<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic baidu.com requests in OpenDNS</title>
    <link>https://community.cisco.com/t5/opendns/baidu-com-requests/m-p/5179655#M6367</link>
    <description>&lt;DIV class="opendns-migrated-content"&gt;&lt;P&gt;Hello all,&lt;/P&gt;
&lt;P&gt;I'm new to the OpenDNS community, and love&amp;nbsp;having the ability to be&amp;nbsp;able to control internet access from my network&amp;nbsp;and make it safer for my family.&lt;/P&gt;
&lt;P&gt;I've noticed that in my stats, one of the leading domain requests are to (&lt;A href="http://www.baidu.com).%C2%A0" rel="nofollow noreferrer"&gt;www.baidu.com).&amp;nbsp;&lt;/A&gt; I'm&amp;nbsp;seeing a couple thousand requests a day.&amp;nbsp; I have&amp;nbsp;blacklisted them, but what I would really like to know is where it is coming from on my end.&amp;nbsp; The requests are still coming, but I'm assuming they aren't getting anywhere.&lt;/P&gt;
&lt;P&gt;Can anyone point me in the right direction on finding this information, or perhaps let me know what is happening in regards to this domain?&amp;nbsp; None of my family use baidu.com, as I believe it's a Chinese made search engine.&lt;/P&gt;
&lt;P&gt;Thanks!&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;/DIV&gt;</description>
    <pubDate>Mon, 14 Aug 2017 18:26:43 GMT</pubDate>
    <dc:creator>rhome1</dc:creator>
    <dc:date>2017-08-14T18:26:43Z</dc:date>
    <item>
      <title>baidu.com requests</title>
      <link>https://community.cisco.com/t5/opendns/baidu-com-requests/m-p/5179655#M6367</link>
      <description>&lt;DIV class="opendns-migrated-content"&gt;&lt;P&gt;Hello all,&lt;/P&gt;
&lt;P&gt;I'm new to the OpenDNS community, and love&amp;nbsp;having the ability to be&amp;nbsp;able to control internet access from my network&amp;nbsp;and make it safer for my family.&lt;/P&gt;
&lt;P&gt;I've noticed that in my stats, one of the leading domain requests are to (&lt;A href="http://www.baidu.com).%C2%A0" rel="nofollow noreferrer"&gt;www.baidu.com).&amp;nbsp;&lt;/A&gt; I'm&amp;nbsp;seeing a couple thousand requests a day.&amp;nbsp; I have&amp;nbsp;blacklisted them, but what I would really like to know is where it is coming from on my end.&amp;nbsp; The requests are still coming, but I'm assuming they aren't getting anywhere.&lt;/P&gt;
&lt;P&gt;Can anyone point me in the right direction on finding this information, or perhaps let me know what is happening in regards to this domain?&amp;nbsp; None of my family use baidu.com, as I believe it's a Chinese made search engine.&lt;/P&gt;
&lt;P&gt;Thanks!&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;/DIV&gt;</description>
      <pubDate>Mon, 14 Aug 2017 18:26:43 GMT</pubDate>
      <guid>https://community.cisco.com/t5/opendns/baidu-com-requests/m-p/5179655#M6367</guid>
      <dc:creator>rhome1</dc:creator>
      <dc:date>2017-08-14T18:26:43Z</dc:date>
    </item>
    <item>
      <title>Re: baidu.com requests</title>
      <link>https://community.cisco.com/t5/opendns/baidu-com-requests/m-p/5179656#M6368</link>
      <description>&lt;DIV class="opendns-migrated-content"&gt;&lt;P&gt;Baidu, Inc., incorporated on January 18, 2000, is a Chinese-American web services company headquartered at the Baidu Campus in Beijing's Haidian District. It is one of the largest Internet companies in the world.&amp;nbsp;&lt;BR /&gt;&lt;A href="https://en.wikipedia.org/wiki/Baidu" rel="nofollow noreferrer"&gt;https://en.wikipedia.org/wiki/Baidu&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;These DNS requests come out of your network. &amp;nbsp;There is no way to see your internal infrastructure from an external service like OpenDNS. &amp;nbsp;You would want to find the device and program out yourself which raises these requests, by installing sniffer software like&amp;nbsp;&lt;A href="http://www.nirsoft.net/utils/dns_query_sniffer.html" rel="nofollow noreferrer"&gt;http://www.nirsoft.net/utils/dns_query_sniffer.html&lt;/A&gt; or&amp;nbsp;&lt;A href="https://www.wireshark.org/" rel="nofollow noreferrer"&gt;https://www.wireshark.org/&lt;/A&gt;. &amp;nbsp;I could think of a Baidu web browser add-on or other helper app which would cause these DNS lookups.&amp;nbsp;&lt;BR /&gt;&lt;A href="https://www.startpage.com/do/search?query=baidu+browser+add-on&amp;amp;cat=web" rel="nofollow noreferrer"&gt;https://www.startpage.com/do/search?query=baidu+browser+add-on&amp;amp;cat=web&lt;/A&gt;&lt;/P&gt;&lt;/DIV&gt;</description>
      <pubDate>Mon, 14 Aug 2017 20:57:28 GMT</pubDate>
      <guid>https://community.cisco.com/t5/opendns/baidu-com-requests/m-p/5179656#M6368</guid>
      <dc:creator>rotblitz</dc:creator>
      <dc:date>2017-08-14T20:57:28Z</dc:date>
    </item>
    <item>
      <title>Re: baidu.com requests</title>
      <link>https://community.cisco.com/t5/opendns/baidu-com-requests/m-p/5179657#M6369</link>
      <description>&lt;DIV class="opendns-migrated-content"&gt;&lt;P&gt;I am noticing the same thing with baidu.com lookups. For example on a single day I have the top 5 OpenDNS lookup stats:&lt;/P&gt;
&lt;TABLE class="stats table-hl" border="0" cellspacing="0" cellpadding="0"&gt;
&lt;TBODY&gt;
&lt;TR class="domain-row even"&gt;
&lt;TD class="rank"&gt;1&lt;/TD&gt;
&lt;TD class="domain" title=""&gt;&lt;SPAN id=""&gt;&lt;A class="top-domain" href="https://dashboard.opendns.com/stats/all/topdomains/2020-01-24/" rel="nofollow noreferrer"&gt;www.baidu.com&lt;/A&gt;&lt;/SPAN&gt;&lt;/TD&gt;
&lt;TD class="count"&gt;14,118&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR class="domain-row odd"&gt;
&lt;TD class="rank"&gt;2&lt;/TD&gt;
&lt;TD class="domain" title=""&gt;&lt;SPAN id=""&gt;&lt;A class="top-domain" href="https://dashboard.opendns.com/stats/all/topdomains/2020-01-24/" rel="nofollow noreferrer"&gt;www.apple.com&lt;/A&gt;&lt;/SPAN&gt;&lt;/TD&gt;
&lt;TD class="count"&gt;374&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR class="domain-row even"&gt;
&lt;TD class="rank"&gt;3&lt;/TD&gt;
&lt;TD class="domain" title=""&gt;&lt;SPAN id=""&gt;&lt;A class="top-domain" href="https://dashboard.opendns.com/stats/all/topdomains/2020-01-24/" rel="nofollow noreferrer"&gt;apple.com&lt;/A&gt;&lt;/SPAN&gt;&lt;/TD&gt;
&lt;TD class="count"&gt;361&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR class="domain-row odd"&gt;
&lt;TD class="rank"&gt;4&lt;/TD&gt;
&lt;TD class="domain" title=""&gt;&lt;SPAN id=""&gt;&lt;A class="top-domain" href="https://dashboard.opendns.com/stats/all/topdomains/2020-01-24/" rel="nofollow noreferrer"&gt;guzzoni.apple.com&lt;/A&gt;&lt;/SPAN&gt;&lt;/TD&gt;
&lt;TD class="count"&gt;346&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR class="domain-row even"&gt;
&lt;TD class="rank"&gt;5&lt;/TD&gt;
&lt;TD class="domain" title=""&gt;&lt;SPAN id=""&gt;&lt;A class="top-domain" href="https://dashboard.opendns.com/stats/all/topdomains/2020-01-24/" rel="nofollow noreferrer"&gt;device-metrics-us.amazon.com&lt;/A&gt;&lt;/SPAN&gt;&lt;/TD&gt;
&lt;TD class="count"&gt;308&lt;/TD&gt;
&lt;/TR&gt;
&lt;/TBODY&gt;
&lt;/TABLE&gt;
&lt;P&gt;We have a 2 macs, 2 iphones, a OnePlus3, Huawei P20Pro, and 2 Window machines in addition to a Playstation, Samsung and routing devices. Identifying which machine is making the abuse requires me to install something between our Wifi router and Internet provider device. I understand there is not much else to do since domain lookups do not include much metadata.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I did try to block the baidu.com domain in my OpenDNS panel but that failed with a "Error blocking &lt;A href="http://www.baidu.com" rel="nofollow noreferrer"&gt;www.baidu.com&lt;/A&gt;. undefined" message. I thought that if I blocked it, maybe I could identify what machine started complaining. Anyone have an idea why can I not block baidu.com?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;/DIV&gt;</description>
      <pubDate>Sun, 26 Jan 2020 21:15:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/opendns/baidu-com-requests/m-p/5179657#M6369</guid>
      <dc:creator>patrick10</dc:creator>
      <dc:date>2020-01-26T21:15:27Z</dc:date>
    </item>
    <item>
      <title>Re: baidu.com requests</title>
      <link>https://community.cisco.com/t5/opendns/baidu-com-requests/m-p/5179658#M6370</link>
      <description>&lt;DIV class="opendns-migrated-content"&gt;&lt;P&gt;You must block it from the content filtering page, not from the stats page.&lt;/P&gt;&lt;/DIV&gt;</description>
      <pubDate>Sun, 26 Jan 2020 21:55:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/opendns/baidu-com-requests/m-p/5179658#M6370</guid>
      <dc:creator>rotblitz</dc:creator>
      <dc:date>2020-01-26T21:55:27Z</dc:date>
    </item>
    <item>
      <title>Re: baidu.com requests</title>
      <link>https://community.cisco.com/t5/opendns/baidu-com-requests/m-p/5179659#M6371</link>
      <description>&lt;DIV class="opendns-migrated-content"&gt;&lt;P&gt;See &lt;A href="https://support.opendns.com/hc/en-us/community/posts/220050607" rel="nofollow noreferrer"&gt;https://support.opendns.com/hc/en-us/community/posts/220050607&lt;/A&gt;&lt;/P&gt;&lt;/DIV&gt;</description>
      <pubDate>Sun, 26 Jan 2020 21:58:31 GMT</pubDate>
      <guid>https://community.cisco.com/t5/opendns/baidu-com-requests/m-p/5179659#M6371</guid>
      <dc:creator>rotblitz</dc:creator>
      <dc:date>2020-01-26T21:58:31Z</dc:date>
    </item>
  </channel>
</rss>

