This is a discussion on Re: How to block DNS record scans ? within the Bind Users forums, part of the DNS and Related Forums category; Brett schrieb: >Find out the ip of the user scanning your domain, report them to their >provider for ...
|
|||||||
| FAQ | Members List | Calendar | Search | Today's Posts | Mark Forums Read |
|
|||
|
Brett schrieb:
>Find out the ip of the user scanning your domain, report them to their >provider for abuse and then blackhole them on your server. > > As a first step... agreed. But that shoudn't be the final solutions as he will be always one step behind a possible attacker. I would strongly suggest an intelligent IDS / IPS which recognizes such attacks and blocks them dynamically. Regards, Stefan -- (o_ Stefan Gofferje | Linux Systems Specialist //\ Reg'd Linux User #247167 | Network Security Specialist V_/_ Heckler & Koch - the original point and click interface |