scanning attack 53 : Prelude
From: Rabii MOUALI (fincom_at_free.fr)
Date: 09/17/03
- Next message: Tim H.: "Re: Port 1033 (netinfo) port is open - what's it for and how do I close it"
- Previous message: Michael Gallo: "Re: Firewall suggestion?"
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ] [ attachment ]
Date: Wed, 17 Sep 2003 18:23:01 -0000
got a new mnf box up and running on a /24 network and I'm seeing alot of
entries in prelude for scanning attack from source pt 53 to several
different dest ports..... the problem is that I KNOW for a fact that this is
a dns server and the dump of the packet SHOWS that it is dns traffic.
Anybody have an info on whats goin on here? It's generating about 100 log
entries an hour(sort of odd considering it's ok traffic).....
help,
- Next message: Tim H.: "Re: Port 1033 (netinfo) port is open - what's it for and how do I close it"
- Previous message: Michael Gallo: "Re: Firewall suggestion?"
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ] [ attachment ]
Relevant Pages
|