Re: [Nolug] Weird data in my firewall logs

From: Joey Kelly <looseduk_at_ductape.net>
Date: Wed, 16 Jan 2002 23:28:09 +0000
Message-Id: <02011623280900.05153@rahab>

Now that you mention it, i found this in my server logs (and I don't even
have a cox account):

Jan 17 00:47:55 ruth named[129]: Lame server on '66.0.1.68.in-addr.arpa' (in
'1.68.in-addr.arpa'?): [68.1.17.5].53 'NS.EAST.COX.NET'
Jan 17 00:47:55 ruth named[129]: Lame server on '66.0.1.68.in-addr.arpa' (in
'1.68.in-addr.arpa'?): [68.1.17.237].53 'NS.COX.NET'
Jan 17 00:47:55 ruth named[129]: ns_forw: query(66.0.1.68.in-addr.arpa) All
possible A RR's lame
Jan 17 00:47:55 ruth named[129]: Lame server on '18.14.11.68.in-addr.arpa'
(in '11.68.in-addr.arpa'?): [68.1.17.237].53 'NS.COX.NET'
Jan 17 00:47:55 ruth named[129]: Lame server on '18.14.11.68.in-addr.arpa'
(in '11.68.in-addr.arpa'?): [68.1.17.5].53 'NS.EAST.COX.NET'

I'm ssh'd in to a cox business services account from another PC on my lan
(different box than my server), dunno what daemon is trying to do lookups on
me.

At any rate, Charles, you've got something misconfigured on your end --- your
PTR records are the culprit.

--Joey

Thou spake:
>Hi, all.
>
>68.11.16.30 & 68.1.208.30 are the addresses of cox's new DNS servers.
>24.4.62.33 is the address of @home's primary DNS server.
>
>Since Cox did The Big Switch today: my modem was out for ~6 hours,
>then when it came back up, I had a new address: 68.11.67.231.
>Could this be from when they were configuring things? Note that
>the name associated with 68.11.16.30 keeps changing. (I got the
>host names using the python function socket.getfqdn()).
>
>Anyone have any clues? Maybe Chuck the Cox Dude?
>
>Here is a list of ports denied entry by my firewall:
> 1122 ---- 68.11.16.30 mctydnss01.sd.sd.cox.net
> 1122 ---- 68.11.16.30 proxy.sd.sd.cox.net
> 1123 ---- 68.1.208.30 dllsdns01.dl.dl.cox.net
> 1123 ---- 68.11.16.30 mctydnss01.sd.sd.cox.net
> 1124 ---- 68.1.208.30 dllsdns01.dl.dl.cox.net
> 1124 ---- 68.1.208.30 proxy.dl.dl.cox.net
> 1124 ---- 68.11.16.30 mctydnss01.sd.sd.cox.net
> 1124 ---- 68.11.16.30 proxy.sd.sd.cox.net
> 1125 ---- 68.1.208.30 dllsdns01.dl.dl.cox.net
> 1125 ---- 68.1.208.30 proxy.dl.dl.cox.net
> 1125 ---- 68.11.16.30 proxy.sd.sd.cox.net
> 1126 ---- 68.1.208.30 dllsdns01.dl.dl.cox.net
> 1126 ---- 68.1.208.30 proxy.dl.dl.cox.net
> 1126 ---- 68.11.16.30 mctydnss01.sd.sd.cox.net
> 1127 supfiledbg ---- 68.1.208.30 proxy.dl.dl.cox.net
> 1127 supfiledbg ---- 68.11.16.30 mctydnss01.sd.sd.cox.net
> 1127 supfiledbg ---- 68.11.16.30 proxy.sd.sd.cox.net
> 1128 ---- 68.1.208.30 dllsdns01.dl.dl.cox.net
> 1128 ---- 68.11.16.30 mctydnss01.sd.sd.cox.net
> 1129 ---- 68.1.208.30 dllsdns01.dl.dl.cox.net
> 1129 ---- 68.1.208.30 proxy.dl.dl.cox.net
> 1129 ---- 68.11.16.30 mctydnss01.sd.sd.cox.net
> 1130 ---- 68.1.208.30 proxy.dl.dl.cox.net
> 6588 ---- 212.100.205.29 212.100.205.29
>61646 ---- 24.4.62.33 proxy1.elmwd1.la.home.com
>61648 ---- 24.4.62.33 proxy1.elmwd1.la.home.com
>61650 ---- 24.4.62.33 proxy1.elmwd1.la.home.com
>61652 ---- 24.4.62.33 proxy1.elmwd1.la.home.com
>61653 ---- 24.4.62.33 proxy1.elmwd1.la.home.com
>61654 ---- 24.4.62.33 proxy1.elmwd1.la.home.com

-- 
Joey Kelly
< Minister of the Gospel | Computer Networking Consultant >
http://joeykelly.dhs.org
"When Government fears the people, it's liberty.
When people fear the Government, it's tyranny."
-- Benjamin Franklin
Ich möchte ein Berliner.
___________________
Nolug mailing list
nolug@nolug.org
Received on 01/17/02

This archive was generated by hypermail 2.2.0 : 12/19/08 EST