[Snort-users] PROTOCOL-DNS Malformed DNS query with HTTP content. What's the angle?

Eric G eric at ...15503...
Wed Apr 23 10:47:58 EDT 2014


On Apr 23, 2014 10:04 AM, "Moore, Jim" <jmoore at ...16816...> wrote:
>
> Last night we had a whole series of these probes.  The packets were
> addressed to UDP port 53 but contained nothing but HTTP headers

Haha Jim and I apparently think alike... I posted the same question around
20 minutes before his

I'm seeing the same odd traffic that has sprung up recently

--
Eric
http://www.linkedin.com/in/ericgearhart
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <https://lists.snort.org/pipermail/snort-users/attachments/20140423/7c8964d8/attachment.html>


More information about the Snort-users mailing list