Fandelem
12-13-2000, 07:00 AM
Dec 12 22:06:58 TCP: port 28929 connection attempt from jhu2109.res.jhu.edu (128.220.196.43):4199
Dec 12 22:06:59 TCP: port 28929 connection attempt from 036resup156.chartermi.net (24.247.36.156):13
92
Dec 12 22:06:59 TCP: port 28929 connection attempt from jhu2109.res.jhu.edu (128.220.196.43):4199
Dec 12 22:07:01 last message repeated 1 times
Dec 12 22:07:01 TCP: port 28929 connection attempt from jhu2109.res.jhu.edu (128.220.196.43):4200
Dec 12 22:07:02 last message repeated 1 times
Dec 12 22:07:02 TCP: port 28929 connection attempt from 036resup156.chartermi.net (24.247.36.156):13
92
Dec 12 22:07:02 TCP: port 28929 connection attempt from jhu2109.res.jhu.edu (128.220.196.43):4200
Dec 12 22:07:08 TCP: port 28929 connection attempt from 036resup156.chartermi.net (24.247.36.156):13
92
Dec 12 22:07:46 last message repeated 1 times
Dec 12 22:07:46 TCP: port 28929 connection attempt from 036resup156.chartermi.net (24.247.36.156):13
93
Dec 12 23:11:24 last message repeated 3 times
Dec 12 23:11:24 TCP: port 28929 connection attempt from 036resup156.chartermi.net (24.247.36.156):14
38
Dec 12 23:24:48 last message repeated 3 times
Dec 12 23:24:48 UDP: dgram to port 1223 from i.root-servers.net (192.36.148.17):53 (446 data bytes)
Dec 12 23:24:52 UDP: dgram to port 1223 from l.root-servers.net (198.32.64.12):53 (446 data bytes)
Dec 12 23:25:00 UDP: dgram to port 1223 from f.root-servers.net (192.5.5.241):53 (443 data bytes)
Dec 12 23:25:04 UDP: dgram to port 1223 from m.root-servers.net (202.12.27.33):53 (446 data bytes)
Dec 12 23:25:15 UDP: dgram to port 1223 from E.ROOT-SERVERS.NET (192.203.230.10):53 (443 data bytes)
Dec 12 23:25:16 UDP: dgram to port 1223 from k.root-servers.net (193.0.14.129):53 (446 data bytes)
Dec 12 23:25:17 UDP: dgram to port 1223 from h.root-servers.net (128.63.2.53):53 (446 data bytes)
Dec 12 23:25:21 UDP: dgram to port 1223 from b.root-servers.net (128.9.0.107):53 (446 data bytes)
Dec 12 23:25:24 UDP: dgram to port 1223 from d.root-servers.net (128.8.10.90):53 (446 data bytes)
Dec 12 23:25:28 UDP: dgram to port 1223 from j.root-servers.net (198.41.0.10):53 (446 data bytes)
Dec 12 23:25:32 UDP: dgram to port 1223 from a.root-servers.net (198.41.0.4):53 (129 data bytes)
this goes on for pages and pages..
should I be worried that these servers are sending stuff to port 1223? it's originating from port 53 which is DNS - which is why I don't get it - I have a name caching DNS server [it shouldn't broadcast, should it??] - if anyone is a DNS guru, maybe I could post my named.conf and see if I am?
Dec 12 22:06:59 TCP: port 28929 connection attempt from 036resup156.chartermi.net (24.247.36.156):13
92
Dec 12 22:06:59 TCP: port 28929 connection attempt from jhu2109.res.jhu.edu (128.220.196.43):4199
Dec 12 22:07:01 last message repeated 1 times
Dec 12 22:07:01 TCP: port 28929 connection attempt from jhu2109.res.jhu.edu (128.220.196.43):4200
Dec 12 22:07:02 last message repeated 1 times
Dec 12 22:07:02 TCP: port 28929 connection attempt from 036resup156.chartermi.net (24.247.36.156):13
92
Dec 12 22:07:02 TCP: port 28929 connection attempt from jhu2109.res.jhu.edu (128.220.196.43):4200
Dec 12 22:07:08 TCP: port 28929 connection attempt from 036resup156.chartermi.net (24.247.36.156):13
92
Dec 12 22:07:46 last message repeated 1 times
Dec 12 22:07:46 TCP: port 28929 connection attempt from 036resup156.chartermi.net (24.247.36.156):13
93
Dec 12 23:11:24 last message repeated 3 times
Dec 12 23:11:24 TCP: port 28929 connection attempt from 036resup156.chartermi.net (24.247.36.156):14
38
Dec 12 23:24:48 last message repeated 3 times
Dec 12 23:24:48 UDP: dgram to port 1223 from i.root-servers.net (192.36.148.17):53 (446 data bytes)
Dec 12 23:24:52 UDP: dgram to port 1223 from l.root-servers.net (198.32.64.12):53 (446 data bytes)
Dec 12 23:25:00 UDP: dgram to port 1223 from f.root-servers.net (192.5.5.241):53 (443 data bytes)
Dec 12 23:25:04 UDP: dgram to port 1223 from m.root-servers.net (202.12.27.33):53 (446 data bytes)
Dec 12 23:25:15 UDP: dgram to port 1223 from E.ROOT-SERVERS.NET (192.203.230.10):53 (443 data bytes)
Dec 12 23:25:16 UDP: dgram to port 1223 from k.root-servers.net (193.0.14.129):53 (446 data bytes)
Dec 12 23:25:17 UDP: dgram to port 1223 from h.root-servers.net (128.63.2.53):53 (446 data bytes)
Dec 12 23:25:21 UDP: dgram to port 1223 from b.root-servers.net (128.9.0.107):53 (446 data bytes)
Dec 12 23:25:24 UDP: dgram to port 1223 from d.root-servers.net (128.8.10.90):53 (446 data bytes)
Dec 12 23:25:28 UDP: dgram to port 1223 from j.root-servers.net (198.41.0.10):53 (446 data bytes)
Dec 12 23:25:32 UDP: dgram to port 1223 from a.root-servers.net (198.41.0.4):53 (129 data bytes)
this goes on for pages and pages..
should I be worried that these servers are sending stuff to port 1223? it's originating from port 53 which is DNS - which is why I don't get it - I have a name caching DNS server [it shouldn't broadcast, should it??] - if anyone is a DNS guru, maybe I could post my named.conf and see if I am?