Community discussions

MikroTik App
 
reza.mnp
Frequent Visitor
Frequent Visitor
Topic Author
Posts: 90
Joined: Mon Jun 11, 2007 9:44 am
Location: ilam - iran
Contact:

what's this problem (DNS)

Mon Jun 13, 2011 8:35 pm

please see attachment.
what's the problem?
You do not have the required permissions to view the files attached to this post.
 
fewi
Forum Guru
Forum Guru
Posts: 7717
Joined: Tue Aug 11, 2009 3:19 am

Re: what's this problem (DNS)

Mon Jun 13, 2011 8:47 pm

It's not a problem as such. Some client is requesting those records, and DNS is unable to resolve them. The most likely cause for the client requesting the records is that it is infected with malware and is part of a botnet, and is trying to contact a control server.
 
reza.mnp
Frequent Visitor
Frequent Visitor
Topic Author
Posts: 90
Joined: Mon Jun 11, 2007 9:44 am
Location: ilam - iran
Contact:

Re: what's this problem (DNS)

Mon Jun 13, 2011 10:28 pm

How to detect and block infected machines ?
 
fewi
Forum Guru
Forum Guru
Posts: 7717
Joined: Tue Aug 11, 2009 3:19 am

Re: what's this problem (DNS)

Mon Jun 13, 2011 10:37 pm

Realistically you can't. You'd have to detect requests to known c&c DNS names via layer 7 inspection and add request sources to address lists, and filter based on that. You'd constantly have to update the lists of known destinations. Just blocking all clients that request unresolvable resources could lead to false positives and you blocking legitimate traffic.
Unless you truly understand how to do that you're probably going to cause more problems trying to fix it.

You can buy firewall appliance that do this for you, with subscriptions so you can download updated signatures and lists.