Nmap Security Scanner
*Intro
*Ref Guide
*Install Guide
*Download
*Changelog
*Book
*Docs
Security Lists
*Nmap Hackers
*Nmap Dev
*Bugtraq
*Full Disclosure
*Pen Test
*Basics
*More
Security Tools
*Pass crackers
*Sniffers
*Vuln Scanners
*Web scanners
*Wireless
*Exploitation
*Packet crafters
*More
Site News
Site Search:
Exploit World
Advertising
About/Contact
Credits
Sponsors:
edgeos



Security Incidents: Re: VPN connection attempts to resolvers?

Re: VPN connection attempts to resolvers?

From: <Valdis.Kletnieks_at_vt.edu>
Date: Thu, 04 Apr 2002 10:53:05 -0500

On Wed, 03 Apr 2002 15:41:23 MST, Mike Lewinski <mike_at_rockynet.com> said:

> Since I am not a VPN expert, I'm wondering if anyone else can shed some
> light on what might be going on here. Is this just a brain-dead VPN client
> that's making bad assumptions about it's resolvers? Or is there something
> more malicious going on? The traffic was picked up after a SYN flood to one
> of the DNS servers led to further investigation.

Been there, done that. Quite possibly a Windows box that has the little
box checked for "Try to negotiate IPSec connection always" (am not a
WIndows person, not sure exactly what it's labeled).

-- 
				Valdis Kletnieks
				Computer Systems Senior Engineer
				Virginia Tech

  • application/pgp-signature attachment: stored
Received on Apr 04 2002
[ Nmap | Sec Tools | Mailing Lists | Site News | About/Contact | Advertising | Privacy ]
edgeos