LinuxQuestions.org
Help answer threads with 0 replies.
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Software
User Name
Password
Linux - Software This forum is for Software issues.
Having a problem installing a new program? Want to know which application is best for the job? Post your question in this forum.

Notices


Reply
  Search this Thread
Old 03-06-2006, 09:42 AM   #1
MikeyCarter
Member
 
Registered: Feb 2003
Location: Orangeville
Distribution: Fedora
Posts: 492

Rep: Reputation: 31
Too Many host lookups.. Virus?


Something on my system is causing a lot of failed DNS lookups:

10:38:25.544397 IP siren.32774 > di-router.domain: 4057+ PTR? 68.205.228.85.in-addr.arpa. (44)
10:38:25.864252 IP di-router.domain > siren.32774: 4057 1/2/2 (200)
10:38:26.930259 IP siren.32774 > di-router.domain: 20400+ PTR? 182.217.27.24.in-addr.arpa. (44)
10:38:26.943762 IP di-router.domain > siren.32774: 20400 1/2/0 (138)
10:38:27.398380 IP siren.32774 > di-router.domain: 3527+ PTR? 18.5.60.84.in-addr.arpa. (41)
10:38:27.413402 IP di-router.domain > siren.32774: 3527 1/4/5 PTR[|domain]
10:38:30.920412 IP siren.32774 > di-router.domain: 50846+ PTR? 222.222.14.24.in-addr.arpa. (44)
10:38:30.983329 IP di-router.domain > siren.32774: 50846 1/2/2 (190)
10:38:31.239844 IP siren.32774 > di-router.domain: 61301+ PTR? 23.10.148.68.in-addr.arpa. (43)
10:38:31.302423 IP di-router.domain > siren.32774: 61301 1/2/2 (162)
10:38:31.434595 IP siren.32774 > di-router.domain: 40189+ PTR? 221.33.180.67.in-addr.arpa. (44)
10:38:31.570495 IP di-router.domain > siren.32774: 40189 1/2/2 (190)
10:38:32.543602 IP siren.32774 > di-router.domain: 29194+ PTR? 224.113.211.210.in-addr.arpa. (46)
10:38:32.833978 IP di-router.domain > siren.32774: 29194 1/2/2 (163)
10:38:34.024803 IP siren.32774 > di-router.domain: 13545+ PTR? 231.56.126.82.in-addr.arpa. (44)


Anyone have any idea what it is or how I can track it?

Thanks,
Michael
 
Old 03-06-2006, 10:06 AM   #2
augurseer
Member
 
Registered: Feb 2006
Location: Canada
Distribution: OpenSuSe 10.2 (Home and Laptop) CentOS 5.0 (Server)
Posts: 171

Rep: Reputation: 30
might be a software issue, some program trying to find a site that doesnt exist or a misconfigurd host file.
 
Old 03-06-2006, 10:14 AM   #3
MikeyCarter
Member
 
Registered: Feb 2003
Location: Orangeville
Distribution: Fedora
Posts: 492

Original Poster
Rep: Reputation: 31
It's not the host file as it hasn't changed in a long while. Any ideas how to track down which program is causing the problem?

Is there a way to check what programs are causing network traffic?

Thanks,
Michael
 
Old 03-06-2006, 01:02 PM   #4
MikeyCarter
Member
 
Registered: Feb 2003
Location: Orangeville
Distribution: Fedora
Posts: 492

Original Poster
Rep: Reputation: 31
Update on the problem

I started shutting things down on the server and couldn't find anything. Until I started blocking ports.

Whatever it is when I block port 6881 (BitTorrent) to the server the lookups stop. I checked and all my BitTorrent clients are shutdown.
 
Old 03-06-2006, 10:31 PM   #5
MikeyCarter
Member
 
Registered: Feb 2003
Location: Orangeville
Distribution: Fedora
Posts: 492

Original Poster
Rep: Reputation: 31
Found

I just thought I'd put this up for anyone who has a similar problem with their ISP. I got a notice from my ISP saying that:

Quote:
We have reason to believe that a computer connected through your Rogers Cable Modem has been infected by virus or has an application that is misconfigured.

Typically, these types of viruses do not affect the performance of your computer and instead carry out attacks and malicious activities behind the scenes, without your knowledge. This type of network activity has the potential to negatively impact the overall service. For your reference, we have included a technical summary of the activity for your reference at the bottom of this e-mail message.

To protect your computer and to safeguard other customers on the Rogers Yahoo! Hi-Speed Internet network, we urge you to remove the virus as quickly as possible. This can usually be done by using an updated Anti-Virus program to scan all the computers connected to your cable modem and choosing to remove the viruses.

If you are unable to remove the virus within 48 hours, we will have to take additional steps to protect other customers and the Rogers Yahoo! Hi-Speed Internet network including temporary service deactivation. Should this occur, we can reactivate your connection once the virus has been removed by calling into our call center.

If the network activity below is not the result of a Virus, we ask that you reconfigure any programs or hardware which is generating the network activity detailed below to reduce the amount of traffic or redirect it to another DNS Server.

High volumes of requests causing Error or Canned (127.0.0.1) responses usually indicate a Worm, Virus, or Bot infection. These viruses will usually attempt to connect to a controlling server or attempt to perform a Denial of Service attack on a specific server on the Internet. Once the desintation is identified, the owner of the server may remove or change the DNS entry causing future Virus infected computers to fail resolving the name. this causes an error to be generated.
Sincerely,

EUA Management Team
Rogers Yahoo Hi-Speed Internet

http://na.edit.client.yahoo.com/roge...ic?.form=terms
00285053


IP Add, Errors, Queries
xx.xx.xx.xx, 356, 1033


I managed to find the two culprits.

1. Bittorrent seems to try to do host lookups on all machines it touches. I was downloading a few linux iso's. It was causing over 400 failed attempts a minutes.

2. I have a script which scans through failed attempts reported by DenyHosts and uploads the data to my web server.

I happened to be doing the download and had all my four computers online last night. So they were all running at the same time. This triggered Rogers to think the traffic created by four computers doing backups, and downloading to report as a virus. So if your ISP is reporting heavy DNS traffic. You may want to look at the number of computers working at the same time.
 
  


Reply


Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
Mysterious DNS Lookups on private host neiljt Linux - Security 3 08-31-2004 07:31 PM
Boot virus or Anti-Virus? AVG Free Anti-Virus Software problems SparceMatrix Linux - Security 9 08-02-2004 02:35 PM
trend chipway virus detected boot virus rafc Linux - Security 1 05-13-2004 01:44 AM
Host lookups fail at first, but then succeed consistently. mikeyt_333 Linux - Networking 1 08-23-2002 01:22 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - Software

All times are GMT -5. The time now is 11:37 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration