Shredding records to resist DOS attack

Have a mac mini server with 10.8 and server 2.2.1 on the internal network that has the log files filling up with some crazy entries:


May 10 17:11:51 myservername.mydomain.com mDNSResponder[43]: CacheRecordAdd: db._dns-sd._udp.0.##.##.##.in-addr.arpa. (PTR) has 4167 answers; shedding records to resist DOS attack


thousdands of these lines. Since its on an internal network, pretty sure we are not getting a DOS attack... or are we?

Mac mini

Posted on May 10, 2013 3:18 PM

Reply
5 replies

May 13, 2013 3:49 AM in response to 41Mac

There is no DOS attack. The text of the message is poorly chosen. Your internal network is configured in an unusual way and is allowing messages to bounce around internally forever. A DNS query is getting thousands of replies which is probably just one or two replies bounced around repeatedly from switch to switch. That message from the Mac is just a warning that the Mac isn't bothering to look at all the replies to see if they agree with one-another, it is ignoring most of them.


If you have a curious network technician you might tell them about this message but it's not causing your computer any significant harm, it's just a sign that useless messages are clogging your internal network, possibly slowing it down for genuine traffic.

Jan 4, 2015 10:15 PM in response to 41Mac

Found this via Google. I'll add to the chorus that my Mac Mini Server (10.8.5) was doing the same thing tonight. It said there were millions of answers, which was impossible. I have a pretty simple network with a Router/AP and an 8-port unmanaged switch connected to that. My system.log file had grown to 4GB in just two hours, and the CPU usage of mDNSResponder was pretty high.


I solved it by restarting the server.

Jan 12, 2015 7:02 AM in response to 41Mac

For anyone else finding this, I stopped the messages by issuing Terminal command...


sudo killall mDNSResponder


It respawns after killing. First tried a -HUP but that had no effect. No idea if the forced kill had any effect on other services (none reported) but I couldn't do a restart but needed to track other log messages (which was impossible with all the mDNS ones).

This thread has been closed by the system or the community team. You may vote for any posts you find helpful, or search the Community for additional answers.

Shredding records to resist DOS attack

Welcome to Apple Support Community
A forum where Apple customers help each other with their products. Get started with your Apple Account.