最近正好手头有一块树莓派闲着,寻思拿来当个内网的 DHCP 服务和 DNS 缓存提升一下上网体验,部署完成后,出于对配置项不熟,懵逼状态下加了个 domain=xxxxx.com 的搜索域( xxxxx.com 只是手动马赛克掉自己的域名,这域名要真是我的...不敢想、不敢想),使用一切也正常,但是今天一翻日志,发现很多莫名其妙的域名查询不知道是哪来的,来请教一下各位。客户端是 win10,试了一下 ping pvdpyzybnhez 能造出类似的记录,可是翻遍了内网也没这么个主机名。
Sep 7 23:42:49 dnsmasq[7971]: query[A] pvdpyzybnhez.xxxxx.com from 192.168.3.110
Sep 7 23:42:49 dnsmasq[7971]: forwarded pvdpyzybnhez.xxxxx.com to 114.114.114.114
Sep 7 23:42:49 dnsmasq[7971]: query[A] bzqesfdambsxnsd.xxxxx.com from 192.168.3.110
Sep 7 23:42:49 dnsmasq[7971]: forwarded bzqesfdambsxnsd.xxxxx.com to 114.114.114.114
Sep 7 23:42:49 dnsmasq[7971]: query[A] xjlpzfiafmtrqtd.xxxxx.com from 192.168.3.110
Sep 7 23:42:49 dnsmasq[7971]: forwarded xjlpzfiafmtrqtd.xxxxx.com to 114.114.114.114
Sep 7 23:42:49 dnsmasq[7971]: reply pvdpyzybnhez.xxxxx.com is NXDOMAIN
Sep 7 23:42:49 dnsmasq[7971]: reply xjlpzfiafmtrqtd.xxxxx.com is NXDOMAIN
Sep 7 23:42:49 dnsmasq[7971]: query[A] xjlpzfiafmtrqtd.xxxxx.com from 192.168.3.110
Sep 7 23:42:49 dnsmasq[7971]: cached xjlpzfiafmtrqtd.xxxxx.com is NXDOMAIN
Sep 7 23:42:49 dnsmasq[7971]: query[A] pvdpyzybnhez.xxxxx.com from 192.168.3.110
Sep 7 23:42:49 dnsmasq[7971]: cached pvdpyzybnhez.xxxxx.com is NXDOMAIN
Sep 7 23:42:49 dnsmasq[7971]: reply bzqesfdambsxnsd.xxxxx.com is NXDOMAIN
Sep 7 23:42:49 dnsmasq[7971]: query[A] bzqesfdambsxnsd.xxxxx.com from 192.168.3.110
Sep 7 23:42:49 dnsmasq[7971]: cached bzqesfdambsxnsd.xxxxx.com is NXDOMAIN
另外还有个比较奇葩的但好歹看起来正常的查询请求 wpad.xxxxx.com ,隔几个小时就请求一次。
Sep 7 23:46:50 dnsmasq[7971]: query[A] wpad.xxxxx.com from 192.168.3.96
Sep 7 23:46:50 dnsmasq[7971]: forwarded wpad.xxxxx.com to 114.114.114.114
这个翻了翻,可能是 win10 的自动代理发现 wpad,但看了设置里自动代理发现是关的,一样的懵。
1
crab 2018-09-09 00:21:58 +08:00
你是不是使用 chrome 浏览器?它有随机域名请求
|
2
ztlong OP @crab 是用的 chrome,非常感谢,顺便附一篇相关内容: http://www.ghacks.net/2012/02/18/chrome-connecting-to-random-domains-on-start-here-is-why/
|