[nsp-sec] Moniker

Hank Nussbacher hank at efes.iucc.ac.il
Wed Feb 18 03:10:37 EST 2009


I have some strange issues from Moniker.  It appears that they have lost a 
number of CNAME records yet A records come through fine.  At one point they 
said this is because they are under a DOS attack - anyone ever see any sort 
of DNS attack that only affects CNAMEs?

I have found all 4 of their servers located in the same LA area:

ns1.domainservice.com. [208.73.210.41]
ns2.domainservice.com. [208.73.211.42]
ns3.domainservice.com. [208.73.210.43]
ns4.domainservice.com. [208.73.211.44]

Not the greatest setup, but I would be curious if anyone has seen any sort 
of attack on the Moniker DNS servers.  I also note that port 53 is closed 
to all 4 of those servers.  Is that just me?

Any info or clue on this would be helpful.

Thanks,
Hank




More information about the nsp-security mailing list