Re: Strange UDP Activity

From: Stephen Friedl (steveat_private)
Date: Tue Apr 16 2002 - 10:45:24 PDT

  • Next message: Dmitri Smirnov: "HTTP CONNECT attempts"

    > I recently started seeing strange UDP traffic to my home DSL
    
    All the traffic was returning from the root servers, and the
    source port (10xx) is irrelevant. Not sure how to explain it,
    but this is not "random" DNS traffic.
    
    198.41.0.4              a.root-servers.net
    128.9.0.107             b.root-servers.net
    192.33.4.12             c.root-servers.net
    128.8.10.90             d.root-servers.net
    192.203.230.10          E.ROOT-SERVERS.NET
    192.5.5.241             f.root-servers.net
    192.112.36.4            G.ROOT-SERVERS.NET
    128.63.2.53             h.root-servers.net
    192.36.148.17           i.root-servers.net
    198.41.0.10             j.root-servers.net
    193.0.14.129            k.root-servers.net
    198.32.64.12            l.root-servers.net
    202.12.27.33            m.root-servers.net
    
    Steve
    
    --- 
    Stephen J Friedl | Software Consultant | Tustin, CA |   +1 714 544-6561
    www.unixwiz.net  | I speak for me only |   KA8CMY   | steveat_private
    
    ----------------------------------------------------------------------------
    This list is provided by the SecurityFocus ARIS analyzer service.
    For more information on this free incident handling, management 
    and tracking system please see: http://aris.securityfocus.com
    



    This archive was generated by hypermail 2b30 : Tue Apr 16 2002 - 13:38:36 PDT