From owner-freebsd-security@FreeBSD.ORG Sat Apr 16 09:44:39 2011 Return-Path: Delivered-To: freebsd-security@freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2001:4f8:fff6::34]) by hub.freebsd.org (Postfix) with ESMTP id B69E7106566B for ; Sat, 16 Apr 2011 09:44:39 +0000 (UTC) (envelope-from przemyslaw@frasunek.com) Received: from lagoon.freebsd.lublin.pl (lagoon.freebsd.lublin.pl [IPv6:2a02:2928:a::3]) by mx1.freebsd.org (Postfix) with ESMTP id 6DD118FC0A for ; Sat, 16 Apr 2011 09:44:39 +0000 (UTC) Received: from [IPv6:2a02:2928:a:ffff:70a6:6b28:ff4e:bb7b] (unknown [IPv6:2a02:2928:a:ffff:70a6:6b28:ff4e:bb7b]) by lagoon.freebsd.lublin.pl (Postfix) with ESMTPSA id 6E32D239461; Sat, 16 Apr 2011 11:44:38 +0200 (CEST) Message-ID: <4DA96506.8040007@frasunek.com> Date: Sat, 16 Apr 2011 11:44:38 +0200 From: Przemyslaw Frasunek Organization: frasunek.com User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; pl; rv:1.9.2.15) Gecko/20110303 Thunderbird/3.1.9 MIME-Version: 1.0 To: Michael Scheidell References: <4DA95938.7050608@secnap.com> <4DA96137.5050100@frasunek.com> <4DA961F1.1040100@secnap.com> In-Reply-To: <4DA961F1.1040100@secnap.com> X-Enigmail-Version: 1.1.1 Content-Type: text/plain; charset=ISO-8859-1 Content-Transfer-Encoding: 7bit Cc: freebsd-security@freebsd.org, Emerging Threats Signatures Subject: Re: 193.138.118.3 ? lagoon.freebsd.lublin.pl /cache, freebsd, lublin, pl on TOR end point list? X-BeenThere: freebsd-security@freebsd.org X-Mailman-Version: 2.1.5 Precedence: list List-Id: "Security issues \[members-only posting\]" List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Sat, 16 Apr 2011 09:44:39 -0000 > I will try to track down what server is lookup up cache.freebsd.lublin.pl and > see why its doing that. cache.freebsd.lublin.pl [193.138.118.6], now named ns2.nette.pl, is a secondary DNS for some high-traffic Polish domains, so probably that's the reason, why you're seeing such lookups.