• There seems to be an uptick in Political comments in recent months. Those of us who are long time members of the site know that Political and Religious content has been banned for years. Nothing has changed. Please leave all political and religious comments out of the forums.

    If you recently joined the forums you were not presented with this restriction in the terms of service. This was due to a conversion error when we went from vBulletin to Xenforo. We have updated our terms of service to reflect these corrections.

    Please note any post refering to a politician will be considered political even if it is intended to be humor. Our experience is these topics have a way of dividing the forums and causing deep resentment among members. It is a poison to the community. We appreciate compliance with the rules.

    The Staff of SOH

  • Server side Maintenance is done. We still have an update to the forum software to run but that one will have to wait for a better time.

new attack

Ickie

SOH Administrator
While monitoring the server I can see that the “named” service is using high CPU usage. I have found lots of questions are sent from multiple IP’s. This seems a DNS amplification attack. This attack is a type of distributed denial of service (DDos) attack that takes advantage of the fact that a small DNS question can generate a much larger response. When combined with source address spoofing, an attacker can direct a large volume of network traffic to a target system by initiating relatively small DNS questions.

here are the ip's and where they are coming from

192.126.118.105
174.139.237.142
70.39.67.110
199.115.102.83
173.234.39.133


hccforums.nl
ietf.org
 
sample of the attack to let you know, this log is 100 times bigger than I am posting and all was being done by them 5 IP's

09-Feb-2014 14:08:27.227 queries: info: client 192.126.118.105#5209: query: ietf.org IN ANY +E
09-Feb-2014 14:08:27.228 queries: info: client 174.139.237.142#5209: query: hccforums.nl IN ANY +E
09-Feb-2014 14:08:27.228 queries: info: client 174.139.237.142#5209: query: hccforums.nl IN ANY +E
09-Feb-2014 14:08:27.228 queries: info: client 174.139.237.142#5209: query: hccforums.nl IN ANY +E
09-Feb-2014 14:08:27.229 queries: info: client 174.139.237.142#5209: query: hccforums.nl IN ANY +E
09-Feb-2014 14:08:27.229 queries: info: client 174.139.237.142#5209: query: hccforums.nl IN ANY +E
09-Feb-2014 14:08:27.229 queries: info: client 174.139.237.142#5209: query: hccforums.nl IN ANY +E
09-Feb-2014 14:08:27.229 queries: info: client 174.139.237.142#5209: query: hccforums.nl IN ANY +E
09-Feb-2014 14:08:27.229 queries: info: client 174.139.237.142#5209: query: hccforums.nl IN ANY +E
09-Feb-2014 14:08:27.229 queries: info: client 192.126.118.105#5209: query: ietf.org IN ANY +E
09-Feb-2014 14:08:27.229 queries: info: client 192.126.118.105#5209: query: ietf.org IN ANY +E
09-Feb-2014 14:08:27.229 queries: info: client 174.139.237.142#5209: query: hccforums.nl IN ANY +E
09-Feb-2014 14:08:27.229 queries: info: client 174.139.237.142#5209: query: hccforums.nl IN ANY +E
09-Feb-2014 14:08:27.230 queries: info: client 192.126.118.105#5209: query: ietf.org IN ANY +E
09-Feb-2014 14:08:27.230 queries: info: client 192.126.118.105#5209: query: ietf.org IN ANY +E
09-Feb-2014 14:08:27.230 queries: info: client 174.139.237.142#5209: query: hccforums.nl IN ANY +E
09-Feb-2014 14:08:27.230 queries: info: client 192.126.118.105#5209: query: ietf.org IN ANY +E
09-Feb-2014 14:08:27.230 queries: info: client 174.139.237.142#5209: query: hccforums.nl IN ANY +E
09-Feb-2014 14:08:27.230 queries: info: client 174.139.237.142#5209: query: hccforums.nl IN ANY +E
09-Feb-2014 14:08:27.230 queries: info: client 174.139.237.142#5209: query: hccforums.nl IN ANY +E
09-Feb-2014 14:08:27.230 queries: info: client 174.139.237.142#5209: query: hccforums.nl IN ANY +E
09-Feb-2014 14:08:27.231 queries: info: client 70.39.67.110#5209: query: hccforums.nl IN ANY +E
09-Feb-2014 14:08:27.231 queries: info: client 192.126.118.105#5209: query: ietf.org IN ANY +E
09-Feb-2014 14:08:27.231 queries: info: client 70.39.67.110#5209: query: hccforums.nl IN ANY +E
09-Feb-2014 14:08:27.231 queries: info: client 70.39.67.110#5209: query: hccforums.nl IN ANY +E
09-Feb-2014 14:08:27.232 queries: info: client 70.39.67.110#5209: query: hccforums.nl IN ANY +E
09-Feb-2014 14:08:27.232 queries: info: client 70.39.67.110#5209: query: hccforums.nl IN ANY +E
09-Feb-2014 14:08:27.232 queries: info: client 174.139.237.142#5209: query: hccforums.nl IN ANY +E
09-Feb-2014 14:08:27.232 queries: info: client 174.139.237.142#5209: query: hccforums.nl IN ANY +E
09-Feb-2014 14:08:27.232 queries: info: client 174.139.237.142#5209: query: hccforums.nl IN ANY +E
09-Feb-2014 14:08:27.232 queries: info: client 174.139.237.142#5209: query: hccforums.nl IN ANY +E
09-Feb-2014 14:08:27.232 queries: info: client 174.139.237.142#5209: query: hccforums.nl IN ANY +E
09-Feb-2014 14:08:27.237 queries: info: client 173.234.39.133#5209: query: hccforums.nl IN ANY +E
09-Feb-2014 14:08:27.238 queries: info: client 173.234.39.133#5209: query: hccforums.nl IN ANY +E
09-Feb-2014 14:08:27.238 queries: info: client 173.234.39.133#5209: query: hccforums.nl IN ANY +E
09-Feb-2014 14:08:27.238 queries: info: client 173.234.39.133#5209: query: hccforums.nl IN ANY +E
09-Feb-2014 14:08:27.239 queries: info: client 173.234.39.133#5209: query: hccforums.nl IN ANY +E
09-Feb-2014 14:08:27.239 queries: info: client 199.115.102.83#5209: query: ietf.org IN ANY +E
09-Feb-2014 14:08:27.239 queries: info: client 199.115.102.83#5209: query: ietf.org IN ANY +E
09-Feb-2014 14:08:27.239 queries: info: client 199.115.102.83#5209: query: ietf.org IN ANY +E
09-Feb-2014 14:08:27.240 queries: info: client 199.115.102.83#5209: query: ietf.org IN ANY +E
09-Feb-2014 14:08:27.240 queries: info: client 199.115.102.83#5209: query: ietf.org IN ANY +E
09-Feb-2014 14:08:27.241 queries: info: client 199.115.102.83#5209: query: ietf.org IN ANY +E
09-Feb-2014 14:08:27.241 queries: info: client 199.115.102.83#5209: query: ietf.org IN ANY +E
09-Feb-2014 14:08:27.241 queries: info: client 199.115.102.83#5209: query: ietf.org IN ANY +E
09-Feb-2014 14:08:27.241 queries: info: client 199.115.102.83#5209: query: ietf.org IN ANY +E
09-Feb-2014 14:08:27.241 queries: info: client 199.115.102.83#5209: query: ietf.org IN ANY +E
09-Feb-2014 14:08:27.242 queries: info: client 173.234.39.133#5209: query: hccforums.nl IN ANY +E
09-Feb-2014 14:08:27.242 queries: info: client 199.115.102.83#5209: query: ietf.org IN ANY +E
09-Feb-2014 14:08:27.242 queries: info: client 199.115.102.83#5209: query: ietf.org IN ANY +E
09-Feb-2014 14:08:27.242 queries: info: client 199.115.102.83#5209: query: ietf.org IN ANY +E
09-Feb-2014 14:08:27.243 queries: info: client 199.115.102.83#5209: query: ietf.org IN ANY +E
09-Feb-2014 14:08:27.243 queries: info: client 173.234.39.133#5209: query: hccforums.nl IN ANY +E
09-Feb-2014 14:08:27.243 queries: info: client 173.234.39.133#5209: query: hccforums.nl IN ANY +E
09-Feb-2014 14:08:27.243 queries: info: client 199.115.102.83#5209: query: ietf.org IN ANY +E
09-Feb-2014 14:08:27.243 queries: info: client 173.234.39.133#5209: query: hccforums.nl IN ANY +E
09-Feb-2014 14:08:27.244 queries: info: client 173.234.39.133#5209: query: hccforums.nl IN ANY +E
09-Feb-2014 14:08:27.250 queries: info: client 199.115.102.83#5209: query: ietf.org IN ANY +E
09-Feb-2014 14:08:27.250 queries: info: client 199.115.102.83#5209: query: ietf.org IN ANY +E
09-Feb-2014 14:08:27.250 queries: info: client 199.115.102.83#5209: query: ietf.org IN ANY +E
09-Feb-2014 14:08:27.250 queries: info: client 199.115.102.83#5209: query: ietf.org IN ANY +E
09-Feb-2014 14:08:27.250 queries: info: client 199.115.102.83#5209: query: ietf.org IN ANY +E
09-Feb-2014 14:08:27.251 queries: info: client 173.234.39.133#5209: query: hccforums.nl IN ANY +E
09-Feb-2014 14:08:27.252 queries: info: client 70.39.67.110#5209: query: hccforums.nl IN ANY +E
09-Feb-2014 14:08:27.252 queries: info: client 70.39.67.110#5209: query: hccforums.nl IN ANY +E
09-Feb-2014 14:08:27.252 queries: info: client 173.234.39.133#5209: query: hccforums.nl IN ANY +E
09-Feb-2014 14:08:27.252 queries: info: client 173.234.39.133#5209: query: hccforums.nl IN ANY +E
09-Feb-2014 14:08:27.252 queries: info: client 173.234.39.133#5209: query: hccforums.nl IN ANY +E
09-Feb-2014 14:08:27.252 queries: info: client 70.39.67.110#5209: query: hccforums.nl IN ANY +E
09-Feb-2014 14:08:27.252 queries: info: client 70.39.67.110#5209: query: hccforums.nl IN ANY +E
09-Feb-2014 14:08:27.252 queries: info: client 70.39.67.110#5209: query: hccforums.nl IN ANY +E
09-Feb-2014 14:08:27.253 queries: info: client 173.234.39.133#5209: query: hccforums.nl IN ANY +E
09-Feb-2014 14:08:27.253 queries: info: client 173.234.39.133#5209: query: hccforums.nl IN ANY +E
09-Feb-2014 14:08:27.254 queries: info: client 173.234.39.133#5209: query: hccforums.nl IN ANY +E
09-Feb-2014 14:08:27.254 queries: info: client 173.234.39.133#5209: query: hccforums.nl IN ANY +E
09-Feb-2014 14:08:27.254 queries: info: client 173.234.39.133#5209: query: hccforums.nl IN ANY +E
09-Feb-2014 14:08:27.254 queries: info: client 70.39.67.110#5209: query: hccforums.nl IN ANY +E
09-Feb-2014 14:08:27.254 queries: info: client 173.234.39.133#5209: query: hccforums.nl IN ANY +E
09-Feb-2014 14:08:27.254 queries: info: client 70.39.67.110#5209: query: hccforums.nl IN ANY +E
09-Feb-2014 14:08:27.255 queries: info: client 70.39.67.110#5209: query: hccforums.nl IN ANY +E
09-Feb-2014 14:08:27.255 queries: info: client 173.234.39.133#5209: query: hccforums.nl IN ANY +E
09-Feb-2014 14:08:27.255 queries: info: client 70.39.67.110#5209: query: hccforums.nl IN ANY +E
09-Feb-2014 14:08:27.255 queries: info: client 70.39.67.110#5209: query: hccforums.nl IN ANY +E
09-Feb-2014 14:08:27.255 queries: info: client 70.39.67.110#5209: query: hccforums.nl IN ANY +E
09-Feb-2014 14:08:27.255 queries: info: client 70.39.67.110#5209: query: hccforums.nl IN ANY +E
09-Feb-2014 14:08:27.256 queries: info: client 70.39.67.110#5209: query: hccforums.nl IN ANY +E
09-Feb-2014 14:08:27.256 queries: info: client 70.39.67.110#5209: query: hccforums.nl IN ANY +E
09-Feb-2014 14:08:27.256 queries: info: client 173.234.39.133#5209: query: hccforums.nl IN ANY +E
09-Feb-2014 14:08:27.256 queries: info: client 173.234.39.133#5209: query: hccforums.nl IN ANY +E
09-Feb-2014 14:08:27.256 queries: info: client 70.39.67.110#5209: query: hccforums.nl IN ANY +E
09-Feb-2014 14:08:27.256 queries: info: client 173.234.39.133#5209: query: hccforums.nl IN ANY +E
09-Feb-2014 14:08:27.257 queries: info: client 173.234.39.133#5209: query: hccforums.nl IN ANY +E
09-Feb-2014 14:08:27.260 queries: info: client 70.39.67.110#5209: query: hccforums.nl IN ANY +E
09-Feb-2014 14:08:27.260 queries: info: client 70.39.67.110#5209: query: hccforums.nl IN ANY +E
09-Feb-2014 14:08:27.261 queries: info: client 70.39.67.110#5209: query: hccforums.nl IN ANY +E
09-Feb-2014 14:08:27.261 queries: info: client 70.39.67.110#5209: query: hccforums.nl IN ANY +E
09-Feb-2014 14:08:27.261 queries: info: client 70.39.67.110#5209: query: hccforums.nl IN ANY +E
09-Feb-2014 14:08:27.265 queries: info: client 192.126.118.105#5209: query: ietf.org IN ANY +E
09-Feb-2014 14:08:27.265 queries: info: client 192.126.118.105#5209: query: ietf.org IN ANY +E
09-Feb-2014 14:08:27.265 queries: info: client 192.126.118.105#5209: query: ietf.org IN ANY +E
09-Feb-2014 14:08:27.266 queries: info: client 199.115.102.83#5209: query: ietf.org IN ANY +E
09-Feb-2014 14:08:27.266 queries: info: client 192.126.118.105#5209: query: ietf.org IN ANY +E
09-Feb-2014 14:08:27.266 queries: info: client 192.126.118.105#5209: query: ietf.org IN ANY +E
09-Feb-2014 14:08:27.266 queries: info: client 192.126.118.105#5209: query: ietf.org IN ANY +E
09-Feb-2014 14:08:27.266 queries: info: client 192.126.118.105#5209: query: ietf.org IN ANY +E
09-Feb-2014 14:08:27.266 queries: info: client 199.115.102.83#5209: query: ietf.org IN ANY +E
09-Feb-2014 14:08:27.267 queries: info: client 199.115.102.83#5209: query: ietf.org IN ANY +E
09-Feb-2014 14:08:27.267 queries: info: client 199.115.102.83#5209: query: ietf.org IN ANY +E
09-Feb-2014 14:08:27.267 queries: info: client 192.126.118.105#5209: query: ietf.org IN ANY +E
09-Feb-2014 14:08:27.267 queries: info: client 192.126.118.105#5209: query: ietf.org IN ANY +E
09-Feb-2014 14:08:27.267 queries: info: client 192.126.118.105#5209: query: ietf.org IN ANY +E
09-Feb-2014 14:08:27.267 queries: info: client 192.126.118.105#5209: query: ietf.org IN ANY +E
09-Feb-2014 14:08:27.267 queries: info: client 192.126.118.105#5209: query: ietf.org IN ANY +E
09-Feb-2014 14:08:27.267 queries: info: client 192.126.118.105#5209: query: ietf.org IN ANY +E
09-Feb-2014 14:08:27.267 queries: info: client 192.126.118.105#5209: query: ietf.org IN ANY +E
09-Feb-2014 14:08:27.267 queries: info: client 199.115.102.83#5209: query: ietf.org IN ANY +E
09-Feb-2014 14:08:27.268 queries: info: client 192.126.118.105#5209: query: ietf.org IN ANY +E
09-Feb-2014 14:08:27.269 queries: info: client 174.139.237.142#5209: query: hccforums.nl IN ANY +E
09-Feb-2014 14:08:27.269 queries: info: client 174.139.237.142#5209: query: hccforums.nl IN ANY +E
09-Feb-2014 14:08:27.269 queries: info: client 174.139.237.142#5209: query: hccforums.nl IN ANY +E
09-Feb-2014 14:08:27.269 queries: info: client 174.139.237.142#5209: query: hccforums.nl IN ANY +E
09-Feb-2014 14:08:27.269 queries: info: client 174.139.237.142#5209: query: hccforums.nl IN ANY +E
09-Feb-2014 14:08:27.270 queries: info: client 192.126.118.105#5209: query: ietf.org IN ANY +E
09-Feb-2014 14:08:27.270 queries: info: client 192.126.118.105#5209: query: ietf.org IN ANY +E
09-Feb-2014 14:08:27.271 queries: info: client 192.126.118.105#5209: query: ietf.org IN ANY +E
09-Feb-2014 14:08:27.271 queries: info: client 192.126.118.105#5209: query: ietf.org IN ANY +E
09-Feb-2014 14:08:27.271 queries: info: client 174.139.237.142#5209: query: hccforums.nl IN ANY +E
09-Feb-2014 14:08:27.271 queries: info: client 174.139.237.142#5209: query: hccforums.nl IN ANY +E
09-Feb-2014 14:08:27.271 queries: info: client 174.139.237.142#5209: query: hccforums.nl IN ANY +E
09-Feb-2014 14:08:27.271 queries: info: client 174.139.237.142#5209: query: hccforums.nl IN ANY +E
09-Feb-2014 14:08:27.271 queries: info: client 174.139.237.142#5209: query: hccforums.nl IN ANY +E
09-Feb-2014 14:08:27.272 queries: info: client 192.126.118.105#5209: query: ietf.org IN ANY +E
09-Feb-2014 14:08:27.272 queries: info: client 192.126.118.105#5209: query: ietf.org IN ANY +E
09-Feb-2014 14:08:27.272 queries: info: client 192.126.118.105#5209: query: ietf.org IN ANY +E
09-Feb-2014 14:08:27.272 queries: info: client 192.126.118.105#5209: query: ietf.org IN ANY +E
09-Feb-2014 14:08:27.273 queries: info: client 174.139.237.142#5209: query: hccforums.nl IN ANY +E
09-Feb-2014 14:08:27.273 queries: info: client 174.139.237.142#5209: query: hccforums.nl IN ANY +E
09-Feb-2014 14:08:27.273 queries: info: client 192.126.118.105#5209: query: ietf.org IN ANY +E
09-Feb-2014 14:08:27.273 queries: info: client 174.139.237.142#5209: query: hccforums.nl IN ANY +E
09-Feb-2014 14:08:27.273 queries: info: client 174.139.237.142#5209: query: hccforums.nl IN ANY +E
09-Feb-2014 14:08:27.273 queries: info: client 174.139.237.142#5209: query: hccforums.nl IN ANY +E
09-Feb-2014 14:08:27.274 queries: info: client 174.139.237.142#5209: query: hccforums.nl IN ANY +E
09-Feb-2014 14:08:27.274 queries: info: client 192.126.118.105#5209: query: ietf.org IN ANY +E
09-Feb-2014 14:08:27.274 queries: info: client 174.139.237.142#5209: query: hccforums.nl IN ANY +E
09-Feb-2014 14:08:27.274 queries: info: client 174.139.237.142#5209: query: hccforums.nl IN ANY +E
09-Feb-2014 14:08:27.274 queries: info: client 174.139.237.142#5209: query: hccforums.nl IN ANY +E
09-Feb-2014 14:08:27.274 queries: info: client 174.139.237.142#5209: query: hccforums.nl IN ANY +E
09-Feb-2014 14:08:27.275 queries: info: client 70.39.67.110#5209: query: hccforums.nl IN ANY +E
09-Feb-2014 14:08:27.276 queries: info: client 70.39.67.110#5209: query: hccforums.nl IN ANY +E
09-Feb-2014 14:08:27.276 queries: info: client 174.139.237.142#5209: query: hccforums.nl IN ANY +E
09-Feb-2014 14:08:27.276 queries: info: client 174.139.237.142#5209: query: hccforums.nl IN ANY +E
09-Feb-2014 14:08:27.276 queries: info: client 174.139.237.142#5209: query: hccforums.nl IN ANY +E
09-Feb-2014 14:08:27.276 queries: info: client
 
I posted this to let the world see who the bad kids and from what website they are really from.
 
I don't get it. Why are they after us? Did we ban some one that now want to go after us or did we get an IP that was used and has bad history?
 
struggled to get to the outhouse

Oh that explains it I hard a hard time getting into the outhouse My internet time was cut short and not logging in here is a hassle I have to visit this place often :wavey:
 
Ickie,

Do you know about the WHOIS at arin.net? For example, with arin.net I can see the IP address 70.39.67.110 belongs to an ISP named Sharknet Colorado USA. Using the IP address in this way could be a clear violation of USA law. You could at least report the IP address to the ISP.

And 174.139.237.142 is from an ISP in California.
 
I need to check my home IP. When I went to log on on sat. I got an "Account Disabled" notice come up. If one of those IP's is me, then mine, or my wife's laptops may have been compromised! It may explain why the whole home system seems to slow to a crawl about 50% of the time. (sent from work computer)
 
The two sites are on different servers running different software (Linux and Windows Server) and the member info is non-transferable between the two so you will need to re-register at the .net site in order to access it fully.

True but you can read on the .net with out re-registering.
 
The two sites are on different servers running different software (Linux and Windows Server) and the member info is non-transferable between the two so you will need to re-register at the .net site in order to access it fully.

Ahh... many thanks, Larry!

Hobbes_2.gif
 
I need to check my home IP. When I went to log on on sat. I got an "Account Disabled" notice come up. If one of those IP's is me, then mine, or my wife's laptops may have been compromised! It may explain why the whole home system seems to slow to a crawl about 50% of the time. (sent from work computer)

Your forthrightness is truly refreshing, sir. I suggest you and Ickie chat about scrubbing up your laptops and trying again. I wish you luck in finding the problem files on your machines. If nothing else, a good scan of those laptops should improve their performance for you.

When you do the scan and repair, keep the logs so they can be analyzed for which miserable malware is likely to be at fault. Others of us can then be able to go after it (them) on our own machines.
 
Your forthrightness is truly refreshing, sir. I suggest you and Ickie chat about scrubbing up your laptops and trying again. I wish you luck in finding the problem files on your machines. If nothing else, a good scan of those laptops should improve their performance for you.

When you do the scan and repair, keep the logs so they can be analyzed for which miserable malware is likely to be at fault. Others of us can then be able to go after it (them) on our own machines.
Back to normal again - perhaps it was just a sympton of the attack. I'm still having a thorough scrub through though - I'm normally fairly careful about these things, but, you never know........drop your guard for a second and whammo!
 
Back
Top