[Dshield] DNS Question

Carl Inglis wyrdrune at yoshiwara.org.uk
Thu Sep 25 16:31:26 GMT 2003


Quoting Bjorn Stromberg <bjorn at thechemistrylab.com>:

> Does anyone know why I'd be getting UDP Packets from my ISP's DNS
> Servers
> from port 53 to port 1031?
> 
> It doesn't happen regularly, but in my logs I see it going back for
> several
> months. Am I missing something? It happens so sporadically that I'd have
> a
> hard time catching the packets without grabbing a ton of other junk.

Running Windows?

What happens is that Windows issues (IIRC) 3 requests, and closes the port 
as soon as one of them comes back. The others are rejected and hit the 
firewall.

That's my understanding, however I'm willign to be corrected.

Carl
-- 





More information about the list mailing list