RE: All port scan attack from our DNS forwards

  • From: "Greg Hess" <gmh@xxxxxxxx>
  • To: <isalist@xxxxxxxxxxxxx>
  • Date: Fri, 01 Mar 2002 07:44:43 -0500

We used to get those from our old ISP all the time. I called them repeatedly 
and was told I was crazy. Since we switched ISP's it's never happened again. My 
geuss was that they were scanning segments for services.

Greg.

-----Original Message-----
From: nathansimpson@xxxxxxxxxxxxxxx 
Sent: Thursday, February 28, 2002 6:52 PM
To: isalist@xxxxxxxxxxxxx; nathansimpson@xxxxxxxxxxxxxxx
Subject: [isalist] All port scan attack from our DNS forwards


http://www.ISAserver.org


Hi,

I just received an all port scan attack from the 2 forwarders which are entered 
on our internal DNS server.

The forwarders are the DNS servers from a local ISP.

Why would they be scanning us?

Should we be suspicious?

TIA

Nathan Simpson


------------------------------------------------------
You are currently subscribed to this ISAserver.org Discussion List as: 
gmh@xxxxxxxx To unsubscribe send a blank email to 
leave-isalist-244273Q@xxxxxxxxxxxxx




Other related posts: