[Snort-users] DNS zone transfer

Semerjian, Ohanes Semerjian.Ohanes at ...4899...
Mon Sep 16 22:45:03 EDT 2002

Thanks for the reply,but what I'd like to know if the signature could be
triggered as a false positive and if that's possible or not dur other
legitimate traffic...!

Best Regards

Ohanes Semerjian
6604 2A46 E64F BEBF A4B7  9D01 9E08 399C 9D45 3254

-----Original Message-----
From: james [mailto:hackerwacker at ...3784...]
Sent: Tuesday, 17 September 2002 15:37
To: Semerjian, Ohanes
Cc: snort-users at lists.sourceforge.net
Subject: Re: [Snort-users] DNS zone transfer

I use this rule to keep an eye on my secondary name service. The rule and
the daemon log one the primary and secondaries report the same thing, a true
tranfer attempt did happen. So far, no false positives.


More information about the Snort-users mailing list