
Tell-tale signs for the non-log watchers
This is the type of behaviour that has been filing my dns logs several times a second, at times from different IPs, for weeks now. the blocked ip list on my firewall grows by at least 2 new ip addresses every day.
31-Jan-2009 03:35:45.214 queries: client xxx.xxx.xxx.xxx#65233: query: . IN NS +
31-Jan-2009 03:35:45.214 security: client xxx.xxx.xxx.xxx#65233: query (cache) './NS/IN' denied
I had just finished blocking one IP at 10:00PM PST, then this and two other IPs started hitting me 2 hours later. It sucks. My DNS server is being used to generate traffic back to the sites being attacked through root queries in the form of denied dns messages, and all I can do is just keep blocking IPs. It' not slowing my traffic down at all. It's just time consuming and frustrating.