|
Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com |
RE: Why alerts on ports 1025-1029, 1036
From: Stuart Wallace (Stuart
nildram.net)
Date: Tue Apr 01 2003 - 02:14:12 CST
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ]
Thats usually responses coming back from a nameserver, replying to original
source port of the query.
e.g. your resolver sends a query to the nameserver on port 53 but with an
arbitrary source port (normally from 1024 upward...), the nameserver
responds to the source port your resolver chose....
Regards
Stuart Wallace
stuart
nildram.net
> -----Original Message-----
> From: Tomas Carlsson [mailto:xtc
skildra.nu]
> Sent: 31 March 2003 23:04
> To: incidents
securityfocus.com
> Subject: Why alerts on ports 1025-1029, 1036
>
>
> I get constant alerts from Zonealarm and it is always blocking on
> ports 1025, 1026, 1027 or 1029.
> Can someone tell me why?
>
> Sometimes also alerts from blocking on port 1036. What's there?
>
> TIA
> Tomas
>
>
>
> --------------------------------------------------------------
> --------------
> Powerful Anti-Spam Management and More...
> SurfControl E-mail Filter puts the brakes on spam,
> viruses and malicious code. Safeguard your business
> critical communications. Download a free 30-day trial:
> http://www.securityfocus.com/SurfControl-incidents
>
>
>
----------------------------------------------------------------------------
Powerful Anti-Spam Management and More...
SurfControl E-mail Filter puts the brakes on spam,
viruses and malicious code. Safeguard your business
critical communications. Download a free 30-day trial:
http://www.securityfocus.com/SurfControl-incidents
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ]