Subject: Re: Flood ping directed at a NetBSD box == loads of DNS requests
To: Chris Tribo <t1345@hopi.dtcc.edu>
From: Jed Davis <jldavis+netbsdlist@cs.oberlin.edu>
List: current-users
Date: 07/16/2002 07:21:08
Chris Tribo <t1345@hopi.dtcc.edu> writes:

> On Sun, 14 Jul 2002, Matthias Scheler wrote:
>
>> In article <Pine.D-G.4.40.0207091821570.4363-100000@zuni.dtcc.edu>,
>> 	Chris Tribo <t1345@hopi.dtcc.edu> writes:
>> > 	I have ipf running, looking at ipfstat -t. Now I flood ping my box
>> > from another machine and I see screen fulls of outgoing DNS requests.
>>
>> Are you running "ipmon"? If you do and you want to avoid this don't
>> invoke it with the option "-n".
>
> 	I am simply running the standard /etc/rc.d/ipmon script at
> startup. Which states: command_args="-D" (start as daemon)

Look at the ipmon_flags setting in /etc/rc.conf or /etc/defaults/rc.conf;
the former sources the latter, and the latter specifies "-ns" (name
lookups + syslogging).

--Jed

-- 
#!/usr/bin/perl -- ## "But life wasn't yes-no, on-off.  Life was shades of gray,
sub f{(($n,$d,@_)=@_)?(substr(## and rainbows not in the order of the spectrum."
" ExhortJavelinBus",$n&&$d/$n,1),$n?f($d##   -- L. E. Modesitt, Jr., _Adiamante_
%$n,$n,@_):&f):("\n")}print f 1461,10324,55001,444162,1208,1341,5660480,79715997