Re: Possible Port scan & IP Spoof?

From: NeoSadist (neos@dist)
Date: 11/26/02


From: "NeoSadist" <neos@dist>
Date: Tue, 26 Nov 2002 14:46:12 -0700


"Mike" <mikey117@hotmail.com> wrote in message
news:LWEE9.65782$8D.1574099@twister.austin.rr.com...
> I'm running a Sonicwall DMZ & in the past week, the log file has been
> filling up in the course of a day, with the majority of the entries like
the
> following. 24.30.200.19 is a Road Runner DNS server, 24.242.XXX.YYY is my
> public IP address & the ZZZZ is about any possible port number you can
think
> of.
> 11/25/2002 12:01:41.752 - UDP packet dropped - Source:24.30.200.19, 53,
> WAN - Destination:24.242.XXX.YYY, ZZZZ, LAN
>
> I wouldn't think a Road Runner DNS server would be making all of these
> attempts. Is there a way I can find out where this is coming from & what
can
> I do to stop it?
>
>

It's possible that maybe someone's forging the packet addresses to make it
look like it's the dns server, when in reality it's not. That's a
possibility. I'd say it's a good thing you have a firewall right about now!
lol



Relevant Pages

  • Re: No BIND
    ... I am reading about strace in man as we speak. ... >>In the log file (what are the best files to ... Fix that! ... as I have successfully started the DNS server ...
    (comp.os.linux.networking)
  • Re: Event ID: 3000 warning
    ... the initial cause of these run-time events, examine the DNS server ... event log entries that precede this event. ... from filling the event log too quickly, ...
    (microsoft.public.windows.server.dns)
  • Re: Migrating users from 2000 server to 2003
    ... DNS Server log file creation at 17.01.2006 5:19:21 UTC ... Message logging key: ...
    (microsoft.public.windows.server.migration)
  • Re: No BIND
    ... > see any new jobs in top. ... Then launch it by hand, read the logs, strace it, etc. ... The log file. ...
    (comp.os.linux.networking)
  • Re: Possible Port scan & IP Spoof?
    ... Why would they be coming over every port number imaginable? ... My log file used ... Now it's daily, causing me to think ... > These are not "attempts" by a Roadrunner DNS server. ...
    (comp.security.firewalls)

Quantcast