Why does DNS.EXE listen on a ephemeral TCP port?



I noticed my x64 Windows 2003 R2 machines running DNS were listening on
wierd TCP ports. DNS.EXE is the listening process. Restarting DNS changes
the port number. I know DNS uses ephemeral UDP ports, but I can't find
anything that describes the use of TCP in this manner. None of the
Microsoft firewall guides I've seen make allowances for this port to be
used, nor does anything in the security configuration wizard indicate that
inbound TCP connections should be allowed to anything other than 53.

Does anyone know what it's for and how it's used?

Brian

Brian Doré
Office of Information Systems
University of Louisiana at Lafayette




.



Relevant Pages

  • RE: IM Programs
    ... want to block these ports. ... you don't need an explicit deny for the other ports. ... Access-list 101 deny any tcp any any eq 5000 ... >Now, when applying these to your firewall, make sure the number ...
    (Security-Basics)
  • Re: What should I block out with my new firewall software?
    ... >> block out that I don't use or need, like UDP or TCP. ... >> activity or attempts from outside hackers to penetrate these ports. ... never stop svchost from comunnicating on the Internet. ... > Web updates, as far as I know, are downloaded the same way that ...
    (comp.security.firewalls)
  • Re: Fingerprinting Windows O/S based on ports open?
    ... finger printing by open default ports is not always ... OS fingerprinting is not as plain and claer cut as it was perhaps a few ... settings in tcp packets. ... >> Looking for a better way to manage your IP security? ...
    (Pen-Test)
  • Re: NFS inconsistent behaviour
    ... of tcp connections in TIME_WAIT state. ... Why there are so many connections in waiting state? ... and remote port so the ports stay in use for a few minutes. ... I ran out of privileged ports due to treemounting on /net from about 50 ...
    (Linux-Kernel)
  • Re: Is there any legit reason for TCP scans?
    ... The TCP scan examines the 1,024 ports that are mainly reserved for TCP ... routers and proxies for users connecting to the Web site through such ... > anti-virus nor Stinger reports the presence of anything malicious. ...
    (comp.security.firewalls)