[NTLUG:Discuss] what is going on?

Richard Cobbe cobbe at directlink.net
Thu May 24 17:10:25 CDT 2001


Lo, on Thursday, May 24, Michael Patrick did write:

> My guess (based on recalling that PROTO 6 is tcp) is that someone trying 
> dns zone transfers.  You might want to run something like tcpdump or snort 
> to capture some of the actual traffic to be sure.

See /etc/protocols for protocol number definitions.

I agree, a packet sniffer will help you analyze the traffic better,
although you'll of course need to know something about DNS.

Richard



More information about the Discuss mailing list