Thanks nebulus200, that could explain the malformed DNS packets I have been getting... but it doesn't explain the infoleak exploit I'm seeing.
Oh and this weekend a new DNS attack was seen hitting two of my DNS servers. It's the DNS_solinger DoS attacks. Once again these are malformed packets, and for BIND 8.2.2 it will cause a 120 second denial of service before DNS resets itself. I'm going to start some recording and check these packets out to see if they match the info you passed me. Thanks once again![]()




Reply With Quote