One report that we run daily lists all attempts across our perimeter security for DNS Zone Transfer and All Records requests. I cannot remember a time where we did not see IPs that scan our entire /22 for one of these types. However, over the past 3 days, I have not seen these scans. A review of port 53 (https://isc.sans.edu/port.html?port=53) in the ISC database is showing a drop in sources but not targets. I realize that my view of Internet traffic is limited, but was wondering if anyone else was seeing this - or if it is even significant? |
Thomas 3 Posts |
thread locked Quote Subscribe |
Feb 24th 2014 8 years ago |
So, I guess I spoke too soon. Our little gremlins are back. I'll own that up to some sort of cycle in the 'scanners'. Still, three days of no activity seemed a little odd... |
Anonymous - |
Thread locked. Quote |
Feb 25th 2014 8 years ago |
Sign Up for Free or Log In to start participating in the conversation!