Go Back   Wireless and Wifi Forums > News > Newsgroups > comp.security.misc
Register FAQ Forum Rules Members List Calendar Search Today's Posts Advertise Mark Forums Read

 
Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 08-17-2012, 12:57 PM
W
Guest
 
Posts: n/a
Default Windows XP Problem Seeing DNS Responses

On our Windows XP and Windows 2003 work computers, we are having some kind
of DNS catastrophe. Clients get into a mode for five to 20 minutes at a
time, during which they cannot *receive* responses from a DNS query.

Put one sniffer on the client computer, and put a second sniffer on the
client network side of a firewall. The firewall sniffer sees the
following:

client requests A record for host xyz from DNS server
client requests A record for host xyz from DNS server
client requests A record for host xyz from DNS server
...
DNS server responds with IP for host xyz
DNS server responds with IP for host xyz
DNS server responds with IP for host xyz

The DNS response seems to target the mac address of the correct client
computer.

But run a sniffer on the client and what you see is only the request and not
the DNS response!!! The client goes into a panic and starts to try to grab
DNS records for domain, and basically nothing resolves. The client
computer is marooned.

This is absolutely as bizarre a situation as I have seen. It literally
looks like the traffic is being shaped by something on the client, and even
though there are responses to the DNS inquiries generated, the client either
doesn't get them or doesn't process them.

Is there any known issue with recent Windows Updates that might cause this
problem? Does this sound like any known trojan?

--
W



Reply With Quote
  #2 (permalink)  
Old 08-17-2012, 01:20 PM
David H. Lipman
Guest
 
Posts: n/a
Default Re: Windows XP Problem Seeing DNS Responses

From: "W" <persistentone@spamarrest.com>

> On our Windows XP and Windows 2003 work computers, we are having some kind
> of DNS catastrophe. Clients get into a mode for five to 20 minutes at a
> time, during which they cannot *receive* responses from a DNS query.
>
> Put one sniffer on the client computer, and put a second sniffer on the
> client network side of a firewall. The firewall sniffer sees the
> following:
>
> client requests A record for host xyz from DNS server
> client requests A record for host xyz from DNS server
> client requests A record for host xyz from DNS server
> ...
> DNS server responds with IP for host xyz
> DNS server responds with IP for host xyz
> DNS server responds with IP for host xyz
>
> The DNS response seems to target the mac address of the correct client
> computer.
>
> But run a sniffer on the client and what you see is only the request and
> not
> the DNS response!!! The client goes into a panic and starts to try to
> grab
> DNS records for domain, and basically nothing resolves. The client
> computer is marooned.
>
> This is absolutely as bizarre a situation as I have seen. It literally
> looks like the traffic is being shaped by something on the client, and
> even
> though there are responses to the DNS inquiries generated, the client
> either
> doesn't get them or doesn't process them.
>
> Is there any known issue with recent Windows Updates that might cause this
> problem? Does this sound like any known trojan?
>


Are you using AT&T ?



--
Dave
Multi-AV Scanning Tool - http://multi-av.thespykiller.co.uk
http://www.pctipp.ch/downloads/dl/35905.asp


Reply With Quote
  #3 (permalink)  
Old 08-17-2012, 01:30 PM
W
Guest
 
Posts: n/a
Default Re: Windows XP Problem Seeing DNS Responses

"David H. Lipman" <DLipman~nospam~@Verizon.Net> wrote in message
news:yuadnb_yQpx72bPNnZ2dnUVZ_smdnZ2d@giganews.com ...
> From: "W" <persistentone@spamarrest.com>
>
> > On our Windows XP and Windows 2003 work computers, we are having some

kind
> > of DNS catastrophe. Clients get into a mode for five to 20 minutes at

a
> > time, during which they cannot *receive* responses from a DNS query.
> >
> > Put one sniffer on the client computer, and put a second sniffer on the
> > client network side of a firewall. The firewall sniffer sees the
> > following:
> >
> > client requests A record for host xyz from DNS server
> > client requests A record for host xyz from DNS server
> > client requests A record for host xyz from DNS server
> > ...
> > DNS server responds with IP for host xyz
> > DNS server responds with IP for host xyz
> > DNS server responds with IP for host xyz
> >
> > The DNS response seems to target the mac address of the correct client
> > computer.
> >
> > But run a sniffer on the client and what you see is only the request and
> > not
> > the DNS response!!! The client goes into a panic and starts to try to
> > grab
> > DNS records for domain, and basically nothing resolves. The client
> > computer is marooned.
> >
> > This is absolutely as bizarre a situation as I have seen. It literally
> > looks like the traffic is being shaped by something on the client, and
> > even
> > though there are responses to the DNS inquiries generated, the client
> > either
> > doesn't get them or doesn't process them.
> >
> > Is there any known issue with recent Windows Updates that might cause

this
> > problem? Does this sound like any known trojan?

>
> Are you using AT&T ?


Yes

--
W



Reply With Quote
  #4 (permalink)  
Old 08-17-2012, 01:33 PM
W
Guest
 
Posts: n/a
Default Re: Windows XP Problem Seeing DNS Responses

"David H. Lipman" <DLipman~nospam~@Verizon.Net> wrote in message
news:yuadnb_yQpx72bPNnZ2dnUVZ_smdnZ2d@giganews.com ...
> From: "W" <persistentone@spamarrest.com>
>
> > On our Windows XP and Windows 2003 work computers, we are having some

kind
> > of DNS catastrophe. Clients get into a mode for five to 20 minutes at

a
> > time, during which they cannot *receive* responses from a DNS query.
> >
> > Put one sniffer on the client computer, and put a second sniffer on the
> > client network side of a firewall. The firewall sniffer sees the
> > following:
> >
> > client requests A record for host xyz from DNS server
> > client requests A record for host xyz from DNS server
> > client requests A record for host xyz from DNS server
> > ...
> > DNS server responds with IP for host xyz
> > DNS server responds with IP for host xyz
> > DNS server responds with IP for host xyz
> >
> > The DNS response seems to target the mac address of the correct client
> > computer.
> >
> > But run a sniffer on the client and what you see is only the request and
> > not
> > the DNS response!!! The client goes into a panic and starts to try to
> > grab
> > DNS records for domain, and basically nothing resolves. The client
> > computer is marooned.
> >
> > This is absolutely as bizarre a situation as I have seen. It literally
> > looks like the traffic is being shaped by something on the client, and
> > even
> > though there are responses to the DNS inquiries generated, the client
> > either
> > doesn't get them or doesn't process them.
> >
> > Is there any known issue with recent Windows Updates that might cause

this
> > problem? Does this sound like any known trojan?
> >

>
> Are you using AT&T ?


I guess I should make explicit that the DNS server I am referring to above
is our Windows 2003 domain controller, and the host XYZ referenced above is
our *internal* host.

There is no issue about resolving Internet hosts.

--
W



Reply With Quote
  #5 (permalink)  
Old 08-17-2012, 04:09 PM
David H. Lipman
Guest
 
Posts: n/a
Default Re: Windows XP Problem Seeing DNS Responses

From: "W" <persistentone@spamarrest.com>

> "David H. Lipman" <DLipman~nospam~@Verizon.Net> wrote in message
> news:yuadnb_yQpx72bPNnZ2dnUVZ_smdnZ2d@giganews.com ...
>> From: "W" <persistentone@spamarrest.com>
>>
>>> On our Windows XP and Windows 2003 work computers, we are having some

> kind
>>> of DNS catastrophe. Clients get into a mode for five to 20 minutes at

> a
>>> time, during which they cannot *receive* responses from a DNS query.
>>>
>>> Put one sniffer on the client computer, and put a second sniffer on the
>>> client network side of a firewall. The firewall sniffer sees the
>>> following:
>>>
>>> client requests A record for host xyz from DNS server
>>> client requests A record for host xyz from DNS server
>>> client requests A record for host xyz from DNS server
>>> ...
>>> DNS server responds with IP for host xyz
>>> DNS server responds with IP for host xyz
>>> DNS server responds with IP for host xyz
>>>
>>> The DNS response seems to target the mac address of the correct client
>>> computer.
>>>
>>> But run a sniffer on the client and what you see is only the request and
>>> not
>>> the DNS response!!! The client goes into a panic and starts to try to
>>> grab
>>> DNS records for domain, and basically nothing resolves. The client
>>> computer is marooned.
>>>
>>> This is absolutely as bizarre a situation as I have seen. It literally
>>> looks like the traffic is being shaped by something on the client, and
>>> even
>>> though there are responses to the DNS inquiries generated, the client
>>> either
>>> doesn't get them or doesn't process them.
>>>
>>> Is there any known issue with recent Windows Updates that might cause

> this
>>> problem? Does this sound like any known trojan?

>>
>> Are you using AT&T ?

>
> Yes
>

AT&T is uder a massive DDoS attack on their respective DNS servers

http://www.pcworld.com/businesscente...ns_outage.html



--
Dave
Multi-AV Scanning Tool - http://multi-av.thespykiller.co.uk
http://www.pctipp.ch/downloads/dl/35905.asp


Reply With Quote
  #6 (permalink)  
Old 08-17-2012, 08:45 PM
W
Guest
 
Posts: n/a
Default Re: Windows XP Problem Seeing DNS Responses

"David H. Lipman" <DLipman~nospam~@Verizon.Net> wrote in message
news:UpednV73ue8P8bPNnZ2dnUVZ_r-dnZ2d@giganews.com...
> From: "W" <persistentone@spamarrest.com>
>
> > "David H. Lipman" <DLipman~nospam~@Verizon.Net> wrote in message
> > news:yuadnb_yQpx72bPNnZ2dnUVZ_smdnZ2d@giganews.com ...
> >> From: "W" <persistentone@spamarrest.com>
> >>
> >>> On our Windows XP and Windows 2003 work computers, we are having some

> > kind
> >>> of DNS catastrophe. Clients get into a mode for five to 20 minutes

at
> > a
> >>> time, during which they cannot *receive* responses from a DNS query.
> >>>
> >>> Put one sniffer on the client computer, and put a second sniffer on

the
> >>> client network side of a firewall. The firewall sniffer sees the
> >>> following:
> >>>
> >>> client requests A record for host xyz from DNS server
> >>> client requests A record for host xyz from DNS server
> >>> client requests A record for host xyz from DNS server
> >>> ...
> >>> DNS server responds with IP for host xyz
> >>> DNS server responds with IP for host xyz
> >>> DNS server responds with IP for host xyz
> >>>
> >>> The DNS response seems to target the mac address of the correct client
> >>> computer.
> >>>
> >>> But run a sniffer on the client and what you see is only the request

and
> >>> not
> >>> the DNS response!!! The client goes into a panic and starts to try

to
> >>> grab
> >>> DNS records for domain, and basically nothing resolves. The client
> >>> computer is marooned.
> >>>
> >>> This is absolutely as bizarre a situation as I have seen. It

literally
> >>> looks like the traffic is being shaped by something on the client, and
> >>> even
> >>> though there are responses to the DNS inquiries generated, the client
> >>> either
> >>> doesn't get them or doesn't process them.
> >>>
> >>> Is there any known issue with recent Windows Updates that might cause

> > this
> >>> problem? Does this sound like any known trojan?
> >>
> >> Are you using AT&T ?

> >
> > Yes
> >

> AT&T is uder a massive DDoS attack on their respective DNS servers
>
>

http://www.pcworld.com/businesscente...ns_outage.html

If you don't use ATT for DNS, this shouldn't affect you?

--
W



Reply With Quote
  #7 (permalink)  
Old 08-17-2012, 11:25 PM
David H. Lipman
Guest
 
Posts: n/a
Default Re: Windows XP Problem Seeing DNS Responses

From: "W" <persistentone@spamarrest.com>

> "David H. Lipman" <DLipman~nospam~@Verizon.Net> wrote in message
> news:UpednV73ue8P8bPNnZ2dnUVZ_r-dnZ2d@giganews.com...
>> From: "W" <persistentone@spamarrest.com>
>>
>>> "David H. Lipman" <DLipman~nospam~@Verizon.Net> wrote in message
>>> news:yuadnb_yQpx72bPNnZ2dnUVZ_smdnZ2d@giganews.com ...
>>>> From: "W" <persistentone@spamarrest.com>
>>>>
>>>>> On our Windows XP and Windows 2003 work computers, we are having some
>>> kind
>>>>> of DNS catastrophe. Clients get into a mode for five to 20 minutes

> at
>>> a
>>>>> time, during which they cannot *receive* responses from a DNS query.
>>>>>
>>>>> Put one sniffer on the client computer, and put a second sniffer on

> the
>>>>> client network side of a firewall. The firewall sniffer sees the
>>>>> following:
>>>>>
>>>>> client requests A record for host xyz from DNS server
>>>>> client requests A record for host xyz from DNS server
>>>>> client requests A record for host xyz from DNS server
>>>>> ...
>>>>> DNS server responds with IP for host xyz
>>>>> DNS server responds with IP for host xyz
>>>>> DNS server responds with IP for host xyz
>>>>>
>>>>> The DNS response seems to target the mac address of the correct client
>>>>> computer.
>>>>>
>>>>> But run a sniffer on the client and what you see is only the request

> and
>>>>> not
>>>>> the DNS response!!! The client goes into a panic and starts to try

> to
>>>>> grab
>>>>> DNS records for domain, and basically nothing resolves. The client
>>>>> computer is marooned.
>>>>>
>>>>> This is absolutely as bizarre a situation as I have seen. It

> literally
>>>>> looks like the traffic is being shaped by something on the client, and
>>>>> even
>>>>> though there are responses to the DNS inquiries generated, the client
>>>>> either
>>>>> doesn't get them or doesn't process them.
>>>>>
>>>>> Is there any known issue with recent Windows Updates that might cause
>>> this
>>>>> problem? Does this sound like any known trojan?
>>>>
>>>> Are you using AT&T ?
>>>
>>> Yes
>>>

>> AT&T is uder a massive DDoS attack on their respective DNS servers
>>

> http://www.pcworld.com/businesscente...ns_outage.html
>
> If you don't use ATT for DNS, this shouldn't affect you?
>


Correct (assuming other servers desired aren't being DDoS'd as well).
For example the public DNS Servers listed here

http://theos.in/windows-xp/free-fast...s-server-list/



--
Dave
Multi-AV Scanning Tool - http://multi-av.thespykiller.co.uk
http://www.pctipp.ch/downloads/dl/35905.asp


Reply With Quote
Reply


Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is Off
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


Similar Threads
Thread Thread Starter Forum Replies Last Post
Unusual website traffic November 5 alt.comp.hardware 3 10-06-2010 04:01 PM
Connection problem with WPA2 Enterprise with Windows Vista (HomePremium) =?ISO-8859-1?Q?=C0ngel_Catal=E0?= alt.internet.wireless 11 05-15-2009 08:30 PM
adding ram and windows problem halex2000 alt.comp.hardware 11 01-14-2007 11:17 AM
system restart Problem anis alt.comp.hardware 0 08-29-2005 10:35 AM


All times are GMT. The time now is 01:10 AM.



Powered by vBulletin® Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.6.0 PL2

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45