Re: this is a port scan, right?

From: Unruh (unruh-spam_at_physics.ubc.ca)
Date: 07/30/05


Date: 30 Jul 2005 18:29:34 GMT

roberson@ibd.nrc-cnrc.gc.ca (Walter Roberson) writes:

>In article <dcgcd4$86u$1@nntp.itservices.ubc.ca>,
>Unruh <unruh-spam@physics.ubc.ca> wrote:
>>"Bush is a Fascist" <z333r@yahoo.com> writes:

>:>Keep in mind that no domain is associated with my server's
>:>IP.

>:Yes, it is. All computers are part of a domain, or addresses could not be
>:mapped to them.

>How's that again, Bill?

He says that "no domain is associated with my server's IP" Not with his
hostname. IP addresses naturally fall into "domains" (the class of the
address, the gateway through which the messages are routed, etc). That was
what I was refering to. Hostname be damned, nothing really depends on them.
IP addresses are all that counts. (Of course the poster mayhave thought
that somehow the worms required a fully formed name for his machine to
work. They do not. They simply make up IP addresses and try them. They are
a lot simpler than names to guess.)

>The assignment of an IP address to an interface does not depend upon
>the computer being part of a "domain" in any networking sense of the word
>"domain" that I am familiar with.

>If you wish to be able to look up a host by name to get its IP
>address, and your lookup is DNS based (as opposed to NETBIOS say),
>then Yes, then one still has the degenerate case that private DNS
>servers could be in use and that the host could be "top level"
>in the scheme of those private DNS servers.

>A hostname doesn't need to be part of a domain until you start wanting
>it to be registered in a public DNS namespace.

>Meanwhile, the port-scans and probes often go directly by IP address,
>skipping DNS, as they don't -care- what the hostname is,
>just whether they can infect the host or not. Registered hostnames
>are NOT necessary for direct access, only for symbolic access.
>--
>This signature intentionally left... Oh, darn!



Relevant Pages

  • Re: this is a port scan, right?
    ... Hostname be damned, ... then one still has the degenerate case that private DNS ... Registered hostnames ... >are NOT necessary for direct access, ...
    (comp.os.linux.networking)
  • Re: this is a port scan, right?
    ... itself through other vulnerable doze system. ... then one still has the degenerate case that private DNS ... Registered hostnames ... > are NOT necessary for direct access, ...
    (comp.os.linux.networking)
  • Re: this is a port scan, right?
    ... itself through other vulnerable doze system. ... then one still has the degenerate case that private DNS ... Registered hostnames ... > are NOT necessary for direct access, ...
    (comp.security.misc)