Internet wide DNS scanning
We have received a request from a research group to let everyone know that they will be conducting Internet wide scanning of DNS servers. This is their request:
"Our team at the Network Architectures and Services Dept. (I8) of TU München, Germany, has started a DNS scan. This has similar goals as the scans that we have conducted for SSL and SSH in the past months. Once again, the purpose is purely scientific. The scanning machine is 131.159.14.42. We are querying DNS servers to resolve host names. We do not in any way try to compromise the servers. Additionally, the load caused by our activities should be very low on a single server. The idea of our queries is to get a better understanding of the inner workings of DNS, one of the most ubiquitous protocols of the Internet. We would it appreciate it very much if you added a comment in your database. Please note that we respond to every complaint and are happy to blocklist systems with annoyed admins."
Their purpose is scientific research. Interesting, I call scanning without permission unethical, and rude. Here is what I recommend if you do not want to be part of the research, that you block all DNS requests from that IP address. They have performed similar SSH and SSL scans in the past, from different IP addresses. What do you think? Let us know via our Contact Us page or in comments below.
Let's be careful out there!
Cheers,
Adrien de Beaupré
Intru-shun.ca Inc.
My SANS Teaching Schedule
Comments
Yes that's very interesting:)
Anonymous
Oct 17th 2013
1 decade ago
Anonymous
Oct 17th 2013
1 decade ago
Anonymous
Oct 17th 2013
1 decade ago
Institut fuer Informatik der TU Muenchen - Germany (malicious scanning)
188.95.234.0/24
131.159.0.0/16
Anonymous
Oct 17th 2013
1 decade ago
Agree. Aren't Europeans supposed to be better mannered w/ respect to privacy and so forth? Or are they just pretenders that go after big stories/deep pockets like Google, Microsoft, etc.
Anonymous
Oct 17th 2013
1 decade ago
So if I leave my keys in my car and the doors aren't locked, it's OK to drive it away?
Anonymous
Oct 17th 2013
1 decade ago
Anonymous
Oct 17th 2013
1 decade ago
"So if I leave my keys in my car and the doors aren't locked, it's OK to drive it away? "
I largely agree with the "Utilizing TCP/IP for it's intended purpose is hardly unethical..." comment.
My car is private property, whereas publicly addressable DNS is intentionally a service on the internet intended to be broadly, if not universally, available to anyone else on the internet to query.
That said, whether or not the "research" falls under the intended purpose of making one's DNS available is to me the question at hand. One could quite easily argue that such "research" probing is not within the intended purpose of making one's DNS available, particularly if it attempts to perform rather invasive probing. This seems to me a decision to be left up to each DNS owner.
TG
Anonymous
Oct 17th 2013
1 decade ago
Anonymous
Oct 17th 2013
1 decade ago