PDA

View Full Version : Is this a hack attempt?


SergioC
11-27-06, 06:16 AM
Hi all,
once again asking for your knowledge...

In am receiving this messages from my firewall:

Nov 27 08:32:48 dominios named[31213]: client 200.49.169.218#60762: updating zone 'grupoti.com/IN': update failed: 'RRset exists (value dependent)' prerequisite not satisfied (NXRRSET)

But the IP 200.49.169.218 has no rights to modify the ZONE of any of my accounts, so my question is, is this an attempt to hack one of the domains in my server?

Your input, as always, is appreciated.

Regards.

WSHosting
11-27-06, 06:20 PM
The most probable is Yes.

Regards,
WSHosting

MattGe
11-28-06, 05:38 AM
WSHosting rights. Most likely you have cracked.

SergioC
11-28-06, 05:49 AM
I discovered that the IP that is trying to modify the ZONE is my customer own IP, could it be that his router is doing this? I assume it is because yesterday I got a lot of messages about this, but it ends when they closed the office. So, my question now is, could a router do this?

Any way, the firewall is working just fine stoping any attempt of modifying the zone.

SergioC
12-03-06, 08:56 AM
UPDATE

Finally, thanks to the help of Jonathan at Configserver, I learned what happened. It is not a hack attempt nor even close to that, I was almost right about what it was, the customer has a router that was configured to point to my server and that is why it was attempting to enter into port 53, so I configured my CSF firewall and fixed the error.

Thanks to all that replied to this post.

Regards.

kyledylanconner
12-30-07, 09:25 PM
Dang...things were getting exciting too when you said it may be a hack. heh.

liammc1
01-03-08, 01:18 PM
I advise you to use CSF or APBF

kromaser
02-21-09, 06:33 PM
sYour input, as always, is appreciated.

rackaid
05-12-09, 07:51 AM
UPDATE

It is not a hack attempt nor even close to that, I was almost right about what it was, the customer has a router that was configured to point to my server and that is why it was attempting to enter into port 53, so I configured my CSF firewall and fixed the error.


Regards.

I see this pretty common with some clients that have on-premise equipment. They erroneously point their internal systems at their server and enable things like dynamic DNS.