I have started getting messages from my router with the following... 2007-12-13 15:47:04 - SYN with Data - Source:202.108.12.147,4901,WAN - Destination:xxx.xxx.xxx.42,53,LAN The 4th number in the address is changing from 12, 62, 146 and 147 and the ports are changing as well. They were coming in last night once every hour or so and lately every few minutes. Does this mean that someone is trying to hack my DNS?
Seems like that IP address is using your server for DNS. On the other side, it's an IP from China, so that sure looks suspicious: http://whois.domaintools.com/202.108.12.147