IS Open DNS Resolver ??

bees

Well-Known Member
Joined
Oct 23, 2004
Messages
490
Reaction score
17
Location
Cape Town
A client just received this from his ISP. Please tell me what the hell this means??

=================

Hi,

We have received a complaint as outlined below, from an IP allocated to
your company. Please investigate this issue and liaise with your
client/user/employee as necessary. Please inform us of the actions taken
and the outcome of your investigations by replying to this email.

--
Kind Regards,
IS Abuse

Please find below complaint information:
----------------------------------------
Subject: [IS Open DNS Resolver] 196.215.135.XXX - 2016-02-22 01:38:11 +0200 [noreply]
Sent to: [email protected]
Assigned to:
Suspected Activity: Open DNS Resolver
Client IP Address: 196.215.135.XXX
Client IP Netblock:
Company Name: XXXXX
Service Identifier: [email protected]
Stalled Status: Client notified

ORIGINAL COMPLAINT - 214XXXX
------------------------------------------------

Hi There,

It seems that we have found an open dns resolver on 196.215.135.XXX.
Please can you get in contact with your customer to get this open dns
resolver closed / shut down.

Details below:
Open DNS Resolver IP: 196.215.135.XXX (At the time of sending this
mail)
Last Detected: 2016-02-22 01:38:11

- You can see if this open dns resolver has been closed by going to
http://dns.lookup.bl.isdsl.net/username
- More info on how this works and secure your system can be found
here: http://dns.lookup.bl.isdsl.net/faq

Thanking you in advance.

--
Kind Regards,
IS CSIRT
===========================
 
You need to check the customers router/server it is allowing others to use the connection to perform DDoS attacks. Basically accepting DNS requests and forwarding them on. Make sure port 53 has no port forwards on both tcp/udp.
Also check you DNS server is accepting requests only from your internal network (if you are running one)
 
You need to check the customers router/server it is allowing others to use the connection to perform DDoS attacks. Basically accepting DNS requests and forwarding them on. Make sure port 53 has no port forwards on both tcp/udp.
Also check you DNS server is accepting requests only from your internal network (if you are running one)

Thanks. No server, only 3 laptops and a basic router. Will check for malware as well.
 
Top
Sign up to the MyBroadband newsletter
X