<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How to find proigram performing dns lookups? in Tech Help - Software/Hardware etc</title>
    <link>https://community.plus.net/t5/Tech-Help-Software-Hardware-etc/How-to-find-proigram-performing-dns-lookups/m-p/1934488#M94953</link>
    <description>&lt;P&gt;Does the DNS server have any logging? That's the first place I'd look. Failing that, you could always use Wireshark.&lt;/P&gt;</description>
    <pubDate>Sat, 19 Aug 2023 08:50:07 GMT</pubDate>
    <dc:creator>bobpullen</dc:creator>
    <dc:date>2023-08-19T08:50:07Z</dc:date>
    <item>
      <title>How to find proigram performing dns lookups?</title>
      <link>https://community.plus.net/t5/Tech-Help-Software-Hardware-etc/How-to-find-proigram-performing-dns-lookups/m-p/1934352#M94946</link>
      <description>&lt;P&gt;I have a windows VPS - windows server 2012.&lt;/P&gt;
&lt;P&gt;Being a bit of a nerd, i installed my experimental dns server on it. It's run on my PC flawlessly for years with minimal fuss as a windows service.&lt;/P&gt;
&lt;P&gt;On the VPS, I leave it running as a GUI in the admins remote desktop session. The VPS is setup in windows networking to use my dns server and the dns server configured to googles dns servers.&lt;/P&gt;
&lt;P&gt;Each day when i log into the VPS by remote desktop, I look at the dns server and see that there are multiple lookups for mail.ru - a russian email service.&lt;/P&gt;
&lt;P&gt;I have minimal software installed on the server - uniformserver (a wamp setup) filezilla ftp server, my dns server, Mercury 32 email server and that's about it.&lt;/P&gt;
&lt;P&gt;How do i find the program that is making these outbound requests? - Like many, i don't feel comfortable with some random program on my VPS trying to phone home to a russian email service. For the time being i've created a zone on the dns server and set the A record to 127.0.0.1 so it's blocked but i still want the process gone!&lt;/P&gt;</description>
      <pubDate>Fri, 18 Aug 2023 11:01:30 GMT</pubDate>
      <guid>https://community.plus.net/t5/Tech-Help-Software-Hardware-etc/How-to-find-proigram-performing-dns-lookups/m-p/1934352#M94946</guid>
      <dc:creator>7up</dc:creator>
      <dc:date>2023-08-18T11:01:30Z</dc:date>
    </item>
    <item>
      <title>Re: How to find proigram performing dns lookups?</title>
      <link>https://community.plus.net/t5/Tech-Help-Software-Hardware-etc/How-to-find-proigram-performing-dns-lookups/m-p/1934487#M94952</link>
      <description>&lt;P&gt;Is your DNS only providing lookups for the services within your VPS, or are you using it as the local DNS for other devices in your home ?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I ask because I also have a DNS setup where I can check which domains have been looked up, and can see those that have been blocked by various filtering rules, or have been stopped by my 'blacklist'.&amp;nbsp; I see a flurry of dangerous looking requests to Russian, Chinese, and other suspicious addresses when my daughter uses her Android phone or Chromebook to watch K-pop music videos, or browsing Korean fashion clothing websites - which are FULL of intrusive adverts.&amp;nbsp; When she uses an ad-blocker in her browser, the dodgy DNS lookups disappear, so it looks to me like the display of the animated adverts is the source of the potentially dangerous DNS requests.&lt;/P&gt;
&lt;P&gt;.&lt;/P&gt;</description>
      <pubDate>Sat, 19 Aug 2023 08:45:30 GMT</pubDate>
      <guid>https://community.plus.net/t5/Tech-Help-Software-Hardware-etc/How-to-find-proigram-performing-dns-lookups/m-p/1934487#M94952</guid>
      <dc:creator>Anonymous</dc:creator>
      <dc:date>2023-08-19T08:45:30Z</dc:date>
    </item>
    <item>
      <title>Re: How to find proigram performing dns lookups?</title>
      <link>https://community.plus.net/t5/Tech-Help-Software-Hardware-etc/How-to-find-proigram-performing-dns-lookups/m-p/1934488#M94953</link>
      <description>&lt;P&gt;Does the DNS server have any logging? That's the first place I'd look. Failing that, you could always use Wireshark.&lt;/P&gt;</description>
      <pubDate>Sat, 19 Aug 2023 08:50:07 GMT</pubDate>
      <guid>https://community.plus.net/t5/Tech-Help-Software-Hardware-etc/How-to-find-proigram-performing-dns-lookups/m-p/1934488#M94953</guid>
      <dc:creator>bobpullen</dc:creator>
      <dc:date>2023-08-19T08:50:07Z</dc:date>
    </item>
    <item>
      <title>Re: How to find proigram performing dns lookups?</title>
      <link>https://community.plus.net/t5/Tech-Help-Software-Hardware-etc/How-to-find-proigram-performing-dns-lookups/m-p/1934535#M94954</link>
      <description>&lt;P&gt;I was just checking my DNS and firewall logs and discovered an attacker with a sense of humour !&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screenshot 2023-08-19 at 15-05-39 - Status System Logs Firewall Normal View.png"&gt;&lt;img src="https://community.plus.net/skins/images/A0C0974F08C2F141307C5AA348823F1B/responsive_peak/images/image_not_found.png" alt="Screenshot 2023-08-19 at 15-05-39 - Status System Logs Firewall Normal View.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;"&lt;FONT face="andale mono,times"&gt;security.criminalip.com&lt;/FONT&gt;"&amp;nbsp;&amp;nbsp; &lt;span class="lia-unicode-emoji" title=":rolling_on_the_floor_laughing:"&gt;🤣&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;.&lt;/P&gt;</description>
      <pubDate>Sat, 19 Aug 2023 14:10:46 GMT</pubDate>
      <guid>https://community.plus.net/t5/Tech-Help-Software-Hardware-etc/How-to-find-proigram-performing-dns-lookups/m-p/1934535#M94954</guid>
      <dc:creator>Anonymous</dc:creator>
      <dc:date>2023-08-19T14:10:46Z</dc:date>
    </item>
  </channel>
</rss>

