09-20-2023 06:47 AM
Hello,
I noticed some weird lines left on the console of a Firepower appliance running ASA 9.16(2)14 today.
ERROR: Invalid hostname: '' *; host ck4glj8u9e5sr[REDACTED]oast.site; ''
INFO: A hostname must have letters or digits, and can have wild characters '*','?','[]'.
ERROR: Invalid hostname: '' *; host ck4glj8u9e5srgac[REDACTED]oast.site; ''
INFO: A hostname must have letters or digits, and can have wild characters '*','?','[]'.
ERROR: Invalid hostname: '' *; host ck4glj8u9e5srg[REDACTED]oast.site; ''
INFO: A hostname must have letters or digits, and can have wild characters '*','?','[]'.
ERROR: Invalid hostname: '' *; host ck4ivp8u9e5s8gg[REDACTED]oast.fun; ''
INFO: A hostname must have letters or digits, and can have wild characters '*','?','[]'.
ERROR: Invalid hostname: '' *; host ck4ivp8u9e5s8ggnhva0[REDACTED]oast.fun; ''
INFO: A hostname must have letters or digits, and can have wild characters '*','?','[]'.
ERROR: Invalid hostname: '' *; host ck4ivp8u9e5s8gg[REDACTED]oast.fun; ''
INFO: A hostname must have letters or digits, and can have wild characters '*','?','[]'.
ERROR: Invalid hostname: '' *; host ck4kim0u9e5s8e[REDACTED]oast.site; ''
INFO: A hostname must have letters or digits, and can have wild characters '*','?','[]'.
ERROR: Invalid hostname: '' *; host ck4kim0u9e5s8e[REDACTED]oast.site; ''
INFO: A hostname must have letters or digits, and can have wild characters '*','?','[]'.
ERROR: Invalid hostname: '' *; host ck4kim0u9e5s[REDACTED]oast.site; ''
INFO: A hostname must have letters or digits, and can have wild characters '*','?','[]'.
ERROR: Invalid hostname: '' *; host ck50g3ou9e5[REDACTED]oast.me; ''
INFO: A hostname must have letters or digits, and can have wild characters '*','?','[]'.
ERROR: Invalid hostname: '' *; host ck50g3ou9e5u[REDACTED]oast.me; ''
INFO: A hostname must have letters or digits, and can have wild characters '*','?','[]'.
ERROR: Invalid hostname: '' *; host ck50g3ou9e5u[REDACTED]oast.me; ''
INFO: A hostname mu
INFO: A hostname must have letters or digits, and can have wild characters '*','?','[]'.
ERROR: Invalid hostname: '' *; host ck58p9o[REDACTED]oast.live; ''
INFO: A hostname must have letters or digits, and can have wild characters '*','?','[]'.
We don't own the domain oast.site and the IP it resolves to is owned by DigitalOcean in the USA which which is constantly attacking our network. These hostnames aren't anywhere in the configs and I did a "show history" and no commands were entered into the console. Any idea what would generate this type of error in an ASA?
09-20-2023 06:55 AM
This may be DDos attack Looks for me, add top rule to block.
also is this outside to inside ? or inside to outside ?
09-20-2023 08:49 AM
Yes but my question is: why would there be a hostname appearing in the logs? And in the console of all things.
If we are getting a DDoS attack shouldn't the logs contain the IP address instead?
09-20-2023 10:26 AM
I have not seen before this kind of error to be honest - if you seeing this Logs on the console ?
Either ASA itself trying to connect that and does not able to resolve "that where you see ERROR: Invalid hostname" since ASA not able to resolve
or i would check any Bugs reported under release notes : ( we have observer some DNS Dos Attack under CSCvz76966 - but that was different logs)
https://www.cisco.com/c/en/us/td/docs/security/asa/asa916/release/notes/asarn916.html
Along with also suggest to Open a TAC (if this device exposed to internet)
10-27-2023 12:45 AM
Did you manage to get any further information regarding this?
I see the same kind of behaviour in our firepower (running ASA 9.18(3)56) but the IP address is the actual public/outside IP of the firewall itself:
...
ERROR: Invalid hostname: 'xx.xx.xx.xx,443'
INFO: A hostname must have letters or digits, and can have wild characters '*','?','[]'.
ERROR: Invalid hostname: 'xx.xx.xx.xx,443'
INFO: A hostname must have letters or digits, and can have wild characters '*','?','[]'.
ERROR: Invalid hostname: 'xx.xx.xx.xx,443'
INFO: A hostname must have letters or digits, and can have wild characters '*','?','[]'.
...
The output is only visible via console just as you described.
10-27-2023 05:03 AM
No, I didn't open a TAC case since we have not seen this one since.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide