Google Groups no longer supports new Usenet posts or subscriptions. Historical content remains viewable.
Dismiss

Connections from 158.152.1.48/158.152.1.53

3 views
Skip to first unread message

Richard Tibbetts

unread,
Jul 16, 2002, 4:30:01 PM7/16/02
to
Should I be worried? My firewall has suddenly started logging *lots*
of attempted connections from the Demon DNS servers from port 53,
trying to connect to a variety of 4nnn ports. This seems to be a new
thing.
--
Richard Tibbetts
http://www.primepeace.ltd.uk/

Richard Clayton

unread,
Jul 16, 2002, 6:03:44 PM7/16/02
to
In article <l409jucpmg7vfflb8...@4ax.com>, Richard
Tibbetts <ric...@primepeace.ltd.uk> writes

>Should I be worried?

yes, your firewall is either useless or you've configured it wrongly

>My firewall has suddenly started logging *lots*
>of attempted connections from the Demon DNS servers from port 53,
>trying to connect to a variety of 4nnn ports.

I expect it is returning the details of names you have looked up

>This seems to be a new
>thing.

then it will be something you changed recently

--
richard Richard Clayton

They that can give up essential liberty to obtain a little temporary
safety deserve neither liberty nor safety. Benjamin Franklin

Richard Tibbetts

unread,
Jul 17, 2002, 3:47:09 AM7/17/02
to
In message <0vGOdmCA...@highwayman.com>, Richard Clayton

<ric...@highwayman.com> wrote on Tue, 16 Jul 2002 23:03:44 +0100:

> In article <l409jucpmg7vfflb8...@4ax.com>, Richard
> Tibbetts <ric...@primepeace.ltd.uk> writes
>
> >Should I be worried?
>
> yes, your firewall is either useless or you've configured it wrongly

Though the latter is more than possible, the former seems to be the
case this time. It appears there was a memory leak on the machine,
which had been running for 17 days, and the proxy software/firewall
had run out of memory.

> >My firewall has suddenly started logging *lots*
> >of attempted connections from the Demon DNS servers from port 53,
> >trying to connect to a variety of 4nnn ports.

Why on port 4nnn??

> I expect it is returning the details of names you have looked up
>
> >This seems to be a new
> >thing.
>
> then it will be something you changed recently

--
Richard Tibbetts
http://www.primepeace.ltd.uk/

Richard Clayton

unread,
Jul 17, 2002, 5:15:21 AM7/17/02
to
In article <h08ajus7tpb6fod14...@4ax.com>, Richard
Tibbetts <ric...@primepeace.ltd.uk> writes

>> >My firewall has suddenly started logging *lots*


>> >of attempted connections from the Demon DNS servers from port 53,
>> >trying to connect to a variety of 4nnn ports.
>
>Why on port 4nnn??

Some port number or other has to be used at your end, and to allow
multiple conversations to occur at once a "random" port number will be
used (clearly on this occasion selected from 4xxx values)

The firewall was not recording the outgoing packet (apparently because
of the memory leak), so the returning packet came as a surprise - so it
objected to it.

BTW I doubt it was "trying to connect" since these would have been UDP
packets with nary a TCP SYN in sight.

0 new messages