Port scan by DNS normal?

Port scan by DNS normal?

Secure Home | Search | About
 Networking Firewalls    Post an article   get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content add this group's latest topics to your Google content
Subject Author Date
Port scan by DNS normal? HotRdd 03-19-2007
Posted by HotRdd on March 19, 2007, 4:16 pm
If you were  Registered and logged in, you could reply and use other advanced thread options
A few months ago I noticed that I start to get a High priority warning about
a port scan on my PC. This is a work PC that is connected to a wireless
router and a DSL modem. After having a closer look and doing a BackTrace the
IP address belongs to my ISPs DNS server. Is this normal?

Severity = Major
Direction = Inbound
Protocol = UDP



Posted by Rick Merrill on March 19, 2007, 4:28 pm
If you were  Registered and logged in, you could reply and use other advanced thread options
HotRdd wrote:
> A few months ago I noticed that I start to get a High priority warning about
> a port scan on my PC. This is a work PC that is connected to a wireless
> router and a DSL modem. After having a closer look and doing a BackTrace the
> IP address belongs to my ISPs DNS server. Is this normal?
>
> Severity = Major
> Direction = Inbound
> Protocol = UDP
>
>

Actually, I think it is normal!

Post some bits of the log file. (You Do have a log file don't you?)

Posted by Ansgar -59cobalt- Wiechers on March 19, 2007, 5:09 pm
If you were  Registered and logged in, you could reply and use other advanced thread options
> A few months ago I noticed that I start to get a High priority warning
> about a port scan on my PC. This is a work PC that is connected to a
> wireless router and a DSL modem. After having a closer look and doing
> a BackTrace the IP address belongs to my ISPs DNS server. Is this
> normal?

You should ask your ISP that, since they are the only ones who'd be able
to answer the question.

> Severity = Major
> Direction = Inbound
> Protocol = UDP

That's not very informative. Is that all that's in your logs? Did you
run a sniffer to capture the traffic from that portscan for further
analysis?

cu
59cobalt
--
"If a software developer ever believes a rootkit is a necessary part of
their architecture they should go back and re-architect their solution."
--Mark Russinovich

Posted by Wolfgang Kueter on March 19, 2007, 5:42 pm
If you were  Registered and logged in, you could reply and use other advanced thread options
HotRdd wrote:

> A few months ago I noticed that I start to get a High priority warning
> about a port scan on my PC. This is a work PC that is connected to a
> wireless router and a DSL modem. After having a closer look and doing a
> BackTrace the IP address belongs to my ISPs DNS server. Is this normal?
>
> Severity = Major
> Direction = Inbound
> Protocol = UDP

Let me guess: The destination port of those packets is > 1024, the source
port is 53 ...

Well, yes it is absolutely normal for various completely braindead personal
firewalls to misinterpret DNS answer packets from the DNS server you use as
a UDP scan. Since you decided to install one of those famous network
communication destruction tools I'm afraid you'll have to live with such
effects.

Wolfgang

Posted by HotRdd on March 20, 2007, 8:37 am
If you were  Registered and logged in, you could reply and use other advanced thread options
I'm using System Suite 7 and there doesn't seem to be any log file
generated. Even turning on Capture Packets doesn't get any of the packets
that I need.



Similar ThreadsPosted
Port scan activty January 11, 2006, 2:35 am
Sonicwall "possible port scan" Help! May 21, 2007, 10:31 am
UPD Port Scan from DNS Server Happening, What's Up? January 15, 2006, 2:30 pm
Frequnt port scan attacks October 15, 2007, 9:42 am
Port scan from grc.com fails 1st time passes the 2nd? March 11, 2005, 3:46 pm
ICMP, normal traffic? October 2, 2006, 12:18 pm
application level gateway vs 'normal' gatway May 17, 2005, 2:11 pm
TCP FIN scan April 14, 2006, 3:08 am
Attempt to scan ports March 12, 2006, 7:59 pm
using nmap to scan firewall September 2, 2007, 12:56 pm

The site map in XML format XML site map

Contact Us | Privacy Policy