[NTLUG:Discuss] what is going on?
Richard Cobbe
cobbe at directlink.net
Thu May 24 17:10:25 CDT 2001
Lo, on Thursday, May 24, Michael Patrick did write:
> My guess (based on recalling that PROTO 6 is tcp) is that someone trying
> dns zone transfers. You might want to run something like tcpdump or snort
> to capture some of the actual traffic to be sure.
See /etc/protocols for protocol number definitions.
I agree, a packet sniffer will help you analyze the traffic better,
although you'll of course need to know something about DNS.
Richard
More information about the Discuss
mailing list