Posted: Mon Sep 01, 2008 12:45 am Post subject: name server question (ubuntu)
I am not very good at security, so I just noticed this "problem" today, a couple of months after moving to a new house.
I am using a new ISP at the new place, but I had hard-coded the old name servers into dhclient.conf (and resolv.conf), so I've been bypassing the router and using the "wrong" name servers.
Today I set my firewall to whitelist mode (don't allow all outbound connections) and the blocked events just started to fly by, like four per second, on every different port you could think of, to IPs all around the world.
But after I changed dhclient to get the name server from the router, there are very few outbound connections.
I guess I am happy with the situation now. But I am just curious about what all of that traffic was before. Can someone explain why my computer was sending so many outbound connections?
You cannot post new topics in this forum You cannot reply to topics in this forum You cannot edit your posts in this forum You cannot delete your posts in this forum You cannot vote in polls in this forum