From owner-freebsd-questions@FreeBSD.ORG Sat Feb 14 20:08:54 2004 Return-Path: Delivered-To: freebsd-questions@freebsd.org Received: from mx1.FreeBSD.org (mx1.freebsd.org [216.136.204.125]) by hub.freebsd.org (Postfix) with ESMTP id 3D23F16A4CE for ; Sat, 14 Feb 2004 20:08:54 -0800 (PST) Received: from saexchange.toneisp.com (saexchange.toneisp.com [209.150.214.147]) by mx1.FreeBSD.org (Postfix) with SMTP id 6139843D2D for ; Sat, 14 Feb 2004 20:08:53 -0800 (PST) (envelope-from fbsdq@kuyarov.org) Received: (qmail 3488 invoked from network); 15 Feb 2004 04:03:15 -0000 Received: from unknown (HELO saexchange.toneisp.com) (127.0.0.1) by localhost.toneisp.com with SMTP; 15 Feb 2004 04:03:15 -0000 Received: (from vpopmail@localhost) by saexchange.toneisp.com (8.12.9/8.12.9/Submit) id i1F43E9s003486; Sat, 14 Feb 2004 21:03:14 -0700 (MST) Message-Id: <200402150403.i1F43E9s003486@saexchange.toneisp.com> X-Authentication-Warning: saexchange.toneisp.com: vpopmail set sender to fbsdq@kuyarov.org using -f From: "fbsdq" To: freebsd-questions@freebsd.org Date: Sat, 14 Feb 2004 21:03:14 -0700 Mime-Version: 1.0 Content-Type: text/plain; format=flowed; charset="iso-8859-1" Content-Transfer-Encoding: 7bit Subject: 3,000+ DNS /./ANY/ANY requests - ...resent... X-BeenThere: freebsd-questions@freebsd.org X-Mailman-Version: 2.1.1 Precedence: list Reply-To: fbsdq List-Id: User questions List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Sun, 15 Feb 2004 04:08:54 -0000 Sorry about the earlier question, that was more or less just blank.... Hello, About a week ago I started noticing 3,000 or more requests coming from several ips for the following DNS queries: XX+/128.255.203.200/./ANY/ANY XX+/193.201.105.4/./ANY/ANY Those are just two examples, but each IP - I have about 20 of them now create 3,000 or more queries within several minutes. All the queries are exactly the same for ./ANY/ANY.....any idea what those queries are? or what they are trying to do? Also how can I create an 'ipfw' rule to block an ip if XX amount of connections come in within XX amount of minutes/seconds?? Right now I manually block them, and yes those IP's try a day or so later to DNS bomb (?) my machine. Thanks ---Peter---