Security Incidents mailing list archives
Re: strange traffic on UDP port 53
From: "Rodney Green" <rgreen () trayerproducts com>
Date: Thu, 5 Jun 2003 16:19:06 -0400
What is the access list that you applied? ---------------------------------- Hi All, We don't have a firewall and is just relying on Access-list on our border router. After i applied the new access-list I am continously receiving the logs showed below. The destination IP is our mail server (not running any DNS service) while the source IP (unsolicited and using source port with some sort of incremental patterm, the denied packets logs is also continuous now for about 4 days) I am not aware of any trojan or worm using the below. I already tried searching google but cannot find the explanation or something that might help me understand the below.... Please advise. --logs starts here--- denied udp XX7.Y3.71.242(54067) -> XX3.Y1.246.66(53), 1 packet denied udp XX7.Y3.71.242(54070) -> XX3.Y1.246.66(53), 1 packet denied udp XX7.Y3.71.242(53967) -> XX3.Y1.246.66(53), 2 packets denied udp XX7.Y3.71.242(53972) -> XX3.Y1.246.66(53), 2 packets denied udp XX7.Y3.71.242(53979) -> XX3.Y1.246.66(53), 2 packets denied udp XX7.Y3.71.242(53989) -> XX3.Y1.246.66(53), 2 packets denied udp XX7.Y3.71.242(54003) -> XX3.Y1.246.66(53), 2 packets denied udp XX7.Y3.71.242(53982) -> XX3.Y1.246.66(53), 34 packets denied udp XX7.Y3.71.242(54009) -> XX3.Y1.246.66(53), 2 packets denied udp XX7.Y3.71.242(54027) -> XX3.Y1.246.66(53), 2 packets denied udp XX7.Y3.71.242(54035) -> XX3.Y1.246.66(53), 2 packets denied udp XX7.Y3.71.242(54042) -> XX3.Y1.246.66(53), 2 packets ---------------------------------------------------------------------------- ---------------------------------------------------------------------------- ---------------------------------------------------------------------------- ----------------------------------------------------------------------------
Current thread:
- strange traffic on UDP port 53 Ronald Belchez (Jun 05)
- Re: strange traffic on UDP port 53 Valdis . Kletnieks (Jun 06)
- IRC botnets Dayne Jordan (Jun 09)
- Re: IRC botnets Angelz (Jun 10)
- IRC botnets Dayne Jordan (Jun 09)
- Re: strange traffic on UDP port 53 Rodney Green (Jun 06)
- RE: strange traffic on UDP port 53 Mike (Jun 06)
- Re: strange traffic on UDP port 53 Roger A. Grimes (Jun 09)
- RE: strange traffic on UDP port 53 David Gillett (Jun 09)
- RE: strange traffic on UDP port 53 Greg A. Woods (Jun 10)
- RE: strange traffic on UDP port 53 David Gillett (Jun 10)
- RE: strange traffic on UDP port 53 Greg A. Woods (Jun 10)
- Re: strange traffic on UDP port 53 Valdis . Kletnieks (Jun 06)
- Re: strange traffic on UDP port 53 Valdis . Kletnieks (Jun 09)
- <Possible follow-ups>
- RE: strange traffic on UDP port 53 Quarantine (Jun 10)
- Re: strange traffic on UDP port 53 Ronald Belchez (Jun 11)
- Re: strange traffic on UDP port 53 Anders Reed Mohn (Jun 12)