Click to See Complete Forum and Search --> : Weird packets in tcpdump?


Etherphyte
01-08-2001, 02:31 AM
Hey gang, been a while. Anyway, while fooling around w/ tcpdump, I see a lot of packets that look like this:
etherphyte.com.1025 > ns1.smcvt.edu.domain:
and
arp who-has etherphyte.com tell ns2.smcvt.edu
and
ns2.smcvt.edu.domain> etherphyte.com.1025
Anyway, etherphyte.com is my box, and ns1 and 2.smcvt.edu are the DNS servers at my college. Why is my box communicating with those servers? They don't do my DNS. I would like to stop this traffic. Any ideas on what those communique's are for, or how to stop them?
Thanks,
Adam

sssadams
01-08-2001, 09:17 PM
It looks like you have set up a second level domain inside your schools domain and the name server is just trying to figure out who you are.Im no guru on this so if its somthing
else I wish someone will correct this assumption.

mrpotatoe
01-09-2001, 05:46 AM
you could put them in your host.deny file under /etc that would stop it, the arp request you cant really get rid of, thats just normal router traffic, unless you set up a firewall and specifically block those host, otherwise you should be fine with the host.deny