FW: DNS servers outbound connections.

From: Philip Bartholomew (Philip.Bartholomewat_private)
Date: Mon Sep 30 2002 - 04:40:27 PDT

  • Next message: Emeric Miszti: "Re: Unusual volume: UDP:137 probes"

    > Dear all
    > I wonder If any of you fine fellows can help. My 2 Nameservers are making
    > a number of  UDP connections "10-20 a minute" originating on port 53 to
    > alternating dest ports e.g.: 1113, 56008, 54002 tries about ten
    > connections to each port then moves on, the addresses they are attempting
    > to connect to are seemingly innocent websites, but not nameservers.
    > 
    > any ideas?
    > 
    > Philip Bartholomew
    > 
    > Network administrator: CmsWebView plc U.K
    > (+44) 207 7020202
    > mailto:Philip.Bartholomewat_private 
    > 
    > 
    
    ----------------------------------------------------------------------------
    This list is provided by the SecurityFocus ARIS analyzer service.
    For more information on this free incident handling, management 
    and tracking system please see: http://aris.securityfocus.com
    



    This archive was generated by hypermail 2b30 : Mon Sep 30 2002 - 13:20:17 PDT