[Snort-users] DNS zone transfer

Semerjian, Ohanes Semerjian.Ohanes at ...4899...
Mon Sep 16 22:45:03 EDT 2002


Thanks for the reply,but what I'd like to know if the signature could be
triggered as a false positive and if that's possible or not dur other
legitimate traffic...!

Best Regards

Ohanes Semerjian
PGP kEY 
6604 2A46 E64F BEBF A4B7  9D01 9E08 399C 9D45 3254


-----Original Message-----
From: james [mailto:hackerwacker at ...3784...]
Sent: Tuesday, 17 September 2002 15:37
To: Semerjian, Ohanes
Cc: snort-users at lists.sourceforge.net
Subject: Re: [Snort-users] DNS zone transfer


I use this rule to keep an eye on my secondary name service. The rule and
the daemon log one the primary and secondaries report the same thing, a true
tranfer attempt did happen. So far, no false positives.

j




More information about the Snort-users mailing list