home hardware prices news articles forums photos user reviews
Go Back   Tech Support Forums - TechIMO.com > PC Hardware and Tech > Networking and Internet
Ask a Tech Support Question (free)!

DNS Hijacked?

Reply
Get bargains at  »  Dealighted.com
 
Thread Tools Search this Thread
Currently Active Users: 2263
Discussions: 200,937, Posts: 2,379,252, Members: 246,302
Old May 26th, 2005, 03:13 PM   Digg it!   #1 (permalink)
Ultimate Member
 
blubomber's Avatar
 
Join Date: Oct 2001
Location: Reno, NV
Posts: 1,623
Send a message via MSN to blubomber Send a message via Yahoo to blubomber
DNS Hijacked?

I was getting alot of DNS traffic going out of my network to the point that it was bringing everything to a crawl. I stopped the DNS server service on my primary DNS server while leaving the backup up. That seemed to have fixed the problem. Now though i need to get my primary DNS fixed because i cant leave it down all the time.

Any suggestions on how to clear this up? I ran spybot but that did not help.

Thanks for any help.
__________________
"Life moves pretty fast, if you dont stop to look around once in a while, you could miss it." -FB
blubomber is offline   Reply With Quote
Old May 26th, 2005, 08:29 PM     #2 (permalink)
Ultimate Member
 
FatalException's Avatar
 
Join Date: Jun 2004
Location: Indianapolis, Indiana
Posts: 1,398
Why are you running a DNS server at your home? Do you have that many systems that you have to have DNS services running?
__________________
Logic shall prevail.
FatalException is offline   Reply With Quote
Old May 26th, 2005, 08:50 PM     #3 (permalink)
Ultimate Member
 
Join Date: Apr 2003
Location: Texas
Posts: 1,292
Send a message via AIM to fourthbean
Maybe he is not at home......I know I would not have a backup dns server for my house.
fourthbean is offline   Reply With Quote
Old May 26th, 2005, 08:57 PM     #4 (permalink)
Ultimate Member
 
FatalException's Avatar
 
Join Date: Jun 2004
Location: Indianapolis, Indiana
Posts: 1,398
Well, if this is a large enough business to require both primary and backup DNS servers, then wouldn't it make sense that someone else there would have the technical know-how to resolve this issue? Perhaps he should contact this other person at his organization and see if they can resolve it since they are likely more familiar with the network than anyone on TechIMO is.
FatalException is offline   Reply With Quote
Old May 26th, 2005, 09:28 PM     #5 (permalink)
Not Really a Member
 
Join Date: Oct 2001
Posts: 25,385
If he's running this for a business, its very likely he's using active directory which demands DNS for internal communication.
In this case its very important to have a backup DNS server as even simple stuff like opening your mail will fail if he loses DNS.

Anyways.

I dont think spyware will be your issue seeing as I *hope* nobody is surfing the net on a network DNS server.
If its a windows box reinstall the latest SP and all of the hotfixes.
Run an antivirus to make sure you didn't get hit by a worm.

maybe run netstat -n and see what ports are open.
There should not be anything besides the normal.
I believe it woould be something like
135, 139, 445, 53... if there are any others post them so we can check.
__________________
Helicopters don't fly; they vibrate so much and make so much noise that the earth rejects them.
vass0922 is offline   Reply With Quote
Old May 27th, 2005, 12:07 AM     #6 (permalink)
Ultimate Member
 
blubomber's Avatar
 
Join Date: Oct 2001
Location: Reno, NV
Posts: 1,623
Send a message via MSN to blubomber Send a message via Yahoo to blubomber
vass0922...i did not think about netstat, thank you i will try that.

Yes, this is for my work and i am running a windows 2000 domain with AD. Good thing i did have the backup DNS because no one would be getting email or anything right now. I have a computer running ethereal right at my gateway and the captured packets are mostly DNS stuff. It is going to take me some time to weed through all the info. It is not just one site it is going to. I have also run Hijackthis and antivirus software which did not come up with anything. Also, all of my servers are in a locked room and i do all of my admin stuff from my desk.

I was just currious if anyone has come across a situation like this before. I guess i will just have to keep plugging away at it. Hope fully i can get it resolved tomorrow. i hate running on just one DNS server.

Thanks for the replies.
blubomber is offline   Reply With Quote
Old May 27th, 2005, 01:16 AM     #7 (permalink)
Ultimate Member
 
FatalException's Avatar
 
Join Date: Jun 2004
Location: Indianapolis, Indiana
Posts: 1,398
Could it possibly be a DDOS attack on your DNS servers? Has your organization received any threats regarding network services? Maybe someone out there has an army of zombie systems hitting your DNS server for some reason. It's also possible that someone out there mis-published their own DNS server data and listed your addresses instead. If a large ISP were to do this, that could create some serious traffic issues for you. Sorry I'm not being much help; I am not extremely familiar with this stuff, so I'm trying to think of what could be causing this based on the limited knowledgebase I do have.
FatalException is offline   Reply With Quote
Old May 27th, 2005, 02:29 AM     #8 (permalink)
Ultimate Member
 
blubomber's Avatar
 
Join Date: Oct 2001
Location: Reno, NV
Posts: 1,623
Send a message via MSN to blubomber Send a message via Yahoo to blubomber
My firewall does not allow incoming DNS and it blocks all DDOS attacks. It is my internal server that is the problem. With the DNS server service turned on, that is when it goes crazy. When the service is stopped, everything returns to normal. It all started on Tuesday of this week. I am gonna have to go back through all my firewall logs to see if there is anything that looks suspicious.

I am also not sure if anyone has seen a DNS server just go crazy for no reason. I am sure it is very rare if possible at all. But, it is stuff like this that keeps my job intersting.
blubomber is offline   Reply With Quote
Old May 27th, 2005, 03:56 AM     #9 (permalink)
Member
 
darkenbinary's Avatar
 
Join Date: Jul 2004
Location: U.S.
Posts: 170
Send a message via Yahoo to darkenbinary
Are the DNS requests all internal? If so try increasing the DNS timeout on the client side. It’s possible the clients aren't getting a response in a timely manner which causes them to query the server repetitively. Sometimes this issue can be caused by one machine. If your office doesn't contain a large amount of machines try shutting them down one by one, and then test to see if the issue goes away. You may be able to find the offending machine this way. This would not occur with the backup DNS if the server has a different IP, and the client is able to gain a response in a timely manner.
darkenbinary is offline   Reply With Quote
Old May 27th, 2005, 05:33 AM     #10 (permalink)
Supporting our military
 
Bill in SD, CA's Avatar
 
Join Date: Oct 2002
Location: Bottom left of U.S.
Posts: 9,197
Check for trojans with The Cleaner .

Update the definitions first.


Bill
__________________
*****
It is easy to be conspicuously "compassionate" if others are being forced to pay the cost. – Murray N. Rothbard
Bill in SD, CA is offline   Reply With Quote
Reply
Thread Tools Search this Thread
Search this Thread:

Advanced Search

Similar Threads
Thread Thread Starter Forum Replies Last Post
IE hijacked rex028 Technical Support 5 April 7th, 2005 07:51 AM
Immediate Help. network hijacked? blubomber General Tech Discussion 5 February 1st, 2005 04:37 PM
Help with Homepage being hijacked maximus01can Security and Privacy Issues 5 May 15th, 2004 07:51 AM
Hijacked browser? renton Security and Privacy Issues 3 March 8th, 2004 02:40 AM
My desktop got hijacked! consumertalks Technical Support 7 September 26th, 2003 07:24 PM


Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Most Active Discussions
Is It Just Me? (2905)
windows 7 problem (7)
CPU fan stops spinning randomly (8)
Wireless Televisions. (8)
California Passes Anti-Flat-HDTV Le.. (43)
Obama the Muslim (14)
Is the PSU I received dead? (11)
windows vista security holes (9)
HIS HD5770 graphic card question (15)
Install XP pro and a Vista laptop ?.. (11)
Print spooler problem (13)
Foreign voltage (10)
Dept. of HS: NSA 'Helped' Develop V.. (15)
A good PSU? (10)
Recent Discussions
windows 7 problem (7)
CPU fan stops spinning randomly (8)
Partition Magic caused HDD problem (3)
Is the PSU I received dead? (11)
Have you switched yet? (85)
Regular Build (4)
Point and Shoot Camera Suggestions. (2)
Modern Warfare 2 freeze (13)
Wireless Televisions. (8)
wireless user (1)
World's largest Monopoly Game using G.. (332)
Ideal cheap graph card for PC-Gaming? (17)
BIOS won't read disk when I try to fl.. (0)
Install XP pro and a Vista laptop ?? (11)
Graphics Card Upgrade Question (1)
favorit (1)
solutions for virtical white lines on.. (1)
Fire in DVD (2)
Modern Warfare For the PC (33)
radeon x850xt platinum & shader 3 (3)
Wireless Router+Cable Modems and Much.. (0)
Optical Audio A-B Switch (1)
windows vista security holes (9)
The NTDVM CPU has encountered an ille.. (24)
[F@H SPAM 11/16/09] ! 1/2 months to r.. (34)


All times are GMT -4. The time now is 12:51 PM.
TechIMO Copyright 2009 All Enthusiast, Inc.



1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28