Re: Botnet Malware issue on bind BIND 9.7.1-P2

2011-12-05 Thread WBrown
jagan padhi wrote on 12/05/2011 12:16:19 PM: > First of all i would like to know what all these .ws domians.due to > this junk domain query CDNS servers load are getting very high. > > Yes There is a limit set in my CDND server,however out of 100 query > 60 queries are coming for these junk

Re: Botnet Malware issue on bind BIND 9.7.1-P2

2011-12-05 Thread jagan padhi
Yes Michael, First of all i would like to know what all these .*ws* domians.due to this junk domain query CDNS servers load are getting very high. Yes There is a limit set in my CDND server,however out of 100 query 60 queries are coming for these junk domains. I am running with BIND 9.7.1-P2 an

Re: Botnet Malware issue on bind BIND 9.7.1-P2

2011-12-05 Thread Michael Graff
I see many valid IP addresses in your list. But that said, are the responses going back "large" individually, or is it the number of them that is "large"? If you think this is attempting to crash the server with a single large answer, that's different than if your server is getting a lot of que

Re: Botnet Malware issue on bind BIND 9.7.1-P2

2011-12-05 Thread jagan padhi
> > Hi, > > There are huge request are coming frm the valid ip with .ws domain which > are not exist and causes degrade the server performance. > > > Thanks, > Jagan > > www3.cbox.ws.barnasinternational.com. (65) > 14:24:41.223958 IP 211.164.230.208.17125 > 103.145.184.40.domain: 64+ A? > mlv

Botnet Malware issue on bind BIND 9.7.1-P2

2011-12-05 Thread jagan padhi
Hi, Pls suggest on this. Thanks, Jagan www3.cbox.ws.barnasinternational.com. (65) 14:24:41.223958 IP 211.164.230.208.17125 > 103.145.184.40.domain: 64+ A? mlvabdz.ws. (28) 14:24:41.300652 IP 61.246.253.55.44111 > 208.73.210.76.domain: 47143 [1au] A? xoguzsdl.ws. (40) 14:24:41.338215 IP 211.1