[Snort-users] DNS zone transfer

Semerjian, Ohanes Semerjian.Ohanes at ...4899...
Wed Sep 18 17:09:08 EDT 2002

Thanks very much for reply, that's what I thought but I wanted to hear it
from someone else to confirm my suspicions.

Best Regards

Ohanes Semerjian

6604 2A46 E64F BEBF A4B7  9D01 9E08 399C 9D45 3254

-----Original Message-----
From: Scott Nursten [mailto:scottn at ...4526...]
Sent: Tuesday, 17 September 2002 20:12
To: Semerjian, Ohanes; 'james'
Cc: snort-users at lists.sourceforge.net
Subject: Re: [Snort-users] DNS zone transfer


As per the signature

dns.rules:alert tcp $EXTERNAL_NET any -> $HOME_NET 53 (msg:"DNS zone
transfer"; flags:A+; content: "|00 00 FC|"; offset:13;
reference:cve,CAN-1999-0532; reference:arachnids,212;
classtype:attempted-recon; sid:255;  rev:6;)

It has to be destined for port 53 and contain the content |00 00 FC| (axfr I
believe), as well as A+ (be an ACK+)  so it would be pretty hard to gen a
false positive but not impossible.

Kind Regards, 

Scott Nursten
S2S Consultants
T: 01444 232 742
F: 01444 232 061
W: http://s2s.ltd.uk
E: scottn at ...4526...

More information about the Snort-users mailing list