Real Geek Forums  

Go Back   Real Geek Forums > Archives > Operating Systems > Windows Vista > Windows Vista Networking & Sharing

Notices

Reply

Vista machine denial of service attacks to DNS ?

 

LinkBack Thread Tools Display Modes
Old 02-29-2008, 03:27 PM   #1 (permalink)
Default Vista machine denial of service attacks to DNS ?

A number of times we have seen windows vista hosts on our Residential
Network (ie machines in student rooms) "Attack" our DNS service.

Most of these events seem to involve a pair of machines sending large
numbers of data packets on dest port 53 > 4,000 per second to both
the primary and secondary DNS servers. Note the port is limited to
10mbps... I have wondered what would have happened if it was 100/1000!!



Investigations and packet captures have revealed:



- The machines are always vista machines

- The DNS requests are attached to a single process. This
appears to be "sharedAccess"

- There appear to be two separate states. Hosts which have
been involved seem to send abnormal numbers of DNS requests under
"normal" operation (state 1), roughly 10pps. Then, somehow an
interatction with another machine (I guess) causes the bombardment .

- The Vista machines seem to be "clean" of virus infection

- Whilst looking at said machines, I have been unable to
replicate an "attack event"

Has anyone seen similar and is it reparable in a service pack for
vista ?






Shera
Guest
 
Posts: n/a
Reply With Quote  
Reply

Tags
None

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


Similar Threads

Thread Thread Starter Forum Replies Last Post
Sync between Vista machine and External Hard Drive and XP Machine bobd Windows Vista File Management 1 01-01-2008 03:55 PM
ZoneAlarm Advertising Blocking Denial of Service Vulnerability JM Tella Llop [MVP Windows] Windows XP Configuration & Management 0 11-21-2004 05:10 PM
IBM HTTP Server Denial of Service Vulnerabilities JM Tella Llop [MVP Windows] Windows XP Configuration & Management 0 11-21-2004 05:09 PM
RPC Denial of Service Jerry Halbert Windows XP Network & Web 0 08-28-2003 06:18 PM
There seems to be a massive denial of service attack going on Mark Jerome Windows XP Security & Administration 7 08-12-2003 07:26 PM


All times are GMT. The time now is 11:26 PM.


Powered by vBulletin® Version 3.7.1
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Copyright © 2005 - 2007 RealGeek.com. All rights reserved.

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85 86 87 88 89 90