[Help]DNS DNS cache poisoning attack

Discussion in 'ESET NOD32 Antivirus/Smart Security Beta' started by Martoon, Jun 29, 2011.

Thread Status:
Not open for further replies.
  1. Martoon

    Martoon Registered Member

    Joined:
    Jun 29, 2011
    Posts:
    2
    I'm running a game server on my own network and it is seems to be getting some different attacks daily, as much as I know it is the same person who is doing the DNS attack, in my country the IP changes everyday but I'm lucky his IP goes betwen 194.90.0-255.0-255, I have tryed to block his IP range but probably it isn't really working, any suggestions?

    Here you can find the log:

    http://hebrithcos.dyndns.org/log.xml
     
  2. NoobStick

    NoobStick Guest

    Joined:
    Jun 23, 2011
    Posts:
    0
    Hello Martoon
    If you do a IP lookup, is seems that it is coming from someone called netvision.net.il in Israel. -http://www.013netvision.net.il/- Regarding blocking a certain ip address maybe this link can help you: http://kb.eset.com/esetkb/index?pag...earch&viewlocale=en_US&searchid=1309444272179
    I presume you are using Eset RC 5, it that case go to " Enter advanced setup" then click on "Web and email" and got to "Web access protection" expand and go to Url address management.
    Take Care

    NoobStick :D
     
    Last edited: Jun 30, 2011
  3. Martoon

    Martoon Registered Member

    Joined:
    Jun 29, 2011
    Posts:
    2
    The ISP called netvision not the attacker, netvision is a internet provider in my country.
     
Thread Status:
Not open for further replies.