[Dshield] DNS traffic?

Johannes Ullrich jullrich at euclidian.com
Tue Aug 26 12:38:51 GMT 2003


can you post some full packets please? Off list is fine if you don't
want to post them public.

On Tue, 2003-08-26 at 02:24, Bob Love wrote:
> I'm seeing a huge increase in DNS probes the last 24 hours, every few hours I get a blast of UDP probes to port 53 from the same half a dozen or so machines... is it just me? Is there some new Bind or MSDNS exploit I haven't heard about?
> 
> Regards
> 
> Bob
> 
> _______________________________________________
> list mailing list
> list at dshield.org
> To change your subscription options (or unsubscribe), see: http://www.dshield.org/mailman/listinfo/list
-- 
--------------------------------------------------------------
Johannes Ullrich                     jullrich at euclidian.com
pgp key: http://johannes.homepc.org/PGPKEYS
--------------------------------------------------------------
   "We regret to inform you that we do not enable any of the 
    security functions within the routers that we install."
         support at covad.net
--------------------------------------------------------------





More information about the list mailing list