hosts.allow or should I do it at the level of Bind itself ? And sorry if this is not 100% on topic, I know it's at the border between BIND and

RE: Script-kiddie / client IP query (cache) 'host/MX/IN' denied

2010-08-03 Thread Dixon, Justin
I would like to know if I can block hosts doing that at the level of /etc/hosts.allow or should I do it at the level of Bind itself ? Use IPTables or add rules to your firewall. I don't believe that BIND pays any attention to /etc/hosts.allow BIND has a blackhole option that will essentially

RE: Script-kiddie / client IP query (cache) 'host/MX/IN' denied

2010-08-03 Thread Lightner, Jeff
BUCHER Sent: Tuesday, August 03, 2010 3:10 PM To: wllarso Cc: bind-us...@isc.org Subject: Re: Script-kiddie / client IP query (cache) 'host/MX/IN' denied Le 03.08.2010 18:28, wllarso a écrit : This seems to be due to a script-kiddie. I would like to know if I can block hosts doing

Re: Script-kiddie / client IP query (cache) 'host/MX/IN' denied

2010-08-03 Thread Kevin Darcy
On 8/3/2010 3:03 PM, Denis BUCHER wrote: Dear Lyle, Le 03.08.2010 18:17, Lyle Giese a écrit : I would like to know if I can block hosts doing that at the level of /etc/hosts.allow or should I do it at the level of Bind itself ? Use IPTables or add rules to your firewall. I don't believe that

RE: Script-kiddie / client IP query (cache) 'host/MX/IN' denied

2010-08-03 Thread Lightner, Jeff
@lists.isc.org [mailto:bind-users-bounces+jlightner=water@lists.isc.org] On Behalf Of Kevin Darcy Sent: Tuesday, August 03, 2010 3:26 PM To: bind-users@lists.isc.org Subject: Re: Script-kiddie / client IP query (cache) 'host/MX/IN' denied On 8/3/2010 3:03 PM, Denis BUCHER wrote: Dear Lyle, Le

Re: Script-kiddie / client IP query (cache) 'host/MX/IN' denied

2010-08-03 Thread Lyle Giese
Kevin Darcy wrote: On 8/3/2010 3:03 PM, Denis BUCHER wrote: Dear Lyle, Le 03.08.2010 18:17, Lyle Giese a écrit : I would like to know if I can block hosts doing that at the level of /etc/hosts.allow or should I do it at the level of Bind itself ? Use IPTables or add rules to your firewall. I

RE: Script-kiddie / client IP query (cache) 'host/MX/IN' denied

2010-08-03 Thread Lightner, Jeff
Sent: Tuesday, August 03, 2010 4:18 PM To: bind-users@lists.isc.org Subject: Re: Script-kiddie / client IP query (cache) 'host/MX/IN' denied Kevin Darcy wrote: On 8/3/2010 3:03 PM, Denis BUCHER wrote: Dear Lyle, Le 03.08.2010 18:17, Lyle Giese a écrit : I would like to know if I can block