Security Incidents mailing list archives

DNS update queries: another sort of suspicious activity.


From: fygrave () TIGERTEAM NET (Fyodor)
Date: Fri, 28 Jan 2000 16:12:38 +0300


Greetings,
 Today noticed quite interesting logs from my named:

Jan 28 05:56:54 ns named[14783]: unapproved update from [192.168.0.4].126 for  myzone.com
Jan 28 05:57:09 ns last message repeated 2 times
...

Looks like someone tried to spoof DNS update queries to `update' zonefiles
of my nameserver. I will try to dissect DNS update query tonight to see if I
could write decent snort rules to detect this sort of attack.

-F


Current thread: