Snort mailing list archives
DNS zone transfer
From: "Semerjian, Ohanes" <Semerjian.Ohanes () wcom com au>
Date: Tue, 17 Sep 2002 10:34:50 +0800
A question about the DNS zone transfer signature. I'm seeing a couple of these signature from internal NT workstaion to our Unix DNS server. Now the signature get triggered if the content of payload match certain pattern. My question is what is the possibilities of false positive and could a legitimate traffic trigger this signature...!or this is a real attempt..! Best Regards Ohanes Semerjian PGP kEY 6604 2A46 E64F BEBF A4B7 9D01 9E08 399C 9D45 3254 ------------------------------------------------------- Sponsored by: AMD - Your access to the experts on Hammer Technology! Open Source & Linux Developers, register now for the AMD Developer Symposium. Code: EX8664 http://www.developwithamd.com/developerlab _______________________________________________ Snort-users mailing list Snort-users () lists sourceforge net Go to this URL to change user options or unsubscribe: https://lists.sourceforge.net/lists/listinfo/snort-users Snort-users list archive: http://www.geocrawler.com/redir-sf.php3?list=snort-users
Current thread:
- DNS zone transfer Semerjian, Ohanes (Sep 16)
- Re: DNS zone transfer james (Sep 16)
- <Possible follow-ups>
- RE: DNS zone transfer Semerjian, Ohanes (Sep 16)
- Re: DNS zone transfer Scott Nursten (Sep 17)
- RE: DNS zone transfer Semerjian, Ohanes (Sep 18)