UDP flood out to nameservers registrar
Hi,
I created a new user account on my cpanel and set up some addon domains. these addon domains all are set up to redirect to another url in cpanel redirect manager.
This works as supposed.
On this new user account I have NO scripts or software installed. Only the htaccess redirects created by cpanel.
My CSF firewall start sending me this logs :
kernel: Firewall:*UDPFLOOD* IN= OUT=eth0 SRC=server-main-IP DST=several-IPs LEN=75 TOS=0x00 PREC=0x00 TTL=64 ID=29755 DF PROTO=UDP SPT=59705 DPT=53 LEN=55 UID=1010 GID=1012
When I study all the DST IP's, they all seems to belong to the nameservers of the registrar where I have the domains set up.
btw> main server IP in the entry above is not the dedicated IP the cpanel account is on, its the general main server IP
Can anybody tell me what is happening here ?
Thanks in advance.
Please sign in to leave a comment.
Comments
0 comments