Still celebrating National IT Professionals Day with 3 months of free Premium Membership. Use Code ITDAY17

x
?
Solved

Which DNS authority to report to

Posted on 2011-02-20
4
Medium Priority
?
273 Views
Last Modified: 2012-05-11
Hi there,
Running server 2008 domain.  Running TS Webaccess so that my users can work on a couple of databases. A couple of users try to abuse the system.  I know the IP addresses.  What should be done at this point.  What is the best option for me.  Which DNS authority to report to?
Imagining that thir ISP is doing nothing.  Any help in this regard would be appreciated.
Thanks
0
Comment
Question by:amanzoor
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 2
4 Comments
 
LVL 57

Accepted Solution

by:
giltjr earned 1000 total points
ID: 34939773
You don't report to DNS authority.  You go to the ISP that has delagated the IP address.  You can go to ARIN at:

     https://www.arin.net/abuse.html

Search on hackers and see their recommendations.
0
 
LVL 33

Assisted Solution

by:Dave Howe
Dave Howe earned 1000 total points
ID: 34949344
normally you would do a whois on the user ip and report to their isp - but you would *also* (unless you believe one of your users share an isp) block the entire IP block for that ISP at the firewall.

I would be surprised if the report does anything though - I have blocked the whole of china (upwards of 200 attacks seen per day, with no response from isps) and have at least 20 other blocks of IPs on the list.
0
 
LVL 33

Expert Comment

by:Dave Howe
ID: 34949367
other common approaches -

move TS to a port above 5000 - most attackers try only "common" ports, and this will reduce your attack profile almost instantly.

make sure you are using ssl certificates for your RDP - again, makes it harder for the attacker, and many will either move on, or not recognise the TS is there.
0
 
LVL 4

Author Comment

by:amanzoor
ID: 34960566
Thanks Guys:
I really appreciate your time, I like the idea of blocking onto the firewall and using ssl.
THanks once again.
0

Featured Post

Get free NFR key for Veeam Availability Suite 9.5

Veeam is happy to provide a free NFR license (1 year, 2 sockets) to all certified IT Pros. The license allows for the non-production use of Veeam Availability Suite v9.5 in your home lab, without any feature limitations. It works for both VMware and Hyper-V environments

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

The Cyber News Rundown brings you the latest happenings in cyber news weekly. Who am I? I’m Connor Madsen, a Webroot Threat Research Analyst, and a guy with a passion for all things security. Any more questions? Just ask.
If you're a modern-day technology professional, you may be wondering if certifications are really necessary. They are. Here's why.
In this video we outline the Physical Segments view of NetCrunch network monitor. By following this brief how-to video, you will be able to learn how NetCrunch visualizes your network, how granular is the information collected, as well as where to f…
NetCrunch network monitor is a highly extensive platform for network monitoring and alert generation. In this video you'll see a live demo of NetCrunch with most notable features explained in a walk-through manner. You'll also get to know the philos…

721 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question