[ Date Index ] [ Thread Index ] [ <= Previous by date / thread ] [ Next by date / thread => ]
TCPDUMP show the content contain strings consistent with these packets being related to anti-spam activity, or possibly just lost DNS traffic (since a lot of DNS traffic is now anti-spam).
Strings extracted include: 14.114.99.123.zen.spamhaus.org 157.104.20.190.zen.spamhaus.org cps.co.uk.dsn.rfc-ignorant.org liposuctionlaser.com.abuse.rfc-ignorant.orgMy best guess is an attempted DDOS on blocklists, but I don't have enough data.
I don't understand why it would use port 37, but the packets are from all over, so I assume spoofed.
Anyone else seeing this? Be nice to know we aren't mangling our own DNS requests or similar.
-- The Mailing List for the Devon & Cornwall LUG http://mailman.dclug.org.uk/listinfo/list FAQ: http://www.dcglug.org.uk/linux_adm/list-faq.html