logo       

portscan: msg#00643

network.dns.bind.user

Subject: portscan

Question. A routine inspection of my logs revealed the following:

May 29 08:57:40 my.router: DoS portscan 128.8.10.90,53 -> áÑ^[´à@0^Aá
,-25359-34222 PR udp len 20 135

"128.8.10.90" resolves to "d.root-servers.net" (which is ok, by itself, as I
run DNS on this server too). But the question is, why would
d.root-servers.net do a portscan??

Or is this some sort of false positive?

I appreciate any comment,

- Mark





<Prev in Thread] Current Thread [Next in Thread>
Google Custom Search

News | FAQ | advertise