Re: UDP Scan port 53(dns) -> dst port <1024

From: Robert Graham (me@robertgraham.com)
Date: 02/22/02


Date: Fri, 22 Feb 2002 17:04:14 -0500 (EST)
From: Robert Graham <me@robertgraham.com>
To: incidents@securityfocus.com


>external(possibly spoofed)host:53 -UDP-> localsystem:987
>external(possibly spoofed)host:53 -UDP-> localsystem:988
>external(possibly spoofed)host:53 -UDP-> localsystem:989

These are probably replies to queries from your own machines
who are behind a NAT:

http://www.robertgraham.com/pubs/firewall-seen.html#1.9

This is a PTR response to resolve the IP address of
192.168.200.82. Since this is a private address, it points
to one machine behind your NAT resolving the IP address
of another machine behind your NAT.

----------------------------------------------------------------------------
This list is provided by the SecurityFocus ARIS analyzer service.
For more information on this free incident handling, management
and tracking system please see: http://aris.securityfocus.com



Relevant Pages

  • Re: NAT connection
    ... NAT doesn't provde name resolution for the Clients the way that a "proxying ... The Client has to be able to resolve names on its own via is ... > I have setup a NAT server in Win2000 server and in the client's> gateway and dns i point it to the NAT server ip but it doesn't resolve ...
    (microsoft.public.win2000.networking)
  • Re: Befuddled by DNS
    ... port and ran back through my forward zones, ... >>the host of the website. ... > host names you wish to resolve. ... I have not done anything with NAT, ...
    (microsoft.public.windows.server.dns)
  • Re: Windows XP profesional NAT i DHCP
    ... I don't mean some commercial solution, but if there is way to resolve this with download from MS web ... Internet Connection Sharing is native to Windows XP. ... While one PC can function as a gateway and NAT device for the other computers on your LAN, ...
    (alt.os.windows-xp)
  • Re: Hacked
    ... >After i removed the NAT, it didn't happened anymore. ... >should i do to resolve this problem? ... Jeff ...
    (microsoft.public.win2000.security)