[Firewall] Still trouble? UDP as well

Roland Haeder r.haeder at gmx.de
Tue Mar 23 18:26:23 CET 2010


no, that was a legitimate connection which has been wrongly dropped. The
source IP matches with the one of my setup-ed name server entries.

Hmmm, or someone has spoofed that IP to poison DNS requests?


On Tue, 2010-03-23 at 16:47 +0100, Arno van Amersfoort wrote:
> I see this happen too on my machines. Afaik, it's just bots looking for 
> crappy firewall that allow (all) traffic with sourceport 53....

-------------- next part --------------
A non-text attachment was scrubbed...
Name: not available
Type: application/pgp-signature
Size: 198 bytes
Desc: This is a digitally signed message part
URL: <http://rocky.eld.leidenuniv.nl/pipermail/firewall/attachments/20100323/45b6bb68/attachment.pgp>

More information about the Firewall mailing list