Kristen Doyle | 6 Jun 2005 08:48

ns1.nimblehost.net

Well fast forward to today I am sorry folks but I am going to have to 
remove ns1.nimblehost.net until spam bots stop using me as a dns server. 
the server was reciving like 100,000 queries a second
######################################################################
This is the discussion list for the Open Network Information
Center.  You can unsubscribe by sending an email containing the words
"unsubscribe discuss" in the body of the message to
"majordomo <at> opennic.glue" or "majordomo <at> opennic.unrated.net".
######################################################################

Noel Shrum | 6 Jun 2005 16:26

Re: ns1.nimblehost.net

Kristen Doyle wrote:
> Well fast forward to today I am sorry folks but I am going to have to
> remove ns1.nimblehost.net until spam bots stop using me as a dns server.
> the server was reciving like 100,000 queries a second

Wouldn't it be better to just ban the ip addresses of the users that are
doing that?

Noel
######################################################################
This is the discussion list for the Open Network Information
Center.  You can unsubscribe by sending an email containing the words
"unsubscribe discuss" in the body of the message to
"majordomo <at> opennic.glue" or "majordomo <at> opennic.unrated.net".
######################################################################

Dennis Carr | 6 Jun 2005 16:44

Re: ns1.nimblehost.net

On Mon, 06 Jun 2005 10:26:51 -0400
Noel Shrum <ar798 <at> tcnet.org> wrote:

> Wouldn't it be better to just ban the ip addresses of the users that
> are doing that?

That's more of an uphill battle if you try that - spambots are usually
just zombies.

Perhaps an IP address is in order then?
######################################################################
This is the discussion list for the Open Network Information
Center.  You can unsubscribe by sending an email containing the words
"unsubscribe discuss" in the body of the message to
"majordomo <at> opennic.glue" or "majordomo <at> opennic.unrated.net".
######################################################################

Noel Shrum | 7 Jun 2005 00:20

Re: ns1.nimblehost.net

Dennis Carr wrote:
> On Mon, 06 Jun 2005 10:26:51 -0400
> Noel Shrum <ar798 <at> tcnet.org> wrote:
> 
> 
>>Wouldn't it be better to just ban the ip addresses of the users that
>>are doing that?
> 
> 
> That's more of an uphill battle if you try that - spambots are usually
> just zombies.
> 
> Perhaps an IP address is in order then?

I just figured that since most (from what I understand) users of opennic
were smart enough to choose to use opennic in the first place, by
banning their ip addresses might get them to look for the reason they
can't use opennic anymore.  Perhaps setting the dns server to resolve
all querys to the same ip address and have that server give them a web
page that tells them why it is happening.  (You can do that, can't you?)

Why punish the users who aren't abusing the service?

Just an idea.

Noel
######################################################################
This is the discussion list for the Open Network Information
Center.  You can unsubscribe by sending an email containing the words
"unsubscribe discuss" in the body of the message to
(Continue reading)

Dennis Carr | 10 Jun 2005 00:11

ns12 back online

I'm reinstating name services for my system.  Bind is not the cause of my 
trouble, it seems.

-Dennis
.fur

######################################################################
This is the discussion list for the Open Network Information
Center.  You can unsubscribe by sending an email containing the words
"unsubscribe discuss" in the body of the message to
"majordomo <at> opennic.glue" or "majordomo <at> opennic.unrated.net".
######################################################################

Jeff Taylor | 10 Jun 2005 16:10
Favicon

Re: ns1.nimblehost.net

And share the IP's here as well!  I discovered yestarday that someone 
was hitting my server so hard that bind was running out of sockets.  
Really killing the performance of my server.  Turns out all the abusive 
queries were coming from 205.209.156.0/24 and 205.209.157.0/24.  (Would 
I correctly cover the whole range if I use 205.209.156.0/23 ?)  Anyway, 
I blocked the whole range in bind and my server is running smoothly again.

Personally I think that if the abusive ranges are posted here, then 
others who are providing tier-2 servers could pre-emptively block any 
abuse.  It would also provide another checkpoint for anyone having 
problems connecting to a tier-2 server, by providing a place to confirm 
they're not within a blacklisted range.

Noel Shrum wrote:

>Kristen Doyle wrote:
>  
>
>>Well fast forward to today I am sorry folks but I am going to have to
>>remove ns1.nimblehost.net until spam bots stop using me as a dns server.
>>the server was reciving like 100,000 queries a second
>>    
>>
>
>Wouldn't it be better to just ban the ip addresses of the users that are
>doing that?
>
>Noel
>######################################################################
>This is the discussion list for the Open Network Information
(Continue reading)

Kristen Doyle | 10 Jun 2005 17:20

Re: ns1.nimblehost.net

yes that was actually the range i ended up blocking the entire /8

Jeff Taylor wrote:

> And share the IP's here as well!  I discovered yestarday that someone 
> was hitting my server so hard that bind was running out of sockets.  
> Really killing the performance of my server.  Turns out all the 
> abusive queries were coming from 205.209.156.0/24 and 
> 205.209.157.0/24.  (Would I correctly cover the whole range if I use 
> 205.209.156.0/23 ?)  Anyway, I blocked the whole range in bind and my 
> server is running smoothly again.
>
> Personally I think that if the abusive ranges are posted here, then 
> others who are providing tier-2 servers could pre-emptively block any 
> abuse.  It would also provide another checkpoint for anyone having 
> problems connecting to a tier-2 server, by providing a place to 
> confirm they're not within a blacklisted range.
>
>
> Noel Shrum wrote:
>
>> Kristen Doyle wrote:
>>  
>>
>>> Well fast forward to today I am sorry folks but I am going to have to
>>> remove ns1.nimblehost.net until spam bots stop using me as a dns 
>>> server.
>>> the server was reciving like 100,000 queries a second
>>>   
>>
(Continue reading)

Jeff Taylor | 13 Jun 2005 14:50
Favicon

Re: ns1.nimblehost.net

(If this gets reposted, sorry... I never got a copy the first time I sent it)

Dennis Carr wrote:

>That's more of an uphill battle if you try that - spambots are usually
>just zombies.
>
>  
>
Waaaiiitttt a minute... what's this you say?  So if I were to start
collecting a list of all the IP's which are generating 10's of lame
server errors every few minutes, I would end up with a list of zombies?
The same zombies that are spamming me to death?

--

-- 
No virus found in this outgoing message.
Checked by AVG Anti-Virus.
Version: 7.0.323 / Virus Database: 267.6.9 - Release Date: 6/11/2005

######################################################################
This is the discussion list for the Open Network Information
Center.  You can unsubscribe by sending an email containing the words
"unsubscribe discuss" in the body of the message to
"majordomo <at> opennic.glue" or "majordomo <at> opennic.unrated.net".
######################################################################

Jeff Taylor | 13 Jun 2005 16:19
Favicon

Re: Possible anti-zombie remedy?

Just to follow up on this... I wrote up a script this weekend that 
simply pulls IP addresses from my log files for  all the lame server and 
unexpected rcode errors.  Ended up with over 3800 uniq IP's listed, and 
when I blocked traffic based on this list, the nameserver traffic went 
WAY down.  I also applied the list and a blocklist in postfix, but have 
not yet seen a single email rejected from this (which is dissapointing).

I need to do two things to clean this up.  First, change the script to 
only look for multiple hits in one second.  The legitimate lame-server 
errors I've seen coming from my own network typically only have a single 
error per requested domain, while the abusers will spawn 3-5 lookups of 
the same domain in a 1-second period. Watching for this should make the 
script much less likely to blacklist a legitimate user.  Second, I need 
to write another script that watches the log file and dynamically 
updates my IP list as new hits come in.

I currently use Spamikaze on my mail server to blacklist IP's sending 
mail to my spamtrap accounts.  I would like to write up something that 
adds these IP's to that same list, because spamikaze-rejected emails 
point the sender to a web page where they can unban their IP.

As another thought to throw out there, what about using this list of 
IP's for purposeful dns poisoning?  If we're certain these are spambots, 
then what would happen if every further query they made, I were to 
return their own IP address back to them?  Wouldn't they likely them try 
sending all outbound emails to themselves, possibly flooding themselves 
off the internet (and forcing the computer owners to actually take a 
look at why their computer is running poorly)?  I'm not exactly sure how 
to get bind to do something like this, but it would sure be interesting 
to see the results.
(Continue reading)

tabris | 13 Jun 2005 16:26

Re: ns1.nimblehost.net

On Monday 13 June 2005 8:50 am, Jeff Taylor wrote:
> (If this gets reposted, sorry... I never got a copy the first time I
> sent it)
>
> Dennis Carr wrote:
> >That's more of an uphill battle if you try that - spambots are
> > usually just zombies.
>
> Waaaiiitttt a minute... what's this you say?  So if I were to start
> collecting a list of all the IP's which are generating 10's of lame
> server errors every few minutes, I would end up with a list of
> zombies? The same zombies that are spamming me to death?
possibly. otoh if they're just trying to be mean and not going for 
anything actually useful, it could be all spoofed. UDP has little to 
nothing preventing IP spoofs.

--

-- 
Many a man that can't direct you to a corner drugstore will get a 
respectful hearing when age has further impaired his mind.
		-- Finley Peter Dunne

Gmane