Re: Why is my ISP scanning me?

From: Adorai (bob@mindway.com)
Date: 04/16/02


From: bob@mindway.com (Adorai)
Date: 16 Apr 2002 03:34:59 -0700

Igor <Igor9277@sprynet.com> wrote in message news:<jb2cbu4sevrf7rfekq80m2b37i086qpk39@4ax.com>...

> >So the ip address is obviously the one from the dns server of the ISP.
> >
> >What you believe to be a hacker portscanning is indeed the ISP's DNS
> >server sending DNS reply packets which that stupid zone alarm drops due
> >to misconfigurationSo . There is a problem, and that is the person
> >sitting in front of the monitor beeing too stupid to configure this
> >so-called firewall to allow answers from his ISP's DNS server. And the
> >other problem is of your you, our well known nutcase writing the usual
> >nonsense.
> >
> Yes. But this does not answer why this just started, coincident with my obtaining a static IP address.
> No changes were made to ZA config -- i.e., before and after static IP assigned.

My guess would be that ns1.mindspring.com is allowed, when it doesn't
respond quick enough and your machine tries to get the DNS from the
backup, which is the one listed in your log, ZA denies those because
it has no idea it SHOULD be accepting those packets. Why it just
started? Who knows, could be that ns1.mindspring.com has just been
really busy lately and isn't able to respond as super fast as it
should be.

Adorai



Relevant Pages

  • Re: Cant Resolve Certain internet DNS names
    ... Our firewall was already using 1500 MTU, but the Checkpoint SmartDefense ... Why are some websites using non-RFC compliant packets for DNS? ... > DNS server, but this reduces DNS efficiency because queries that won't fit ...
    (microsoft.public.windows.server.dns)
  • Re: DNS Fixup/Inspect Pix/ASA 7.0 or greater breaking email
    ... emails being sent to AOL and Comcast plus a few other mom and pops to hang ... I have that there is no way that a DNS inspect command could cause only ... long responses have the response dropped, ... 1500 byte packets these days, that they can just send back longer ...
    (comp.dcom.sys.cisco)
  • A paper by Amit Klein (Trusteer): "OpenBSD DNS Cache Poisoning and Multiple O/S Predictable IP ID Vu
    ... DNS transaction ID (OpenBSD ported BIND 9 into their code tree, ... fragmentation ID normalization feature (e.g. "scrub out random- ... packets and raw IP packets. ...
    (Bugtraq)
  • Re: IP Tables DNS issues
    ... >I'm having problem with my IP tables allowing DNS queries, ... ># Log packets with impossible source addresses ... There is significant discussion of the merits of DROP verses DENY ... (send RESET or ICMP Type 3). ...
    (comp.security.firewalls)
  • RE: Firewall Rule Set not allowing access to DNS servers?
    ... I changed the DNS rules as you suggested, and the firewall works perfectly - ... > # Allow out access to my ISP's Domain name server. ... > so your udp packets never match this rule and default to ...
    (freebsd-questions)

Quantcast