Security Incidents mailing list archives

Re: Increase in DNS traffic?


From: <measl () mfn org>
Date: Wed, 8 Aug 2001 15:36:45 -0500 (CDT)



On Tue, 7 Aug 2001, kath wrote:

Anyone see a spike in traffic to port 53?

This is really odd, considering noone really uses this DNS server for
lookups.

- k

But I'll bet *you* use it for DNS lookups, dontcha ;-)   ?

Everytime a CRII infected system tries your web server, you probably do a
lookup.  DNS traffic has been mimicking CRII traffic, for obvious
reasons...

 -- 
Yours, 
J.A. Terranson
sysadmin () mfn org

If Governments really want us to behave like civilized human beings, they
should give serious consideration towards setting a better example:
Ruling by force, rather than consensus; the unrestrained application of
unjust laws (which the victim-populations were never allowed input on in
the first place); the State policy of justice only for the rich and 
elected; the intentional abuse and occassionally destruction of entire
populations merely to distract an already apathetic and numb electorate...
This type of demogoguery must surely wipe out the fascist United States
as surely as it wiped out the fascist Union of Soviet Socialist Republics.

The views expressed here are mine, and NOT those of my employers,
associates, or others.  Besides, if it *were* the opinion of all of
those people, I doubt there would be a problem to bitch about in the
first place...
--------------------------------------------------------------------



----------------------------------------------------------------------------
This list is provided by the SecurityFocus ARIS analyzer service.
For more information on this free incident handling, management 
and tracking system please see: http://aris.securityfocus.com


Current thread: