Security Incidents mailing list archives

FW: DNS servers outbound connections.


From: Philip Bartholomew <Philip.Bartholomew () cms co uk>
Date: Mon, 30 Sep 2002 12:40:27 +0100


Dear all
I wonder If any of you fine fellows can help. My 2 Nameservers are making
a number of  UDP connections "10-20 a minute" originating on port 53 to
alternating dest ports e.g.: 1113, 56008, 54002 tries about ten
connections to each port then moves on, the addresses they are attempting
to connect to are seemingly innocent websites, but not nameservers.

any ideas?

Philip Bartholomew

Network administrator: CmsWebView plc U.K
(+44) 207 7020202
mailto:Philip.Bartholomew () CMS co uk 



----------------------------------------------------------------------------
This list is provided by the SecurityFocus ARIS analyzer service.
For more information on this free incident handling, management 
and tracking system please see: http://aris.securityfocus.com


Current thread: