Re: Flood of bad DNS queries
From: Kurt Seifried (bt_at_seifried.org)
Date: 12/04/03
- Previous message: Ockey: "Re: udp and dst port 1026"
- In reply to: Brett Glass: "Flood of bad DNS queries"
- Next in thread: Jacques Bourdeau: "Re: Flood of bad DNS queries"
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ] [ attachment ]
To: <incidents@securityfocus.com>, "Brett Glass" <brett@lariat.org> Date: Wed, 3 Dec 2003 17:54:39 -0700
This behaviour was previously noted with Microsoft's load balancing
equipment (I believe it was 3DNS) and windowsupdate. Perhaps the same
problems are occuring with their load balancing of MSN servers. You can
expect to see queries trickle in well after a conneciton is established (in
some cases days later).
Kurt Seifried, kurt@seifried.org
A15B BEE5 B391 B9AD B0EF
AEB0 AD63 0B4E AD56 E574
http://seifried.org/security/
---------------------------------------------------------------------------
----------------------------------------------------------------------------
- Previous message: Ockey: "Re: udp and dst port 1026"
- In reply to: Brett Glass: "Flood of bad DNS queries"
- Next in thread: Jacques Bourdeau: "Re: Flood of bad DNS queries"
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ] [ attachment ]