What can cause excessive amount of _dns-sd queries?

Eivind Olsen eivind at aminor.no
Thu Aug 23 11:43:32 UTC 2012


I haven't seen this before.. I'm currently seeing someone (1 ip address)
do about 2.1 million queries / hour where a majority of the queries seem
to be:

b._dns-sd._udp. IN PTR +
db._dns-sd._udp. IN PTR +
r._dns-sd._udp. IN PTR +
talk.l.google.com IN A +
gmail-pop.l.google.com IN A +
gmail-imap.l.google.com IN A +

...and similar variations of these.

Have any of you seen something like this before?

Eivind Olsen

