[dns-operations] Abnormal activity fron chinanet?

Simon Munton Simon.Munton at communitydns.net
Fri Jan 20 10:49:50 UTC 2012


Our anycast node in SanJose has been getting something similar for some 
time, mostly from 121.14.142.95 when we looked the other day.

http://stats.communitydns.net/public/0.0.0.1/00188B-F852AE.html

Our automated anti-D/DoS is catching most of it. Bangkok started seeing 
it more recently

http://stats.communitydns.net/public/0.0.0.1/842B2B-12989E.html

All are IN/ANY queries for lots of different domains that all exist - 
mostly hitting one or two registrar's accounts who aren't using our 
HongKong node - otherwise (if its coming from China) I'd expect we'd be 
seeing it there.



-------------- next part --------------
A non-text attachment was scrubbed...
Name: 00188B-F852AE-week.png
Type: image/png
Size: 28405 bytes
Desc: not available
URL: <http://lists.dns-oarc.net/pipermail/dns-operations/attachments/20120120/7acef3a0/attachment.png>


More information about the dns-operations mailing list