Strange DNS names showing up in Win domain

LeiZaK

Diamond Member
May 25, 2005
3,749
4
0
At work, we are running a Win2K/2K3 based network with active directory and all that good stuff. I recently installed Microsoft's Software Update Services (SUS) on one of the servers.

I've been noticed a couple of strange names coming up in the logs. Names that I can't seem to ping or perform a nslookup, but they appear in SUS to be a part of the domain. They don't show up in Active Directory, DNS, or DHCP services. The director of my department also noticed that one of them was surfing the net today through some internet usage monitoring software he uses.

I was under the impression that group policy had to be configured for the AutoUpdates client to recognize the SUS server. Since these hosts aren't in Active directory, they also are not part of the OU that has the GP applied.

The names are "h5t5r7" and "p9k9d9" if that means anything

Any ideas???
 

skyking

Lifer
Nov 21, 2001
22,707
5,832
146
Do you have wireless? do you have physical accounting of available network jacks?
I'd start with the basics. If you have wireless, then the sky's the limit for access. If not, try and match MACs of known clients to names, then use the switches to track down the unknowns and the ports those are attached to. Find the ports, find the jacks, and probably find somebody's laptop from home.
 

LeiZaK

Diamond Member
May 25, 2005
3,749
4
0
I found out the problem... The DNS servers were not set to 'scavenge stale records' and names from years ago were still being maintained in the reverse lookup zones. Some IP's had 6 or 7 names associated with them.

If anyone wants to know, this option is in the properties for the lookup zone in DNS on Win2K/2k3 servers. Click the 'Aging' button and it gives this option.

Thanks