I was getting a constant ping on my system so I opened EtherApe and took a look. I found what was causing the repetitive "TIME_WAIT" acks every 5 seconds, checkip.dyndns.com. It turns out that the Plasmoid which shows your IP on your desktop uses that service and it results in a regular tick on your Network Traffic graph. While using EtherApe I noticed another visitor who was rather persistently knocking on my ports. I did an "whois" on the IP address and here is what it returned:
I also saw the same IP but ending in 187 as well. They may be domain name servers.
I found they were related to this website: http://micasa.com/ I wonder what their relation to Microsoft is?
Regardless, what is a dns doing probing my ports?
jerry@sonyvgnfw140e:~$ whois 207.68.188.186
OrgName: Microsoft Corp
OrgID: MSFT
Address: One Microsoft Way
City: Redmond
StateProv: WA
PostalCode: 98052
Country: US
NetRange: 207.68.128.0 - 207.68.207.255
CIDR: 207.68.128.0/18, 207.68.192.0/20
NetName: MICROSOFT-CORP-MSN-BLK
NetHandle: NET-207-68-128-0-1
Parent: NET-207-0-0-0-0
NetType: Direct Allocation
NameServer: NS1.MSFT.NET
NameServer: NS5.MSFT.NET
NameServer: NS2.MSFT.NET
NameServer: NS3.MSFT.NET
NameServer: NS4.MSFT.NET
Comment:
RegDate: 1996-03-26
Updated: 2005-06-29
RTechHandle: ZM39-ARIN
RTechName: Microsoft
RTechPhone: +1-425-882-8080
RTechEmail: noc@microsoft.com
OrgAbuseHandle: ABUSE231-ARIN
OrgAbuseName: Abuse
OrgAbusePhone: +1-425-882-8080
OrgAbuseEmail: abuse@hotmail.com
OrgName: Microsoft Corp
OrgID: MSFT
Address: One Microsoft Way
City: Redmond
StateProv: WA
PostalCode: 98052
Country: US
NetRange: 207.68.128.0 - 207.68.207.255
CIDR: 207.68.128.0/18, 207.68.192.0/20
NetName: MICROSOFT-CORP-MSN-BLK
NetHandle: NET-207-68-128-0-1
Parent: NET-207-0-0-0-0
NetType: Direct Allocation
NameServer: NS1.MSFT.NET
NameServer: NS5.MSFT.NET
NameServer: NS2.MSFT.NET
NameServer: NS3.MSFT.NET
NameServer: NS4.MSFT.NET
Comment:
RegDate: 1996-03-26
Updated: 2005-06-29
RTechHandle: ZM39-ARIN
RTechName: Microsoft
RTechPhone: +1-425-882-8080
RTechEmail: noc@microsoft.com
OrgAbuseHandle: ABUSE231-ARIN
OrgAbuseName: Abuse
OrgAbusePhone: +1-425-882-8080
OrgAbuseEmail: abuse@hotmail.com
I found they were related to this website: http://micasa.com/ I wonder what their relation to Microsoft is?
Regardless, what is a dns doing probing my ports?
Comment