Security Basics mailing list archives

RE: TCP DNS requests


From: "Willis, Mark" <mwillis () fnni com>
Date: Thu, 31 Oct 2002 13:00:56 -0600

Using an employee number for an employee is our only option. There must be a record in the eHR DB2 in order to playback 
a script.

~-----Original Message-----
~From: Daniel Miessler [mailto:danielrm26 () hotmail com]
~Sent: Thursday, October 31, 2002 11:20 AM
~To: 'Carl R Diliberto'; 'security-basics'
~Subject: RE: TCP DNS requests
~
~
~Zone Transfers use TCP instead of UDP on port 53.  That is most likely
~what you are seeing.
~
~--Daniel
~
~> We are reporting TCP based DNS requests to one of our DNS servers
~coming
~> from internal, client IP addresses.  My manager would like to block
~the TCP
~> packets.  What or why would their be random TCP packets?  We 
~monitored
~> several clients and it appears it only needs UDP.
~
~


Current thread: