* The Business of SoftwareA community discussing the business of software, from the smallest shareware operation to Microsoft. A part of Joel on Software. |
||
|
This community works best when people use their real names. Please register for a free account. Links:
» Business of Software FAQ Movie:"Make Better Software" is a 6 movie course designed to help you as you grow from a micro-ISV to a large software company. Moderators:
Andy Brice Doug Nebeker ("Doug")
Jonathan Matthews
Nicholas Hebb
Bob Walsh |
My server is also being hammered by domain names that always resolve to 67.215.65.132. This address apparently belongs to OpenDNS which seems to be a legit company.
The behavior is the same described in the previous post, but they don't contain the SBUA user agent. I've found some information online about this IP, and it seems involved in forum spam (about drugs) and apparently a guy in a Spanish Linux forum was complaining his ftp server had been attacked by this IP. Here are some of the domain names: retail.dynamic.sify.net 8323316588-host.servainet.com static.unknown.charter.com 54.60.in-addr.arpa 132.115.in-addr.arpa New ones are showing up everyday, but they always resolve to 67.215.65.132: hit-nxdomain.opendns.com I already contacted abuse@opendns.com but got no reply so far. What might be going on? Why ME???
Yes, they are innocent and I'm getting 67.215.65.132 as a fallback address from OpenDNS because the domains are not resolving correctly.
Several years ago I had a similar problem and my host company solved it by changing my servers IP address and leaving the 'old' IP address in a black hole.
All OpenDNS does is quickly resolve domain requests to IP's. Sounds like the hacking community is simply using them as a very fast conduit to attack various IP locations quickly with little transparency. All these have to do is switch the IP on a few domains picked up by OpenDNS, and probably get immediate results as far as who they target. I would forget the IP and tell them what are the offending domains, and have them blacklisted. They should be able to control what domains they are processing for their clients?
|
|


