[SOLVED] how to stop sending dns requests to "bing.com"?

[SOLVED] how to stop sending dns requests to "bing.com"?

Postby magfan » Jul 20th, '17, 15:25

This morning our network administrator told me that my linux system (mga5) sends dns requests to "bing.com" every few seconds. How can I find out which process is sending those requests? I want to stop this process.
Last edited by magfan on Jul 24th, '17, 09:50, edited 1 time in total.
magfan
 
Posts: 334
Joined: Apr 3rd, '12, 12:33

Re: how to stop sending dns requests to "bing.com"?

Postby doktor5000 » Jul 20th, '17, 17:26

By using tcpdump or similar and filtering for the DNS name, IP adresses or for port 53 ?
Also see the hints in viewtopic.php?f=25&t=11720 on how to trace that back to actual processes.
Cauldron is not for the faint of heart!
Caution: Hot, bubbling magic inside. May explode or cook your kittens!
----
Disclaimer: Beware of allergic reactions in answer to unconstructive complaint-type posts
User avatar
doktor5000
 
Posts: 18049
Joined: Jun 4th, '11, 10:10
Location: Leipzig, Germany

Re: how to stop sending dns requests to "bing.com"?

Postby magfan » Jul 24th, '17, 09:50

doktor5000 wrote:By using tcpdump or similar and filtering for the DNS name, IP adresses or for port 53 ?


Thank you! After a long time searching it turned out to be very simple: one user occasionally started a virtual machine which is using the hosts IP address to connect to the internet (NAT). And whenever the internet explorer was running in that vm there were regular attempts to contact "bing.com". After disabling that option within internet explorer the dns queries disappeared.
magfan
 
Posts: 334
Joined: Apr 3rd, '12, 12:33


Return to Networking

Who is online

Users browsing this forum: No registered users and 1 guest

cron