2 Feb
2001
2 Feb
'01
8:40 a.m.
On Fri, 2 Feb 2001, Rich Sena wrote:
On Feb 1, 2001 Wayne Bouchard reported:
53, 111, and 137 are the most common scans I trap at my firewall. Interesting bit with the scans to port 53 lately is that they're hitting the port 2 and 3 times, not just the usual once to identify and then move on.
I betcha a guiness and a smile at N21 that those are Global Load Balancers probing for distance metrics to your DNS servers on 53 and not malicious scans...
I can see it now. Someone at Akamai cackling as they instruct all boxes to nmap every NS entry in the .com zone... :) J