Security Incidents mailing list archives

Re: VPN connection attempts to resolvers?


From: Valdis.Kletnieks () vt edu
Date: Thu, 04 Apr 2002 10:53:05 -0500

On Wed, 03 Apr 2002 15:41:23 MST, Mike Lewinski <mike () rockynet com>  said:

Since I am not a VPN expert, I'm wondering if anyone else can shed some
light on what might be going on here. Is this just a brain-dead VPN client
that's making bad assumptions about it's resolvers? Or is there something
more malicious going on? The traffic was picked up after a SYN flood to one
of the DNS servers led to further investigation.

Been there, done that.  Quite possibly a Windows box that has the little
box checked for "Try to negotiate IPSec connection always" (am not a
WIndows person, not sure exactly what it's labeled).

-- 
                                Valdis Kletnieks
                                Computer Systems Senior Engineer
                                Virginia Tech

Attachment: _bin
Description:


Current thread: