Subdomains Hack Attack?

Discussion in 'Site & Server Administration' started by donnareed, Oct 31, 2009.

  1. #1
    I have been seeing something troubling in my web logs in AWStats- my raw server logs also confirm it- which looks like DNS hi-jacking, and was wondering if anyone knows what this is or how to prevent it. It seems like someone has gained control of my DNS to add junk subdomains.

    In my logs I see referral traffic coming from urls that look like : evkklulksghfoejn.mydomain.com and wqwklqwoqpwqwhd.mydomain.com/page-on-my-site. It amounts to about 10 or so visits from each garbage subdomain, of which there look to be half a dozen per week. It is intermittent, happening only one or 2 days a week, at least so far.

    Visiting the url, the browser will show what seems like a redirect or frame of the non-subdomain equivalent of my site, so this is not referrer spam, at least not the usual type. This is on an Apache server, shared host, and the site is built with Drupal.

    So far my site has not lost any traffic, but I fear this could be the prelude to some sort of attempt to remove my site from the index via duplicate content. Any comments or advice would be appreciated as I’m not sure what category this falls in- DNS hijack, SQL injection, or scripting exploit.
     
    donnareed, Oct 31, 2009 IP
  2. chandan123

    chandan123 Prominent Member

    Messages:
    11,586
    Likes Received:
    578
    Best Answers:
    0
    Trophy Points:
    360
    #2
    why not disable catch all subdomain feature
     
    chandan123, Oct 31, 2009 IP
  3. kailash

    kailash Well-Known Member

    Messages:
    1,248
    Likes Received:
    42
    Best Answers:
    0
    Trophy Points:
    190
    #3
    You can remove wild-card DNS entry (* or @ record) for your domain.

    Kailash
     
    kailash, Nov 2, 2009 IP