[Snort-users] DNS zone transfer

Semerjian, Ohanes Semerjian.Ohanes at ...4899...
Mon Sep 16 19:36:02 EDT 2002


A question about the DNS zone transfer signature. I'm seeing a couple of
these signature from internal NT workstaion to our Unix DNS server. Now the
signature get triggered if the content of payload match certain pattern. My
question is what is the possibilities of false positive and could a
legitimate traffic trigger this signature...!or this is a real attempt..!

Best Regards
Ohanes Semerjian

PGP kEY 
6604 2A46 E64F BEBF A4B7  9D01 9E08 399C 9D45 3254




More information about the Snort-users mailing list