[fw-wiz] Domain Name Requests

From: Rick Greep (RickGreep_at_cti-consulting.com)
Date: 02/11/05

  • Next message: ArkanoiD: "[fw-wiz] i-cap proposals"
    To: Firewall Wizards <firewall-wizards@honor.icsalabs.com>
    Date: Fri, 11 Feb 2005 10:11:33 -0600
    
    

    Hello,

            Within the last month I have noticed a number of packets directed to port 53
    on my home connection. The limited information from my router only reports
    that inbound packets were directed to port 53 from > 1024 but not whether it
    was UDP or TCP. I am getting around 50 hits per day in bursts from 5 to 30 at
    a time from random sites.

            I am running named internally but inbound connections from the internet are
    blocked. The requests are coming from ISP's like level3.net but also from
    non-ISP's like doubleclick.net.

            Is anyone else seeing this? Could this be some type of worm attempting to
    spread to DNS servers? I remember doubleclick being attacked with some type
    of DNS denial of service a couple of months ago, could this be related?

            
    Take care,

    -- 
    Rick Greep, Core Technologies, Inc.
    RickGreep@cti-consulting.com
    Phone: 877 293-2702
    Public Key: 807E9BD3
    _______________________________________________
    firewall-wizards mailing list
    firewall-wizards@honor.icsalabs.com
    http://honor.icsalabs.com/mailman/listinfo/firewall-wizards
    

  • Next message: ArkanoiD: "[fw-wiz] i-cap proposals"

    Relevant Pages

    • Re: Netgear RP114 Problem
      ... >> Does your router provide your pc's with an ip address via dhcp? ... By default the rp114 will do dhcp for the first 30 ip addresses or so ... you can set the DNS servers of your ISP. ... can open a port or range of ports to a host. ...
      (Fedora)
    • Re: Cant Resolve from behind firewall
      ... DNS servers are even getting past the handshake phase? ... do have to strict usage to port 80, now with the PDM i try permiting ... The information in this e-mail, and any attachment therein, is confidential ... Although the Company attempts to sweep e-mail and attachments for viruses, ...
      (Security-Basics)
    • Re: Risks of not using isps DNS
      ... When you say "we are all getting" port probes, ... non local DNS servers does this make me a target for more of these ... are my dns lookups to that proxy still ... > The downside of not using your ISPs DNS server is that lookups ...
      (comp.security.firewalls)
    • Re: Port 32512 DNS queries
      ... | with replies from DNS servers to queries (inverse look-ups on the IP ... | addresses of the DNS servers listed in /etc/resolv.conf) issued from port ... Does anyone know of a Linux client process that runs ... BOFH excuse #448: The cause of the problem is: greenpeace free'd the mallocs ...
      (comp.os.linux.networking)
    • Re: 2K3 Server - 2 NICS, 1 External, 1 Internal.. Heres my problem...
      ... I believe before, I left the G/W and DNS Servers out of NIC 2, and I ... couldn't cruise the internet at all from within the building. ... >> This NIC is plugged Directly into the back of Port 1 of my 4 Port DSL ...
      (microsoft.public.windows.server.networking)