RE: Basic Question only

From: Joe Klein (jsklein@mindspring.com)
Date: 10/31/02


From: "Joe Klein" <jsklein@mindspring.com>
To: "'Christopher Rea'" <chris_rea@hotmail.com>, <security-basics@security-focus.com>
Date: Thu, 31 Oct 2002 15:25:39 -0500

Christopher,

To begin with, you need to identify who owns the IP address:

You can do this in two way:

1. Use the whois command in UNIX or
2. go to http://ws.arin.net/cgi-bin/whois.pl to look up each of the IP
addresses.

Next you may want to look up this ip address to see if this IP address
or type of scan is chronic throught out the Internet. Go to
www.incidents.org.

At this point, you need to decide, based on your security policy and
your incident handling policy, what to do next.

Joe Klein, CISSP

-----Original Message-----
From: Christopher Rea [mailto:chris_rea@hotmail.com]
Sent: Wednesday, October 30, 2002 11:52 PM
To: security-basics@security-focus.com
Subject: Basic Question only

I am sure that this is a silly question, but who are these guys that
keep
trying my firewall on port 53 (DNS) and port 8. I am sure they must be
the
good guys, but why do they keep knocking, I only have one DNS server
that is
setup for lookup mode ???

66.28.34.130

204.71.35.136

212.62.17.145

64.14.117.10

66.28.12.98

65.119.25.162

205.158.108.194

64.15.251.198

204.176.88.5

208.185.54.14

64.0.96.12

213.61.6.2



Relevant Pages

  • Re: Unknown svchost.exe DNS port 53 network activity
    ... activity on my router as well as my PC LAN connection icon in the tray. ... port 53 with a remote address of my ISP's DNS server. ... No traffic can come to the machine, unless you have opened the inbound port ... Svchost allows the communication between machines in a LAN or WAN situation. ...
    (comp.security.firewalls)
  • RE: problems receiving e-mail to my server redux
    ... I installed BIND on my Linux box and set it up to start at every ... > To: Ed McCorduck ... > run a dns server if you want things to work. ... > which implies that you are trying to use port 80 for your dns server. ...
    (RedHat)
  • Re: SendPort
    ... If you want your DNS server should listen on port other than 53, ... the best way would be to have a firewall or set up NAT, ... on which the DNS servers is listening then what will you achieve with this? ...
    (microsoft.public.windows.server.dns)
  • Re: questionable access to my computer - please help
    ... > Download portref.zip from: wilders.org for a full port reference listing. ... > If the firewall is blocking internet access to that addy, ... even shows you that it _is_ a DNS server. ... The only question here is what is more stupid, this firewall simulation ...
    (comp.security.firewalls)
  • Re: DNS lookup not working
    ... That is exactly why it is not working because you have filtering enabled on ... UDP and it is blocking return traffic to your computer from your ISP DNS ... The only time you would want to enable UDP filtering for port 53 ... would be if you were running a DNS server. ...
    (microsoft.public.windowsxp.security_admin)

Loading