Security Incidents mailing list archives
Domain probes from 210.103.181.1
From: fire-eyes <sgtphou () FIRE-EYES YI ORG>
Date: Fri, 16 Mar 2001 18:55:47 -0500
Myself and another person on another network got these types of probes within 5 minutes of each other. Anyone else? All dates are United States EST Mar 16 18:45:19 fire-eyes kernel: DOMAIN -> <- IN=ppp0 OUT= MAC= SRC=210.103.181 .1 DST=x LEN=58 TOS=0x00 PREC=0x00 TTL=46 ID=47503 PROTO=UDP SPT=15 93 DPT=53 LEN=38 Mar 16 18:45:19 fire-eyes kernel: DOMAIN -> <- IN=ppp0 OUT= MAC= SRC=210.103.181 .1 DST=x LEN=493 TOS=0x00 PREC=0x00 TTL=46 ID=47505 PROTO=UDP SPT=1 593 DPT=53 LEN=473 Mar 16 18:45:20 fire-eyes kernel: DOMAIN -> <- IN=ppp0 OUT= MAC= SRC=210.103.181 .1 DST=x LEN=493 TOS=0x00 PREC=0x00 TTL=46 ID=47508 PROTO=UDP SPT=1 593 DPT=53 LEN=473 Mar 16 18:45:20 fire-eyes kernel: DOMAIN -> <- IN=ppp0 OUT= MAC= SRC=210.103.181 .1 DST=x LEN=493 TOS=0x00 PREC=0x00 TTL=46 ID=47511 PROTO=UDP SPT=1 593 DPT=53 LEN=473 Mar 16 18:45:21 fire-eyes kernel: DOMAIN -> <- IN=ppp0 OUT= MAC= SRC=210.103.181 .1 DST=x LEN=493 TOS=0x00 PREC=0x00 TTL=46 ID=47514 PROTO=UDP SPT=1 593 DPT=53 LEN=473 Mar 16 18:45:40 fire-eyes iplog[265]: UDP: dgram to [deleted] (xxx.xxx.xxx.xxx):domain from 210.103.181.1:1593 (30 data bytes) Mar 16 18:45:40 fire-eyes iplog[265]: UDP: dgram to [deleted] (xxx.xxx.xxx.xxx):domain from 210.103.181.1:1593 (465 data bytes) -- http://ns3.clubdreamland.com/~jerky/ "The things you own, they end up owning you." - Tyler Durden [eof]
Current thread:
- Domain probes from 210.103.181.1 fire-eyes (Mar 17)