[Dshield] Why is uncle Bill doing this?

Paul Marsh pmarsh at nmefdn.org
Tue Aug 21 13:02:38 GMT 2001


This is kind of curious, both IP's belong to uncle Bill.  Any body have an
idea what this is all about?  

08/20/2001 - 	TCP connection dropped - 	Source:207.46.106.84, 9932,
WAN - 	Destination:x.x.106, 53, LAN - 	'Name Service (DNS)' - 	Rule 0
08/20/2001 - 	TCP connection dropped - 	Source:207.46.106.84, 10169,
WAN - 	Destination:x.x.106, 53, LAN - 	'Name Service (DNS)' - 	Rule 0
08/20/2001 - 	TCP connection dropped - 	Source:207.46.106.84, 10946,
WAN - 	Destination:x.x.106, 53, LAN - 	'Name Service (DNS)' - 	Rule 0
08/20/2001 - 	TCP connection dropped - 	Source:207.46.106.84, 11150,
WAN - 	Destination:x.x.106, 53, LAN - 	'Name Service (DNS)' - 	Rule 0

08/20/2001 - 	TCP connection dropped - 	Source:207.68.131.17, 3093,
WAN - 	Destination:x.x.106, 53, LAN - 	'Name Service (DNS)' - 	Rule 0
08/20/2001 - 	TCP connection dropped - 	Source:207.68.131.17, 3362,
WAN - 	Destination:x.x.106, 53, LAN - 	'Name Service (DNS)' - 	Rule 0
08/20/2001 - 	TCP connection dropped - 	Source:207.68.131.17, 3843,
WAN - 	Destination:x.x.106, 53, LAN - 	'Name Service (DNS)' - 	Rule 0
08/20/2001 - 	TCP connection dropped - 	Source:207.68.131.17, 4230,
WAN - 	Destination:x.x.106, 53, LAN - 	'Name Service (DNS)' - 	Rule 0


Thanx, Paul




More information about the list mailing list