1

I've recently experienced an XML-RPC attack vs wordpress from a pair of machines for which dig -x returns a very very odd looking result:

;; ANSWER SECTION:
54.249.96.191.in-addr.arpa. 60  IN  PTR DEDICATED.SERVER.

I've never seen a TLD named DEDICATED before. I get the same result from my home machine and within amazon...

Gus
  • 127
  • 2
  • 11

2 Answers2

9

There is no actual requirement that PTR records return valid host names.

Unfortunately.


The typical approach to find the owner or ISP that manages an IP-address (range) is a WHOIS lookup.

In this case the 191.96.249/24 range is managed by company called Dmzhost Limited with abuse AT DMZHOST.CO as their email contact.

HBruijn
  • 77,029
  • 24
  • 135
  • 201
0

The guy who runs those servers (chris@dmzhost.co) is as dodgy as they come, and he allows his servers to be used for DDoS:

https://medium.com/@alek.boyd/plunging-into-a-ddos-hole-a-how-to-guide-b7565f814513#.s97ens0gl

  • 1
    I realise your username is a fairly big clue, but you might want to make the fact you are the author of that post clearer (see e.g. https://serverfault.com/help/promotion) - and extend your answer a little to reflect the contents of both your medium post, and the post you made on your own blog. – iwaseatenbyagrue Mar 19 '17 at 10:01