somebody hacking ?
Tong
tong at csusb.net
Sat Nov 20 00:48:38 UTC 1999
Dear All,
I just executed 'netstat' on a name server and found
a lot of TCP connections ( about 70 ) to the DOMAIN port ( port 53 ? )
from the same IP address ( please see sample output below ).
I checked and found that the IP address corresponds to
nw3-131.world-net.co.nz . Does this mean that somebody
from there was hacking the name server ?
Any hints will be much appreciated.
Thanks.
Tong
__________________________________
tcp 0 0 ns.zapid.com:domain 202.37.68.131:3220 ESTABLISHED
tcp 0 0 ns.zapid.com:domain 202.37.68.131:3219 ESTABLISHED
tcp 0 0 ns.zapid.com:domain 202.37.68.131:3223 ESTABLISHED
tcp 0 0 ns.zapid.com:domain 202.37.68.131:3222 ESTABLISHED
tcp 0 0 ns.zapid.com:domain 202.37.68.131:3221 ESTABLISHED
tcp 0 0 ns.zapid.com:domain 202.37.68.131:3220 ESTABLISHED
tcp 0 0 ns.zapid.com:domain 202.37.68.131:3219 ESTABLISHED
tcp 0 0 ns.zapid.com:domain 202.37.68.131:3218 ESTABLISHED
tcp 0 0 ns.zapid.com:domain 202.37.68.131:3217 ESTABLISHED
tcp 0 0 ns.zapid.com:domain 202.37.68.131:3216 ESTABLISHED
tcp 0 0 ns.zapid.com:domain 202.37.68.131:3215 ESTABLISHED
tcp 0 0 ns.zapid.com:domain 202.37.68.131:3214 ESTABLISHED
tcp 0 0 ns.zapid.com:domain 202.37.68.131:3213 ESTABLISHED
tcp 0 0 ns.zapid.com:domain 202.37.68.131:3209 ESTABLISHED
tcp 0 0 ns.zapid.com:domain 202.37.68.131:3212 ESTABLISHED
tcp 0 0 ns.zapid.com:domain 202.37.68.131:3211 ESTABLISHED
tcp 0 0 ns.zapid.com:domain 202.37.68.131:3210 ESTABLISHED
tcp 0 0 ns.zapid.com:domain 202.37.68.131:3208 ESTABLISHED
tcp 0 0 ns.zapid.com:domain 202.37.68.131:3207 ESTABLISHED
tcp 0 0 ns.zapid.com:domain 202.37.68.131:3206 ESTABLISHED
tcp 0 0 ns.zapid.com:domain 202.37.68.131:3205 ESTABLISHED
tcp 0 0 ns.zapid.com:domain 202.37.68.131:3204 ESTABLISHED
More information about the bind-users
mailing list