Strange CUPS attempts #1189
Replies: 5 comments
-
|
Some more: |
Beta Was this translation helpful? Give feedback.
-
Beta Was this translation helpful? Give feedback.
-
|
hi @SeaDude , That seems a collision of IPs and domains. Those domains seem to be cached with the IP 127.0.0.53. Could you add a rule to allow connections from dnsmasq, systemd-resolved, etc to 127.0.0.53 and port 53? And restart the daemon. |
Beta Was this translation helpful? Give feedback.
-
|
The two arpa domains are totally normal to see. Domains ending in .arpa are mostly used to map ip addresses to domain names (instead of domain names to ip addresses like usual). Source: https://www.iana.org/domains/arpa The youtubei.googleapis.net one is quite strange though. That I do not have an explanation for and likely warrants some deeper investigation. |
Beta Was this translation helpful? Give feedback.
-
|
I think it's related :) https://www.evilsocket.net/2024/09/26/Attacking-UNIX-systems-via-CUPS-Part-I/ |
Beta Was this translation helpful? Give feedback.


Uh oh!
There was an error while loading. Please reload this page.
-
I get these CUPS attempts at least 1x / session.
I thought CUPS was a printer protocol...?
Most are not from recognizable URLS, they are usually go to
arpasomething or other...Beta Was this translation helpful? Give feedback.
All reactions