Security Incidents mailing list archives

Domain probes from 210.103.181.1


From: fire-eyes <sgtphou () FIRE-EYES YI ORG>
Date: Fri, 16 Mar 2001 18:55:47 -0500

Myself and another person on another network got these types of probes
within 5 minutes of each other.

Anyone else?

All dates are United States EST

Mar 16 18:45:19 fire-eyes kernel: DOMAIN -> <- IN=ppp0 OUT= MAC=
SRC=210.103.181
.1 DST=x LEN=58 TOS=0x00 PREC=0x00 TTL=46 ID=47503 PROTO=UDP SPT=15
93 DPT=53 LEN=38
Mar 16 18:45:19 fire-eyes kernel: DOMAIN -> <- IN=ppp0 OUT= MAC=
SRC=210.103.181
.1 DST=x LEN=493 TOS=0x00 PREC=0x00 TTL=46 ID=47505 PROTO=UDP SPT=1
593 DPT=53 LEN=473
Mar 16 18:45:20 fire-eyes kernel: DOMAIN -> <- IN=ppp0 OUT= MAC=
SRC=210.103.181
.1 DST=x LEN=493 TOS=0x00 PREC=0x00 TTL=46 ID=47508 PROTO=UDP SPT=1
593 DPT=53 LEN=473
Mar 16 18:45:20 fire-eyes kernel: DOMAIN -> <- IN=ppp0 OUT= MAC=
SRC=210.103.181
.1 DST=x LEN=493 TOS=0x00 PREC=0x00 TTL=46 ID=47511 PROTO=UDP SPT=1
593 DPT=53 LEN=473
Mar 16 18:45:21 fire-eyes kernel: DOMAIN -> <- IN=ppp0 OUT= MAC=
SRC=210.103.181
.1 DST=x LEN=493 TOS=0x00 PREC=0x00 TTL=46 ID=47514 PROTO=UDP SPT=1
593 DPT=53 LEN=473
Mar 16 18:45:40 fire-eyes iplog[265]: UDP: dgram to [deleted]
 (xxx.xxx.xxx.xxx):domain from 210.103.181.1:1593 (30 data bytes)
Mar 16 18:45:40 fire-eyes iplog[265]: UDP: dgram to [deleted]
 (xxx.xxx.xxx.xxx):domain from 210.103.181.1:1593 (465 data bytes)

--

http://ns3.clubdreamland.com/~jerky/

 "The things you own, they end up owning you." - Tyler Durden
[eof]


Current thread: