A Windows Vista forum. Vista Banter

Welcome to Vista Banter.

You are currently viewing our boards as a guest which gives you limited access to view most discussions, articles and access our other FREE features. By joining our free community you will have access to ask questions and reply to others posts, upload your own photos and access many other special features. Registration is fast, simple and absolutely free so please, join our community today!

If you have any problems with the registration process or your account login, please contact contact support.

Go Back   Home » Vista Banter forum » Microsoft Windows Vista » Networking with Windows Vista
Site Map Home Register Authors List Search Today's Posts Mark Forums Read Web Partners

Networking with Windows Vista Networking issues and questions with Windows Vista. (microsoft.public.windows.vista.networking_sharing)

Vista machine denial of service attacks to DNS ?



 
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old February 29th 08, 03:27 PM posted to microsoft.public.windows.vista.networking_sharing
Shera
external usenet poster
 
Posts: 1
Default Vista machine denial of service attacks to DNS ?

A number of times we have seen windows vista hosts on our Residential
Network (ie machines in student rooms) "Attack" our DNS service.

Most of these events seem to involve a pair of machines sending large
numbers of data packets on dest port 53 4,000 per second to both
the primary and secondary DNS servers. Note the port is limited to
10mbps... I have wondered what would have happened if it was 100/1000!!



Investigations and packet captures have revealed:



- The machines are always vista machines

- The DNS requests are attached to a single process. This
appears to be "sharedAccess"

- There appear to be two separate states. Hosts which have
been involved seem to send abnormal numbers of DNS requests under
"normal" operation (state 1), roughly 10pps. Then, somehow an
interatction with another machine (I guess) causes the bombardment .

- The Vista machines seem to be "clean" of virus infection

- Whilst looking at said machines, I have been unable to
replicate an "attack event"

Has anyone seen similar and is it reparable in a service pack for
vista ?






 




Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT. The time now is 07:13 PM.


Powered by vBulletin® Version 3.6.4
Copyright ©2000 - 2012, Jelsoft Enterprises Ltd.Search Engine Optimization by vBSEO 3.0.0 RC6
Copyright ©2004-2012 Vista Banter.
The comments are property of their posters.