2 Feb
2001
2 Feb
'01
8:25 a.m.
On Feb 1, 2001 Wayne Bouchard reported:
53, 111, and 137 are the most common scans I trap at my firewall. Interesting bit with the scans to port 53 lately is that they're hitting the port 2 and 3 times, not just the usual once to identify and then move on.
I betcha a guiness and a smile at N21 that those are Global Load Balancers probing for distance metrics to your DNS servers on 53 and not malicious scans... -- Rich Sena - ras@thick.net ThickNET Consulting "On the way to understanding; you understand, and forget."