Security Incidents mailing list archives

low numbers connects to DNS?


From: Kurt Weiske <kweiske () KATAAN ORG>
Date: Sun, 23 Jul 2000 08:59:11 -0700

My system is primary DNS server for my domain. My IPchains filters started
logging several connects over ports < 1024 (but not 53) to my domain port
(port 53) a few nights ago.

Is this normal? I thought named would try and use a non-priveliged source
port (over 1024) to connect to a server's destination domain port.

--Kurt

(BTW, thanks to the list for some wonderful insights over the past few
months. I've been lurking around here, and feel like I've learned a lot from
listening in on the conversations going on here...)


---
Kurt Weiske
email: kweiske () kataan org


Current thread: