Security Incidents mailing list archives

connections from Microsoft to dns server?


From: admin () SCORPIONS NET (Alex Blinetskiy)
Date: Thu, 6 Apr 2000 13:03:02 -0400


Some weird incoming connections from microsoft it keeps on connecting for
2 days ....

Apr  6 12:57:44 doit tcplogd: "Syn
probe" 208.184.4.138.microsoft.com[208.184.4.138]:[2300]->ns.scorpions.net[209.123.217.66]:domain
Apr  6 12:57:44 doit tcplogd: "Syn
probe" 208.184.4.138.microsoft.com[208.184.4.138]:[2301]->ns.scorpions.net[209.123.217.66]:domain
Apr  6 12:57:44 doit tcplogd: "Syn
probe" 208.184.4.138.microsoft.com[208.184.4.138]:[2302]->ns.scorpions.net[209.123.217.66]:domain

another ip also from them:
Apr  6 12:57:32 doit tcplogd: "Syn
probe" 207.46.106.75[207.46.106.75]:[2200]->ns.scorpions.net[209.123.217.66]:domain
Apr  6 12:57:32 doit tcplogd: "Syn
probe" 207.46.106.75[207.46.106.75]:[2201]->ns.scorpions.net[209.123.217.66]:domain
Apr  6 12:57:32 doit tcplogd: "Syn
probe" 207.46.106.75[207.46.106.75]:[2202]->ns.scorpions.net[209.123.217.66]:domain

ANyone has any ideas?
Thanks,
Alex Blinetskiy


Current thread: