# Malicious DNS attacks

**URL:** <https://boards.straightdope.com/t/malicious-dns-attacks/658589>\
**Category:** Factual Questions\
**Created:** [May 17, 2013, 7:51am UTC](https://boards.straightdope.com/t/malicious-dns-attacks/658589 "2013-05-17T07:51:24Z")\
**Posts on this page:** 9\
**Page:** 1

<div class="post-metadata">

**Author:** ![Johanna](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/johanna/32/8318_2.png) [@Johanna](https://boards.straightdope.com/u/Johanna)\
**Post date:** [May 17, 2013, 7:51am UTC](https://boards.straightdope.com/t/malicious-dns-attacks/658589/1 "2013-05-17T07:51:24Z")

</div>

Over the past half hour, Norton has notified me that it has blocked several intrusion attempts from a “malicious DNS domain.” It identified the name of the attacking server as a fairly obscure Hindi word which I have used in various places online, but have not used recently. The likelihood of _that_ being a coincidence is essentially nil. Also, the IP address the attack originated from was identical to my own IP address, the destination of the attack, except for the last digit 2, where the last digit of my IP address is 1.

WTF is going on here? Has an attacker taken data from my computer to mimic it, to disguise itself?

---

<div class="post-metadata">

**Author:** ![Dog80](https://avatars.discourse-cdn.com/v4/letter/d/6bbea6/32.png) [@Dog80](https://boards.straightdope.com/u/Dog80)\
**Post date:** [May 17, 2013, 8:14am UTC](https://boards.straightdope.com/t/malicious-dns-attacks/658589/2 "2013-05-17T08:14:14Z")

</div>

It is another computer or device in your network that tries to establish a connection with your computer. The Hindi word is probably the computer name (NETBIOS name) of the other computer.

---

<div class="post-metadata">

**Author:** ![yoyodyne](https://avatars.discourse-cdn.com/v4/letter/y/a9a28c/32.png) [@yoyodyne](https://boards.straightdope.com/u/yoyodyne)\
**Post date:** [May 17, 2013, 2:18pm UTC](https://boards.straightdope.com/t/malicious-dns-attacks/658589/3 "2013-05-17T14:18:25Z")

</div>

It’s a false alarm.

---

<div class="post-metadata">

**Author:** ![Johanna](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/johanna/32/8318_2.png) [@Johanna](https://boards.straightdope.com/u/Johanna)\
**Post date:** [May 17, 2013, 4:46pm UTC](https://boards.straightdope.com/t/malicious-dns-attacks/658589/4 "2013-05-17T16:46:45Z")

</div>

Why is it a false alarm?  
Why would another computer be named after an obscure word that only I have ever used?  
Why would the IP address differ from mine by only 1?

---

<div class="post-metadata">

**Author:** ![yoyodyne](https://avatars.discourse-cdn.com/v4/letter/y/a9a28c/32.png) [@yoyodyne](https://boards.straightdope.com/u/yoyodyne)\
**Post date:** [May 17, 2013, 5:55pm UTC](https://boards.straightdope.com/t/malicious-dns-attacks/658589/5 "2013-05-17T17:55:02Z")

</div>

Because…IT’S IN YOUR HOUSE!

IP addresses are local to your LAN and are handed out by your router in sequence. It’s typical that the .1 address is used by the router, how do you know that’s your computer?

What other devices do you have on the network? Phone, tablet, laptop? Go to Control Panel, System. What is the name of your desktop?

---

<div class="post-metadata">

**Author:** ![Johanna](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/johanna/32/8318_2.png) [@Johanna](https://boards.straightdope.com/u/Johanna)\
**Post date:** [May 17, 2013, 9:45pm UTC](https://boards.straightdope.com/t/malicious-dns-attacks/658589/6 "2013-05-17T21:45:55Z")

</div>

That’s why I was speculating that the attacker was masking itself with data stolen from me. Otherwise, how could I be attacking myself? There are 2 computers here sharing a wireless connection.

---

<div class="post-metadata">

**Author:** ![yoyodyne](https://avatars.discourse-cdn.com/v4/letter/y/a9a28c/32.png) [@yoyodyne](https://boards.straightdope.com/u/yoyodyne)\
**Post date:** [May 18, 2013, 12:55am UTC](https://boards.straightdope.com/t/malicious-dns-attacks/658589/7 "2013-05-18T00:55:37Z")

</div>

There is no attack, it’s due to normal traffic that the POS Norton is falsely alarming on. There should be a way to tell Norton to ignore it.

---

<div class="post-metadata">

**Author:** ![Johanna](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/johanna/32/8318_2.png) [@Johanna](https://boards.straightdope.com/u/Johanna)\
**Post date:** [May 18, 2013, 8:10am UTC](https://boards.straightdope.com/t/malicious-dns-attacks/658589/8 "2013-05-18T08:10:49Z")

</div>

OK, that’s a relief. Thinking back, I remembered that the Hindi word is the name I assigned this computer when I first got it several years ago. I didn’t know that Norton could be fooled that way, like getting scared of your own reflection. Thanks!

---

<div class="post-metadata">

**Author:** ![Duke\_of\_York](https://avatars.discourse-cdn.com/v4/letter/d/f6c823/32.png) [@Duke\_of\_York](https://boards.straightdope.com/u/Duke_of_York)\
**Post date:** [May 18, 2013, 12:42pm UTC](https://boards.straightdope.com/t/malicious-dns-attacks/658589/9 "2013-05-18T12:42:15Z")

</div>

In my opinion I wouldn’t waste your money on Norton, They have to justify their cost by giving you plenty of alarms to worry about. I use the free version of Avast (anti virus) plus the free version of Zone alarm (firewall) and it works real fine.
