Re: DNS Activity - Strange or Not?

From: RainbowHat (nHiATlE@blSackholeP.mAit.edMu.invalid)
Date: 03/16/02


From: RainbowHat <nHiATlE@blSackholeP.mAit.edMu.invalid>
Date: Sat, 16 Mar 2002 06:26:02 +0000 (UTC)


< Morgan
>i've also checked the other boxes on my lan for rootkits /
>virii and have found nothing yet.

Here is not a answer but a little suggestion. How about you run
`tcpdump` on internal interface. If there are many traffics, the
cause is other boxes. If not, the cause is your firewall box. You
can divide the problem. If firewall box, how about you try `netstat`
or `lsof` and `grep 1099`. You can find which process open port 1099.

-- 
Best Regards, RainbowHat.
http://www.tuxedo.org/~esr/faqs/hacker-howto.html#BELIEVE1
a belief that even though you may not know all of what you need to solve 
a problem, if you tackle just a piece of it and learn from that, you'll 
learn enough to solve the next piece -- and so on, until you're done.
----+----1----+----2----+----3----+----4----+----5----+----6----+----7



Relevant Pages

  • Re: Suggest firewall for Win98se+ICS(dialup)+NAV
    ... to go out and buy all new boxes capable of running Win 2000 Pro or Win XP ... |> either disable the firewall or otherwise change its settings. ... vulnerability in a small business environment is from the inside, ... Any disgruntled Win 98 SE user can obviously walk in and install something ...
    (comp.security.firewalls)
  • Re: [fw-wiz] segmentation of DMZs
    ... public as well as private boxes. ... In fact, separate zones can make some things easier, for instance when ... as they pass through the firewall, so that the response always passes ... "open ports x,y,z and 1024-65535 in both directions", etc. ...
    (Firewall-Wizards)
  • Fwd: Re: [Full-Disclosure] Microsoft urging users to buy Harware Firewalls
    ... In my exprerience, these boxes just work. ... So why should we have to stick a firewall in front of a machine ... NAT boxes and hardware firewalls are tools. ... I myself put my windows boxes ...
    (Full-Disclosure)
  • Re: Firewall for VMS / TRU64
    ... >> something like the WatchGuard brand boxes ... >There appears to be heavy competition in the firewall/router market ... and it does not appear that any general purpose operating ... They have their own Sunscreen firewall package running on Solaris ...
    (comp.os.vms)
  • Re: recommended for home use
    ... and seems to be adding big features all the time. ... OOTH, if you have say, a netgear firewall box. ... Sonicwall/Watchguard/Dlink type boxes. ... The enterprise level boxes do tend to support more higher-end ...
    (comp.dcom.sys.cisco)