If you are seeing queries for this domain, than you are likely participating in DNS Amplification attacks and your DNS server is probably reachable from the internet and has recursion enabled.
If you are seeing responses for this domain.. unlucky. You are currently beeing DDOS-ed! Good luck.
There are two iptable rules available. If your distribution supports Iptables 'u32' module pick this one, otherwise use the 'string' rule.
iptables --insert INPUT -p udp --dport 53 -m u32 --u32 "0x28&0xFFDFDFDF=0x03495249 && 0x2c&0xFFDFDFFF=0x02534f00" -j DROP -m comment --comment "DROP DNS Q iri.so"
More U32 rules can be found here:
iptables --insert INPUT -p udp --dport 53 -m string --from 40 --to 48 --algo bm --hex-string '|0369726902736f00|' -j DROP -m comment --comment "DROP DNS Q iri.so"
More Iptables rules for the STRING module can be found here:
No IP source for this domain
;; ANSWER SECTION:
iri.so. 600 IN NS ns1.spaceweb.ru.
iri.so. 600 IN NS ns2.spaceweb.ru.
This whois service is provided by GMO Registry and only contains
information pertaining to Internet domain names we have registered for
our customers. By using this service you are agreeing (1) not to use any
information presented here for any purpose other than determining
ownership of domain names, (2) not to store or reproduce this data in
any way, (3) not to use any high-volume, automated, electronic processes
to obtain data from this service. Abuse of this service is monitored and
actions in contravention of these terms will result in being permanently
blacklisted. All data is (c) GMO Registry http://www.gmo-registry.com/en/
Last Updated On:2013-09-25T10:13:18.0Z
Registrant Name:Kanevsky Alexandr
Registrant Street1:Dniprovska Naberejna, 26
Registrant Postal Code:02000
Admin Name:Kanevsky Alexandr
Admin Street1:Dniprovska Naberejna, 26
Admin Postal Code:02000
Tech Name:Kanevsky Alexandr
Tech Street1:Dniprovska Naberejna, 26
Tech Postal Code:02000
Billing Name:Kanevsky Alexandr
Billing Street1:Dniprovska Naberejna, 26
Billing Postal Code:02000
Sponsoring Registrar ID:subreg
Sponsoring Registrar Organization:Gransy s.r.o. d/b/a/ subreg.cz
Sponsoring Registrar Street1:Borivojova 35
Sponsoring Registrar City:Praha
Sponsoring Registrar Postal Code:135 00
Sponsoring Registrar Country:CZ
Sponsoring Registrar Phone:+420.420732954549
This is a fantastic post,very well authored and easy to understand.Thanks so much for thisReplyDelete
Domain Registration Bangalore
Linux Hosting Bangalore
This help me a lot :) I was under an attack, and just blocked the input with dst port 53 en drop the packets and my network is back again. This in RouterOS Thanks for the advice.ReplyDelete
I am suffering from this... how do I block it? windows server 2008 r2ReplyDelete
In windows server disable recursion. If you need recursion than you shoul consider split dns design.ReplyDelete
No so good option: create iri.so dummy zone and add iri in global query blok list.
You should do split DNS. Outside should not be recursive.Delete