Community discussions

MikroTik App
 
fiery2
just joined
Topic Author
Posts: 5
Joined: Sat Jun 03, 2017 7:48 pm

Weird dns cache entries

Fri May 11, 2018 8:33 am

I got a lot of dns entries with random string name in this past few day.
mikrotik random dns string.PNG
From the same ip address,its a legitimate client/device.
mikrotik random dns string CLIENT.PNG
Dns setting is allow remote request from internal network,with drop dns request from external network in firewall(above accept established/related new connection).

Currently dropping connection from that client : add action=drop chain=input comment="CLIENT REQUEST WEIRD DNS !!!!!" src-mac-address=94:DE:80:57:53:60

Pretty sure its come from adware though,given a lot of ads poping out every now and then on that device.
Whats the risk if i allow this client "putting" such dns entries?
You do not have the required permissions to view the files attached to this post.
 
User avatar
Anumrak
Forum Guru
Forum Guru
Posts: 1174
Joined: Fri Jul 28, 2017 2:53 pm

Re: Weird dns cache entries  [SOLVED]

Fri May 11, 2018 9:29 am

That dns flood from your LAN, so these requests just flooding your RAM on router, what is not cool. You should block dns queries for this host and figure out how to fix him, then release the host.

P.S.: I bet that's a virus.

Who is online

Users browsing this forum: anav, tuiespacecorp and 40 guests