stopping continuous unapproved AXFR

Bill Moseley moseley at hank.org
Wed Jul 12 00:41:01 UTC 2000


Howdy,

Every five minutes for about three days now I've been seeing this:

   unapproved AXFR from [205.229.206.20].{varying ports}

It's not one of my secondaries, not one I have listed and know about, anyway.

Not that it bugs me that much, but is there much one can do to try to stop
the requests?  I poked around 205.229.206.20 and didn't find much (like an
smtp host to mail).

I figured if they are asking me for info I can ask them for info too.  Hope
they don't mind...

> nmap -sS -O 205.229.206.20

Starting nmap V. 2.3BETA6 by Fyodor (fyodor at dhp.com, www.insecure.org/nmap/)
Interesting ports on  (205.229.206.20):
Port    State       Protocol  Service
53      open        tcp       domain                  
80      open        tcp       http                    
135     open        tcp       loc-srv                 
443     open        tcp       https                   
1030    open        tcp       iad1                    

TCP Sequence Prediction: Class=trivial time dependency
                         Difficulty=6 (Trivial joke)
Remote operating system guess: Windows NT4 / Win95 / Win98


Bill Moseley
mailto:moseley at hank.org



More information about the bind-users mailing list