[Snort-sigs] Sig thought (wpad)
Jason_Haar at ...3686...
Sun Feb 16 18:31:54 EST 2014
If domain-based windows computers are set to use wpad, they will do
wpad.their.AD.domain as part of their prancing through the dns-daisies,
along with the more expected "wpad.current.domain". Why? Ask Microsoft
(guess: if they do the "their.AD.domain" lookup first, it would
potentially make wpad slightly more secure [because an organization
could gain control of wpad offsite] - so it could be a security measure?)
Information Security Manager, Trimble Navigation Ltd.
Phone: +1 408 481 8171
PGP Fingerprint: 7A2E 0407 C9A6 CAF6 2B9F 8422 C063 5EBB FE1D 66D1
More information about the Snort-sigs