repeated 16 hour interval spike in authoritative PTR lookups

jm9386 jm9386 at att.com
Wed Jan 9 19:41:17 UTC 2019


We have been noticing repeated LARGE spikes in in-addr.arpa queries for PTR
records in arpa zones we are authoritative for.  It looks like network
scanning, or data mining, perhaps nmap processes or something.  It started
roughly beginning of December and re-occurs roughly every 16 hours.   Im
wondering if anyone else who manages a large number of in-addr.arpa zones
(read thousands and thousands) have seen similar traffic patterns since the
beginning of December.

Jeremy



--
Sent from: http://bind-users-forum.2342410.n4.nabble.com/


More information about the bind-users mailing list