Follows is a short exerpt of a log showing what I believe is
unauthorized use of my DNS:

Jul 20 18:26:07 Athelon named[21283]: client 148.160.29.10#34769: query:
sanitaetshaus-haeusner.de IN A +
Jul 20 18:29:16 Athelon named[21283]: client 148.160.29.6#33079: query:
btu-online.de IN NS +
Jul 20 18:29:19 Athelon named[21283]: client 148.160.29.10#34769: query:
nabu-krefeld-viersen.de IN A +
Jul 20 18:32:27 Athelon named[21283]: client 148.160.29.6#33079: query:
suburbia.de IN NS +
Jul 20 18:32:30 Athelon named[21283]: client 148.160.29.10#34769: query:
schwarzwaldmuseum.de IN A +
Jul 20 18:35:38 Athelon named[21283]: client 148.160.29.6#33079: query:
laus-miller.de IN NS +
Jul 20 18:35:42 Athelon named[21283]: client 148.160.29.10#34769: query:
more-db.de IN A +
Jul 20 18:36:48 Athelon named[21283]: client 65.110.190.249#11111:
query: ircchat.terra.cl IN A -


I do not have any reason for these addresses to be querying my DNS
except possibly as part of an attempt by them to breach security, if not
on my system, then to bypass security on their own network using my
system to provide them probing or other access they otherwise wouldn't
have.    If they were asking for information about *my* systems, for
instance, about mail or www, that would be legimitate querying of my
server from any external site, but for those same sites to request
information that requires that I query overseas is very suspicious.   

My question is how can I limit what external sites can query, ie, *I* or
my network machines may need to lookup any of those same queries (though
I can't see why at the moment), but external sites have no business
doing so.   External sites *may* have legitimate reasons to look up
certain public addresses like mail or www or similar information so I
can't just shut off  port 53 to outsiders.    I remember once upon a
time reading about this problem and a solution, but now, for the life of
me, I can't find it.    Any Ideas?

Thanks,
Richard

-- 
To unsubscribe, e-mail: [EMAIL PROTECTED]
For additional commands, e-mail: [EMAIL PROTECTED]

Reply via email to