DNS blokkeren

Hoe ging dat

  • onderzoeken gegevens van spammers domeinen
  • zoeken van DNS servers voor alleen spam
  • daarnaar uitgaand UDP poort 53 blokkeren
  • verschuiving IP adressen ervan waarnemen
  • uitgaand UDP poort 53 naar subnetten blokken
  • DNS van subdomeinen werd elders gezet

Hoe werkt dat

  • heel goed
  • collectie van spammer domeinnamen

  fred@videns:~ > host -t ns 1sthomesearch.com
  1sthomesearch.com is an alias for www.1sthomesearch.com.
  fred@videns:~ > host -v -t ns 1sthomesearch.com A.GTLD-SERVERS.NET.
  ...
  ;; QUESTION SECTION:
  ;1sthomesearch.com.             IN      NS

  ;; ANSWER SECTION:
  1sthomesearch.com.      172800  IN      NS      dns1.name-services.com.
  1sthomesearch.com.      172800  IN      NS      dns2.name-services.com.
  1sthomesearch.com.      172800  IN      NS      dns3.name-services.com.
  1sthomesearch.com.      172800  IN      NS      dns4.name-services.com.
  1sthomesearch.com.      172800  IN      NS      dns5.name-services.com.

  fred@videns:~ > host -v -t ns BLIND.AE NS-AE.RIPE.NET.
  ...
  ;; QUESTION SECTION:
  ;BLIND.AE.                      IN      NS

  ;; AUTHORITY SECTION:
  BLIND.AE.               10800   IN      NS      ns1.superbtechnologies.com.
  BLIND.AE.               10800   IN      NS      ns2.superbtechnologies.com.

  fred@videns:~ > host -v -t ns ns1.superbtechnologies.com. A.GTLD-SERVERS.NET.
  ;; QUESTION SECTION:
  ;ns1.superbtechnologies.com.    IN      NS

  ;; AUTHORITY SECTION:
  superbtechnologies.com. 172800  IN      NS      dns1.name-services.com.
  superbtechnologies.com. 172800  IN      NS      dns2.name-services.com.
  superbtechnologies.com. 172800  IN      NS      dns3.name-services.com.
  superbtechnologies.com. 172800  IN      NS      dns4.name-services.com.
  superbtechnologies.com. 172800  IN      NS      dns5.name-services.com.

  fred@videns:~ > host -t ns 105.149.120.65.4homeincome.com
  105.149.120.65.4homeincome.com has no NS record
  fred@videns:~ > host -t ns 4homeincome.com
  4homeincome.com name server dns2.name-services.com.
  4homeincome.com name server dns5.name-services.com.
  4homeincome.com name server dns4.name-services.com.
  4homeincome.com name server dns3.name-services.com.
  4homeincome.com name server dns1.name-services.com.