Solved

Find source of DNS reuquest

Posted on 2010-11-26
8
336 Views
Last Modified: 2012-05-10
I am trying to trace back to the source of a DNS reuquest.  I can see the request to a BAD IP ADDRESS from our internal DNS server.  I would like to trace back to the system that made the original request.  How can this be done?
0
Comment
Question by:McFarlandClinic
8 Comments
 
LVL 10

Expert Comment

by:moon_blue69
ID: 34218044
What is your operating System.

I would suggest using network monitor if its a windows system. It can be added via add or remove windows componets.

Or wireshark
0
 

Author Comment

by:McFarlandClinic
ID: 34218062
I have run wireshark, but I am a novice at using it.  I can see where my internal DNS tried to resolve the name, but I can't tell what internal system my DNS is doing the lookup for.
0
 
LVL 10

Expert Comment

by:moon_blue69
ID: 34218076
What platform you are on?? Windows Server 2003??
0
 
LVL 10

Expert Comment

by:moon_blue69
ID: 34218101
Have you got enough client access licesnses ? (CAL)?
0
6 Surprising Benefits of Threat Intelligence

All sorts of threat intelligence is available on the web. Intelligence you can learn from, and use to anticipate and prepare for future attacks.

 
LVL 10

Expert Comment

by:moon_blue69
ID: 34218206
"Have you got enough client access licesnses ? (CAL)?"

sorry that was a wrong message posted
0
 

Author Comment

by:McFarlandClinic
ID: 34218219
Windows server 2003
0
 
LVL 70

Expert Comment

by:Chris Dent
ID: 34221575

> I have run wireshark, but I am a novice at using it.  I can see where my internal DNS tried to resolve the name, but I can't tell
> what internal system my DNS is doing the lookup for.

You'd need to capture the request from the client, not the request from the server to the rest of the world. The logging options in the DNS console should permit this although it won't be easy.

DNS packets do not contain a history of who asked what, therefore your only chance is to grab the request and its source IP.

Chris
0
 
LVL 25

Accepted Solution

by:
DrDave242 earned 500 total points
ID: 34235317
You can also turn on debug logging on the DNS server:

Open the DNS console, right-click on your DNS server, and select Properties.  Click the Debug Logging tab and select the checkbox for Log packets for debugging.  Then you have a whole pile of options for which types of packets you want to log.  You can select and deselect those as appropriate.  (I'd leave both Outgoing and Incoming selected, as well as Request and Response.)

The log file is saved as system32\dns\dns.log by default, although you can change that in the Properties window also.  Open the log in Notepad or your favorite text editor, do a little searching, and you should have the source of the query in no time.

Don't forget to turn off debug logging when you're done.
0

Featured Post

Free Trending Threat Insights Every Day

Enhance your security with threat intelligence from the web. Get trending threat insights on hackers, exploits, and suspicious IP addresses delivered to your inbox with our free Cyber Daily.

Join & Write a Comment

Most DNS problems are VERY easily troubleshot and identifiable if you can follow the steps a DNS query takes. I would like to share the step-by-step a DNS query takes from the origin to the destination. _____________________________________________…
I've written instructions for one router type, but this principle may be useful for others of the same brand and even other brands of router. Problem: I had an issue especially with mobile devices that refused to use DNS information supplied via…
Get a first impression of how PRTG looks and learn how it works.   This video is a short introduction to PRTG, as an initial overview or as a quick start for new PRTG users.
In this tutorial you'll learn about bandwidth monitoring with flows and packet sniffing with our network monitoring solution PRTG Network Monitor (https://www.paessler.com/prtg). If you're interested in additional methods for monitoring bandwidt…

760 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

17 Experts available now in Live!

Get 1:1 Help Now