Security Incidents mailing list archives

Re: Win2k Machine contacting Root Server???


From: Jeff Rosowski <rosowskij () ie ymp gov>
Date: Tue, 28 Mar 2006 16:26:00 -0800 (PST)

I recently ran "netstat" on my personal laptop (running Win2k) and was shocked to see that it had been making TCP connections to the root servers (to their domain port). I know that some DNS queries are performed using TCP, but I find it somewhat disturbing that the root servers were involved.

I did a little googling and found a few remarks that Win2k machines sometimes do this... But mine has the lastest updates....

We've seen it when they couldn't reverse lookup their address.


Current thread: