Pantek Library
Hosting Provided By
CybrHost
High Speed Hosting

Re: DNS packet analysis.

From: Mark Cooper <mark(at)mhc-online.co.uk>
Date: Wed Dec 11 2002 - 16:47:27 EST

Hi V.Jay,

There is nothing malicious happening here.

Each DNS response comes in two legitimate-looking fragments, for a total of 1480+575=2055 bytes. By "legitimate looking", I mean that the first fragment is always at offset 0 and of 1480bytes, and the second starts at offset 1480. Nothing untowards here.

It shows that the MTU of at least part of the path between DNS.server.com and outside.guy.com is 1480 bytes. I understand that this is the default MTU for Win/XP using PPPoE.

Hope this helps.

Regards,

Mark

---
Mark Cooper
SANS GCIA


----- Original Message -----
From: "larosa, vjay" 
To: 
Sent: Wednesday, December 11, 2002 8:37 PM
Subject: DNS packet analysis.

> Hello,
familiar
> with snort
Received on Wed Dec 11 18:04:49 2002
Do you need help?X

This archive was generated by hypermail 2.1.8 : Wed Aug 23 2006 - 14:01:04 EDT


Contact Us  Legal Notices  Order Services Online 
Pantek Home  Privacy Policy  IT news  Site Map  Pantek Library