Security Incidents mailing list archives

Re: Strange DNS/TCP activity


From: asmodeus () BENSHAW COM (Asmodeus)
Date: Thu, 27 Jan 2000 11:15:08 -0500


On Wed, 26 Jan 2000, Pavel Kankovsky wrote:

Our nameservers have been a subject of suspicious probes (?) aimed at TCP
port 53 recently. Here is a genuine tcpdump transcript of one of the
probes (line-wrapped for better readability):
<snip>

 A server I administrate has received the same probes for months now.
ALways from 3 increasing ports, the first port number is always rounded to
the nearest hundred (as in 2900,2901,2902; 2800,2801,2802, etc)

 There seem to be a number of machines in a single class C which are doing
it, and several which are from other IP blocks.

 IIRC, I received no response from the whois-obtained contacts.

.Shawn


Current thread: