[Dshield] DNS from Taiwan ?

Daniel Cherton dcherton at aei.ca
Mon Jun 27 02:00:43 GMT 2005


Hi,

Following the list is very interesting, one thing I did was to check
my setup for sending logs according to recommendation, and it's working 
properly.

One thing I noticed was, that every time Dshield client is sending a log
and that my DSL is off, the dial on demand is open by the following request:

PPPoE: opening connection ... src:myIP:2388 dst:168.95.192.1:53

I cannot see anything special with ethereal before and after this event.

My two other computers are doing the same when booting.

Being in Canada or anywhere else, I don't see why a DNS from Taiwan 
(hntp1.hinet.net)
 is used to open my connection. My ISP gives me a dynamic address with 2 
DNS.

Is there a way to track what is happening ?

Thanks.



-- 
No virus found in this outgoing message.
Checked by AVG Anti-Virus.
Version: 7.0.323 / Virus Database: 267.8.1/28 - Release Date: 6/24/2005



More information about the list mailing list