Re: Curious DNS traffic



Do you see any unusual volumes of outgoing SMTP traffic, or possibly SMTP
originating from inappropriate hosts? If this is a hack, one reason to do
the DNS lookups on a controlled machine might be to guarantee the ability to
do MX record lookups at higher speeds for sending spam from the machine.

If the target host is controlled by the same group, then all bets are off
and you would need to look at the actual traffic. They could run telnet on
port 53 and just be trying to bypass the firewall ruleset over well known
ports.

Anyway, sounds like you have some fun debugging ahead. :)

--
Will


"Dougga" <doug.almquist@xxxxxxxxx> wrote in message
news:1192648682.292497.88830@xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx
I'm seeing strange DNS traffic from one of my windows hosts.
Specifically I have a WinXP client on a Windows domain that his
attmepting to communicate to external hosts on port 53.

Here's a single line from my firewall log:
2:08:56 Default DROP TCP 10.1.10.5:2818 ? 193.0.14.129 : 53 [SYN]
len=52 ttl=127 tos=0x00 srcmac=00:09:5b:89:d2:0a
dstmac=00:13:46:e6:13:5e

The target hosts is a root server in the Netherlands so it appears
that this client is acting as a DNS Server and ignoring the local
server that it understands to be its own server. Using traditional
command line tools, it queries the local DNS server while continuing
to attempt communications externally to the root DNS servers.

Does anyone have hints as to why this would be?
I've tried the usual suspects of network protocol settings (DHCP-
defined servers and explicit definitions of DNS servers).

Thanks


.



Relevant Pages

  • Re: Restrict Dynamic Updates
    ... outlined in the article "HOW TO Configure DNS for Internet Access in ... Windows Server 2003", realizing that that was not the initial intent ... internal DNS server host external public data. ... internal DNS server that hosts your internal AD infrastructure access from ...
    (microsoft.public.windows.server.dns)
  • Re: questionable access to my computer - please help
    ... Just because a server is running a DNS listener, ... the source port was irrelevant. ... > which looks much like a DNS server. ... > The only question here is what is more stupid, this firewall simulation ...
    (comp.security.firewalls)
  • Re: No outgoing email - everything else OK
    ... If you cannot telnet out on port 25 from your SBS Server then something is ... Checking TCP/UDP SOA serial number using DNS server. ... Starting TCP and UDP DNS queries for the local domain. ...
    (microsoft.public.backoffice.smallbiz2000)
  • Re: IE6 Stops Working, Emails, Ping, Other ports just fine
    ... Server: nscache.prserv.net ... Could not open a connection to host on port ... > A contrary condition could occur if either your HOSTS file or your ... > is try to verify connectivity to that server without using IE. ...
    (microsoft.public.windows.inetexplorer.ie6.browser)
  • Re: IE6 Stops Working, Emails, Ping, Other ports just fine
    ... Server: nscache.prserv.net ... Could not open a connection to host on port ... > A contrary condition could occur if either your HOSTS file or your ... > is try to verify connectivity to that server without using IE. ...
    (microsoft.public.win2000.networking)