Configuring DNS Black Hole on Win2003 Server running Plesk

Posted on 2010-08-14
Last Modified: 2013-11-08
Hi all,

I was wondering if anyone could help me configure DNS to deny access or else based on third party dns black lists.

My server has several websites open for sql injection and Id like to stop it, first by identifying the IP addresses or domains of the ofenders and denying them access to the websites.

I'm new to all this, so if you can give me clear instructions and suggestions, I appreciate it.


Question by:Ederwainer
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 3
  • 3

Expert Comment

ID: 33436411
you can confogire this in  iis in secuirty tab and define which ip you want to access your web

Author Comment

ID: 33436488
Yes, I've come to that option, however, the offenders of my server are the same all over the internet.
So instead of entering them manually one by one, I'd rather get a list from another source and just update it once in a while.

One problem in doing it the way you suggested is that I do not know how to recognize the offender on the traffic logs.

If anybody can help me with identifying them, I'll go with IP blocking for now, as the situation is an emergency.



Assisted Solution

lscarbor earned 500 total points
ID: 33442592
port 1433 is (normally) access to sql via tsql-- wouldn't blocking it with a firewall and making sure that the only access is internal solve the problem? You don't need to know all the possible sources (unless I don't understand how you are using it).
If you block it at the firewall pointed to the ISP you end access for all.
Visualize your virtual and backup environments

Create well-organized and polished visualizations of your virtual and backup environments when planning VMware vSphere, Microsoft Hyper-V or Veeam deployments. It helps you to gain better visibility and valuable business insights.


Accepted Solution

lscarbor earned 500 total points
ID: 33442594
Here's someone showing how to block unauthorized access in a hosting situation:

Author Comment

ID: 33447925
Hi Iscarbor.

So far I have done nothing but patch a few websites and clean the infected databases.
Today we applied a patch to one of them and will monitor for the following days to see if it solved the problem.

In the meantime I will look into what you suggested and will post back soon.

Thanks for your help so far.


Expert Comment

ID: 33448054
I'm happy that you have it working! Thanks for the update.

Author Closing Comment

ID: 34472238
You gave me some very straiht forward solution to the problem.
Thank you so very much!

Featured Post

Is Your Team Achieving Their Full Potential?

74% of employees feel they are not achieving their full potential. With Linux Academy, not only will you strengthen your team's core competencies but also their knowledge of of the newest IT topics.

With new material every week, we'll make sure that you stay ahead of the game.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

I wrote this article to explain some important DNS concepts that should be known to avoid some typical configuration errors I often see in forums. I assume that what is described here is the typical behavior of Microsoft DNS client. I don't know …
Resolve DNS query failed errors for Exchange
Connecting to an Amazon Linux EC2 Instance from Windows Using PuTTY.
This demo shows you how to set up the containerized NetScaler CPX with NetScaler Management and Analytics System in a non-routable Mesos/Marathon environment for use with Micro-Services applications.

734 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question