[Snort-users] Anyone else seen a massive upsurge in named version scanning?

Mark Vevers mark at ...5096...
Mon Mar 18 09:12:03 EST 2002

Over the last 3 - 4 days I've seen a massive upsurge in dns named-version
scanning going on - has anyone else noticed this?  This is based on scanning
about half of a /13 worth of address space, so YMMV, but I'm seeing
thousands of alerts per day, sweeping across the address space and am just
wondering if a new DNS exploit is in the offing?


