[Dshield] DNS traffic?

Johannes Ullrich jullrich at euclidian.com
Tue Aug 26 12:38:51 GMT 2003

can you post some full packets please? Off list is fine if you don't
want to post them public.

On Tue, 2003-08-26 at 02:24, Bob Love wrote:
> I'm seeing a huge increase in DNS probes the last 24 hours, every few hours I get a blast of UDP probes to port 53 from the same half a dozen or so machines... is it just me? Is there some new Bind or MSDNS exploit I haven't heard about?
> Regards
> Bob
> _______________________________________________
> list mailing list
> list at dshield.org
> To change your subscription options (or unsubscribe), see: http://www.dshield.org/mailman/listinfo/list
Johannes Ullrich                     jullrich at euclidian.com
pgp key: http://johannes.homepc.org/PGPKEYS
   "We regret to inform you that we do not enable any of the 
    security functions within the routers that we install."
         support at covad.net

More information about the list mailing list