[Dshield] Can you pros take a look?

Johannes B. Ullrich jullrich at euclidian.com
Sat Jul 21 02:03:14 GMT 2001


To me, they look like harmless and necessary DNS server responses.


On Fri, 20 Jul 2001, Paul Marsh wrote:

>
> 	Can you pro's take a look?  This is a little snap shot of my
> firewall log, can anyone tell me what these are from?  Some days it's just a
> few and other days there are a lot of them.
>
> Thanx, Paul
>
> 	UDP packet dropped - 	Source:209.xxx.xx.x, 53, WAN -
> Destination:192.xxx.x.xx, 3454, LAN - 	 -
> 	UDP packet dropped - 	Source:209.xxx.xx.x, 53, WAN -
> Destination:192.xxx.x.xx, 3602, LAN - 	 -
> 	UDP packet dropped - 	Source:209.xxx.xx.x, 53, WAN -
> Destination:192.xxx.x.xx, 3650, LAN - 	 -
> 	UDP packet dropped - 	Source:209.xxx.xx.x, 53, WAN -
> Destination:192.xxx.x.xx, 3853, LAN - 	 -
> 	UDP packet dropped - 	Source:209.xxx.xx.x, 53, WAN -
> Destination:192.xxx.x.xx, 3995, LAN - 	 -
> 	UDP packet dropped - 	Source:209.xxx.xx.x, 53, WAN -
> Destination:192.xxx.x.xx, 4088, LAN - 	 -
> 	UDP packet dropped - 	Source:209.xxx.xx.x, 53, WAN -
> Destination:192.xxx.x.xx, 4124, LAN - 	 -
>
>
>
> _______________________________________________
> Dshield mailing list
> Dshield at dshield.org
> To change your subscription options (or unsubscribe), see: http://www1.dshield.org/mailman/listinfo/dshield
>

-- 
-------
jullrich at sans.org                    Join http://www.DShield.org
                                     Distributed Intrusion Detection System





More information about the list mailing list