Hi!
Im running snort om my firewall and it keeps catching connections from
one of my ISP's DNS servers. Im quite sure this traffic is legit but it
has been bugging me for while what it's there for. Since its coming from
port 53 Im guessing that it has something todo with DNS. My ISP assigns
a
On Sun, 13 Jan 2002, Peter [ISO-8859-1] Jnsson wrote:
Hi!
Im running snort om my firewall and it keeps catching connections from
one of my ISP's DNS servers. Im quite sure this traffic is legit but it
has been bugging me for while what it's there for. Since its coming from
port 53 Im
Ok..
I pretty sure now that this is just snort reporting when the dns-server
sends back the data from the lookup. The dns-server just happens to send
it to some port that snort is looking for traffic on. But wont this make
it very easy to hide your attempts to connect to a backdoor ( or
You need to say Yes to Network Firewalls, IP: firewalling,
IP: masquerading and IP: masquerading special modules support.
You also need to say Yes to Prompt for development and/or
incomplete code/drivers if you haven't already.
j.
--
Jeremy L. Gaddis [EMAIL PROTECTED]
-Original
4 matches
Mail list logo