1. Advertising
    y u no do it?

    Advertising (learn more)

    Advertise virtually anything here, with CPM banner ads, CPM email ads and CPC contextual links. You can target relevant areas of the site and show ads based on geographical location of the user if you wish.

    Starts at just $1 per CPM or $0.10 per CPC.

Can someone explaine this to me about blasting my server?

Discussion in 'Security' started by TheSyndicate, Mar 27, 2012.

  1. #1
    I got this email from server admin after my server went down

    Mar 27 06:03:05 hel named[4101]: client 121.00.000.00#44916: view external: query (cache) 'asiomasbarato.com/ANY/IN' denied
    Mar 27 06:03:05 hel named[4101]: client 121.00.000.00#20212: view external: query (cache) 'asiomasbarato.com/ANY/IN' denied
    Mar 27 06:03:05 hel named[4101]: client 121.00.000.00#64946: view external: query (cache) 'asiomasbarato.com/ANY/IN' denied
    Mar 27 06:03:06 hel named[4101]: client 121.00.000.00#8043: view external: query (cache) 'asiomasbarato.com/ANY/IN' denied
    Mar 27 06:03:06 hel named[4101]: client 121.00.000.00#36552: view external: query (cache) 'asiomasbarato.com/ANY/IN' denied
    Mar 27 06:03:06 hel named[4101]: client 121.00.000.00#51791: view external: query (cache) 'asiomasbarato.com/ANY/IN' denied
    Mar 27 06:03:06 hel named[4101]: client 121.00.000.00#13761: view external: query (cache) 'asiomasbarato.com/ANY/IN' denied
    Mar 27 06:03:06 hel named[4101]: client 121.00.000.00#16878: view external: query (cache) 'asiomasbarato.com/ANY/IN' denied
    Mar 27 06:03:06 hel named[4101]: client 121.00.000.00#14069: view external: query (cache) 'asiomasbarato.com/ANY/IN' denied
    Mar 27 06:03:06 hel named[4101]: client 121.00.000.00#22224: view external: query (cache) 'asiomasbarato.com/ANY/IN' denied
    Mar 27 06:03:06 hel named[4101]: client 121.00.000.00#34433: view external: query (cache) 'asiomasbarato.com/ANY/IN' denied
    Mar 27 06:03:07 hel named[4101]: client 121.00.000.00#40595: view external: query (cache) 'asiomasbarato.com/ANY/IN' denied
    Mar 27 06:03:07 hel named[4101]: client 121.00.000.00#32194: view external: query (cache) 'asiomasbarato.com/ANY/IN' denied
    Mar 27 06:03:08 hel named[4101]: client 121.00.000.00#39628: view external: query (cache) 'asiomasbarato.com/ANY/IN' denied
    Mar 27 06:03:08 hel named[4101]: client 121.00.000.00#14005: view external: query (cache) 'asiomasbarato.com/ANY/IN' denied
    Mar 27 06:03:08 hel named[4101]: client 121.00.000.00#49983: view external: query (cache) 'asiomasbarato.com/ANY/IN' denied
    Mar 27 06:03:08 hel named[4101]: client 121.00.000.00#18362: view external: query (cache) 'asiomasbarato.com/ANY/IN' denied
    Mar 27 06:03:08 hel named[4101]: client 121.00.000.00#43431: view external: query (cache) 'asiomasbarato.com/ANY/IN' denied
    Mar 27 06:03:08 hel named[4101]: client 121.00.000.00#28072: view external: query (cache) 'asiomasbarato.com/ANY/IN' denied
    Mar 27 06:03:08 hel named[4101]: client 121.00.000.00#63364: view external: query (cache) 'asiomasbarato.com/ANY/IN' denied
    PHP:
    The output you are referring to, with regards to 'asiomasbarato.com' is a
    DNS query being targeted to your server for some (unknown) reason.

    That happens to be the request the external IP address is making of your server,
    hammering it with DNS queries. The previous admin has taken action against
    this behavior by blocking the IP.

    Does it mean this asiomasbarato.com is sending out that it is hosted at my server?
     
    TheSyndicate, Mar 27, 2012 IP
  2. madaboutlinux

    madaboutlinux Member

    Messages:
    250
    Likes Received:
    7
    Best Answers:
    2
    Trophy Points:
    43
    #2
    No, it means your server is queried for the DNS record of asiomasbarato.com. To avoid such issues, you should disable 'recursion' in the named configuration file. Edit /etc/named.conf and add the following in the "options" section

     
    madaboutlinux, Mar 29, 2012 IP
  3. TheSyndicate

    TheSyndicate Prominent Member

    Messages:
    5,410
    Likes Received:
    289
    Best Answers:
    0
    Trophy Points:
    365
    #3
    The server say the DNS will stop asking sooner or later.
     
    TheSyndicate, Mar 29, 2012 IP