2k server generating some weird traffic

FiberOptik

Member
Aug 2, 2001
171
0
0
Hey all, I'm a student at a University and they are giving a software package to all students. This package contains an upgrade version of 2k server so I installed it and started messing around with it. I noticed that it's been generating lots of traffic to the following IPs: 192.5.6.30 and 192.175.48.1. I'm sure it's generating this traffic for a reason, does anyone know why? The above two IPs resolve to the following addresses.

192.5.6.30 = a.gtld-servers.net
192.175.48.1 = prisoner.iana.org
 

FiberOptik

Member
Aug 2, 2001
171
0
0
No, I'm pretty sure I'm not hacked, I am behind a decent linux firewall. I think the above has something to do with win2k DNS as all the traffic generated on the above IPs is on port 53 (DNS). Is there a setting that I can enable within win2k DNS that will disable this traffic?
 

bsobel

Moderator Emeritus<br>Elite Member
Dec 9, 2001
13,346
0
0
Looks like you installed the dns server and have it set to do lookups against the root servers. Disable the DNS server or configure it to use forwarders to your local DNS if you want to kill this traffic.
Bill
 

stash

Diamond Member
Jun 22, 2000
5,468
0
0
The second IP is the address for prisoner.iana.org. This is the primary DNS server that holds the zones for the three unroutable IP ranges (10.in-addr.arpa, 16.172.in-addr.arpa, and 168.192.in-addr.arpa).

So if your machine has an address in one of these ranges, it will try to register a PTR record with a DNS server. If you don't have a local DNS server with one of those zones, it will try to register with prisoner.iana.org, which will reject it.

This isnt anything to worry about.

Also, I believe the first IP is a DNS root server.
 
sale-70-410-exam    | Exam-200-125-pdf    | we-sale-70-410-exam    | hot-sale-70-410-exam    | Latest-exam-700-603-Dumps    | Dumps-98-363-exams-date    | Certs-200-125-date    | Dumps-300-075-exams-date    | hot-sale-book-C8010-726-book    | Hot-Sale-200-310-Exam    | Exam-Description-200-310-dumps?    | hot-sale-book-200-125-book    | Latest-Updated-300-209-Exam    | Dumps-210-260-exams-date    | Download-200-125-Exam-PDF    | Exam-Description-300-101-dumps    | Certs-300-101-date    | Hot-Sale-300-075-Exam    | Latest-exam-200-125-Dumps    | Exam-Description-200-125-dumps    | Latest-Updated-300-075-Exam    | hot-sale-book-210-260-book    | Dumps-200-901-exams-date    | Certs-200-901-date    | Latest-exam-1Z0-062-Dumps    | Hot-Sale-1Z0-062-Exam    | Certs-CSSLP-date    | 100%-Pass-70-383-Exams    | Latest-JN0-360-real-exam-questions    | 100%-Pass-4A0-100-Real-Exam-Questions    | Dumps-300-135-exams-date    | Passed-200-105-Tech-Exams    | Latest-Updated-200-310-Exam    | Download-300-070-Exam-PDF    | Hot-Sale-JN0-360-Exam    | 100%-Pass-JN0-360-Exams    | 100%-Pass-JN0-360-Real-Exam-Questions    | Dumps-JN0-360-exams-date    | Exam-Description-1Z0-876-dumps    | Latest-exam-1Z0-876-Dumps    | Dumps-HPE0-Y53-exams-date    | 2017-Latest-HPE0-Y53-Exam    | 100%-Pass-HPE0-Y53-Real-Exam-Questions    | Pass-4A0-100-Exam    | Latest-4A0-100-Questions    | Dumps-98-365-exams-date    | 2017-Latest-98-365-Exam    | 100%-Pass-VCS-254-Exams    | 2017-Latest-VCS-273-Exam    | Dumps-200-355-exams-date    | 2017-Latest-300-320-Exam    | Pass-300-101-Exam    | 100%-Pass-300-115-Exams    |
http://www.portvapes.co.uk/    | http://www.portvapes.co.uk/    |