Snort mailing list archives

RE: DNS zone transfer


From: "Semerjian, Ohanes" <Semerjian.Ohanes () wcom com au>
Date: Tue, 17 Sep 2002 13:44:13 +0800

Thanks for the reply,but what I'd like to know if the signature could be
triggered as a false positive and if that's possible or not dur other
legitimate traffic...!

Best Regards

Ohanes Semerjian
PGP kEY 
6604 2A46 E64F BEBF A4B7  9D01 9E08 399C 9D45 3254


-----Original Message-----
From: james [mailto:hackerwacker () cybermesa com]
Sent: Tuesday, 17 September 2002 15:37
To: Semerjian, Ohanes
Cc: snort-users () lists sourceforge net
Subject: Re: [Snort-users] DNS zone transfer


I use this rule to keep an eye on my secondary name service. The rule and
the daemon log one the primary and secondaries report the same thing, a true
tranfer attempt did happen. So far, no false positives.

j


-------------------------------------------------------
Sponsored by: AMD - Your access to the experts on Hammer Technology! 
Open Source & Linux Developers, register now for the AMD Developer 
Symposium. Code: EX8664 http://www.developwithamd.com/developerlab
_______________________________________________
Snort-users mailing list
Snort-users () lists sourceforge net
Go to this URL to change user options or unsubscribe:
https://lists.sourceforge.net/lists/listinfo/snort-users
Snort-users list archive:
http://www.geocrawler.com/redir-sf.php3?list=snort-users


Current thread: