G
Guest
Does LSASS.EXE have a legitimate reason to communicate on
port 53 (DNS)? Outside of my network?!
I am auditing port 53 on my domain controller and was
surprised to see outbound traffic from LSASS.EXE. The
destinations include all of the DNS servers specified in
the server's TCP/IP settings. [One of those is the
server's own IP. The other two are fail-over DNS servers
located outside of our network.] What is LSASS.EXE looking
for? And why is it using port 53? [I mean, it isn't
actually performing DNS lookups, is it?]
Any advice is greatly appreciated.
port 53 (DNS)? Outside of my network?!
I am auditing port 53 on my domain controller and was
surprised to see outbound traffic from LSASS.EXE. The
destinations include all of the DNS servers specified in
the server's TCP/IP settings. [One of those is the
server's own IP. The other two are fail-over DNS servers
located outside of our network.] What is LSASS.EXE looking
for? And why is it using port 53? [I mean, it isn't
actually performing DNS lookups, is it?]
Any advice is greatly appreciated.