SIM restarts HTTP becuase of someone tries to update zone files
I keep getting errors from the System integrity monitor as listed below: I have done a google search and search here and the general concensus seems to be that it is a Windows 2K macine. But this happens everynight just after 00:00 and it has originated from 10 or so different IP addresses. It also repeats itself many times. I add the IP's to the APF everyday but it reappears with different IP's the next day. The IP's are mostly asian and Puerto Rico. In the research they state Win 2K only tried this one time and then gives up, but these are presistent enough to cause SIM to restart the HTTP....
WHOIS results for 203.86.45.18
Generated by www.DNSstuff.com
Location: China [City: Beijing, Guangdong]
Any ideals?
I keep getting errors from the System integrity monitor as listed below: I have done a google search and search here and the general concensus seems to be that it is a Windows 2K macine. But this happens everynight just after 00:00 and it has originated from 10 or so different IP addresses. It also repeats itself many times. I add the IP's to the APF everyday but it reappears with different IP's the next day. The IP's are mostly asian and Puerto Rico. In the research they state Win 2K only tried this one time and then gives up, but these are presistent enough to cause SIM to restart the HTTP....
Code:
System integrity monitor on xxx.xxxx.xxx has taken action in responce to an event.
Recent event logs are enclosed below for your inspection. There has been 8 events today,
if an average of 8 events is reached, e-mail alerts will be terminated for the duration of
the day.
- Events Summary:
Total event count: 8
Average event count: 1
- Service Summary:
HTTP [restarted - 8 events]
DNS [online - 0 events]
MYSQL [online - 0 events]
SMTP [online - 0 events]
- System Summary:
LOAD [0.04 - status good - 0 events]
NETWORK [eth0 - online - 0 events]
- SIM Log:
[10/11/05 00:30:01]: NETWORK is online.
[10/11/05 00:30:01]: HTTP service is online.
[10/11/05 00:30:01]: HTTP url request failed, assuming offline.
[10/11/05 00:30:01]: Restarted HTTP service (7 HTTP events today).
[10/11/05 00:30:01]: DNS service is online.
[10/11/05 00:30:01]: MYSQL service is online.
[10/11/05 00:30:01]: SMTP service is online.
[10/11/05 00:35:00]: LOAD 0.04 (status good)
[10/11/05 00:35:00]: NETWORK is online.
[10/11/05 00:35:00]: HTTP service is online.
[10/11/05 00:35:00]: HTTP url request failed, assuming offline.
[10/11/05 00:35:00]: Restarted HTTP service (8 HTTP events today).
[10/11/05 00:35:00]: DNS service is online.
[10/11/05 00:35:00]: MYSQL service is online.
[10/11/05 00:35:00]: SMTP service is online.
- System Log:
Oct 11 00:26:07 host named[2681]: client 203.86.45.18#2618: update 'xxxxx.xxx/IN'
denied Oct 11 00:26:08 host named[2681]: client
203.86.45.18#2526: updating zone 'xxxxx.xxx/IN': update failed: 'RRset exists (value
dependent)' prerequisite not satisfied (NXRRSET) Oct 11 00:26:10 host named[2681]: client
203.86.45.18#2529: update 'xxxxx.xxx/IN' denied Oct 11 00:27:11 host named[2681]:
client
203.86.45.18#1866: updating zone 'xxxxx.xxx/IN': update failed: 'RRset exists (value
dependent)' prerequisite not satisfied (NXRRSET) Oct 11
00:27:12 host named[2681]: client 203.86.45.18#1869: update 'xxxxx.xxx/IN' denied Oct
11 00:27:43 host named[2681]: client
203.86.45.18#3872: update 'xxxxx.xxx/IN' denied Oct 11 00:28:29 host
named[2681]: client 203.86.45.18#3884: update 'xxxxx.xxx/IN' denied Oct
11 00:29:38 host named[2681]: client 203.86.45.18#1433: updating zone
'xxxxx.xxx/IN': update failed: 'RRset exists (value dependent)'
prerequisite not satisfied (NXRRSET) Oct 11 00:29:38 host named[2681]:
client 203.86.45.18#1433: error sending response: host unreachable Oct 11
00:31:12 host pure-ftpd: ([email protected]) [INFO] New connection from 127.0.0.1 Oct 11 00:31:12 host pure-ftpd: ([email protected]) [INFO] Logout.
Oct 11 00:31:28 host named[2681]: client 203.86.45.18#3892: update 'xxxxx.xxx/IN'
denied Oct 11 00:32:09 host named[2681]: client
203.86.45.18#3898: update 'xxxxx.xxx/IN' denied Oct 11 00:33:43 host
named[2681]: client 203.86.45.18#1986: updating zone 'xxxxx.xxx/IN':
update failed: 'RRset exists (value dependent)' prerequisite not satisfied
(NXRRSET) Oct 11 00:33:45 host named[2681]: client 203.86.45.18#1989:
update 'xxxxx.xxx/IN' denied
======================================================
SIM 2.5-3 <[email protected]> 10/11/05
00:35:00
Generated by www.DNSstuff.com
Location: China [City: Beijing, Guangdong]
Any ideals?
Last edited: