Re: DNS Logs.

"Vitalii Serhiiovych Horbatov -X \(vhorbato - SOFTSERVE INC at Cisco\) via Snort-users" <[email protected]> Tue, 7 Jan 2025 14:48:20 +0000
Newsgroups gmane.comp.security.ids.snort.general
Message-ID <MW4PR11MB8290483830E8514B0CC0604BDB112@MW4PR11MB8290.namprd11.prod.outlook.com>
--===============6179743928127115471==
Content-Language: en-GB
Content-Type: multipart/alternative;
	boundary="_000_MW4PR11MB8290483830E8514B0CC0604BDB112MW4PR11MB8290namp_"

--_000_MW4PR11MB8290483830E8514B0CC0604BDB112MW4PR11MB8290namp_
Content-Type: text/plain; charset="us-ascii"
Content-Transfer-Encoding: quoted-printable

Hi Wojciech!

Can you please provide the initial version that you used (the one without a=
ny alerts)?

I don't see any changes in that rule during that timeframe, so it could be =
triggered by either changes in Snort 3 or changes in your network traffic.

The rule aims to detect https://nvd.nist.gov/vuln/detail/cve-2020-1350 whic=
h is of a CRITICAL score, so it can be something to be worried about.
I suggest you to check rule description(https://snort.org/rule_docs/1-54577=
) and CVE description, and analyze some traffic captures, to understand if =
alerts are valid or false positives.

Thanks,
Vitalii!

From: Snort-users <[email protected]> on behalf of Variou=
s emails via Snort-users <[email protected]>
Date: Thursday, 19 December 2024 at 19:44
To: [email protected] <[email protected]>
Subject: [Snort-users] DNS Logs.
Hello Snort Community,

I have a question about alerts, that started to appear in logs since
late November, I think after I installed the latest version on Snort 3
but not sure. Every device on my network  is slowly scanned. Is this
something to be worried about?

I use subscription rules.

12/18-14:21:39.031143 [**] [1:54577:4] "SERVER-OTHER Microsoft Windows
DNS server remote integer overflow attempt" [**] [Classification:
Attempted User Privilege Gain] [Priority: 1] [AppID: DNS] {UDP}
1.1.1.1:53 -> 192.168.10.212:52696
12/18-20:36:32.853211 [**] [1:54577:4] "SERVER-OTHER Microsoft Windows
DNS server remote integer overflow attempt" [**] [Classification:
Attempted User Privilege Gain] [Priority: 1] [AppID: DNS] {UDP}
8.8.8.8:53 -> 192.168.10.7:59170
12/18-23:08:15.699170 [**] [1:54577:4] "SERVER-OTHER Microsoft Windows
DNS server remote integer overflow attempt" [**] [Classification:
Attempted User Privilege Gain] [Priority: 1] [AppID: DNS] {UDP}
1.1.1.1:53 -> 192.168.17.9:55277
12/19-06:15:56.963296 [**] [1:54577:4] "SERVER-OTHER Microsoft Windows
DNS server remote integer overflow attempt" [**] [Classification:
Attempted User Privilege Gain] [Priority: 1] [AppID: DNS] {UDP}
1.1.1.1:53 -> 192.168.17.9:36419

w@w:/var/log/snort$ snort -V

    ,,_     -*> Snort++ <*-
   o"  )~   Version 3.5.2.0
    ''''    By Martin Roesch & The Snort Team
            http://snort.org/contact#team
            Copyright (C) 2014-2024 Cisco and/or its affiliates. All
rights reserved.
            Copyright (C) 1998-2013 Sourcefire, Inc., et al.
            Using DAQ version 3.0.17
            Using libpcap version 1.10.4 (with TPACKET_V3)
            Using LuaJIT version 2.1.1703358377
            Using LZMA version 5.4.5
            Using OpenSSL 3.0.13 30 Jan 2024
            Using PCRE version 8.45 2021-06-15
            Using ZLIB version 1.3


Thank you,

Wojciech



_______________________________________________
Snort-users mailing list
[email protected]
Go to this URL to change user options or unsubscribe:
https://lists.snort.org/mailman/listinfo/snort-users

        To unsubscribe, send an email to:
        [email protected]

Please visit http://blog.snort.org to stay current on all the latest Snort =
news!

Please follow these rules: https://snort.org/faq/what-is-the-mailing-list-e=
tiquette

--_000_MW4PR11MB8290483830E8514B0CC0604BDB112MW4PR11MB8290namp_
Content-Type: text/html; charset="us-ascii"
Content-Transfer-Encoding: quoted-printable

<html xmlns:o=3D"urn:schemas-microsoft-com:office:office" xmlns:w=3D"urn:sc=
hemas-microsoft-com:office:word" xmlns:m=3D"http://schemas.microsoft.com/of=
fice/2004/12/omml" xmlns=3D"http://www.w3.org/TR/REC-html40">
<head>
<meta http-equiv=3D"Content-Type" content=3D"text/html; charset=3Dus-ascii"=
>
<meta name=3D"Generator" content=3D"Microsoft Word 15 (filtered medium)">
<style><!--
/* Font Definitions */
@font-face
	{font-family:"Cambria Math";
	panose-1:2 4 5 3 5 4 6 3 2 4;}
@font-face
	{font-family:Calibri;
	panose-1:2 15 5 2 2 2 4 3 2 4;}
@font-face
	{font-family:Aptos;
	panose-1:2 11 0 4 2 2 2 2 2 4;}
@font-face
	{font-family:"Helvetica Neue Light";
	panose-1:2 0 4 3 0 0 0 2 0 4;}
/* Style Definitions */
p.MsoNormal, li.MsoNormal, div.MsoNormal
	{margin:0cm;
	font-size:12.0pt;
	font-family:"Aptos",sans-serif;}
a:link, span.MsoHyperlink
	{mso-style-priority:99;
	color:blue;
	text-decoration:underline;}
p.p1, li.p1, div.p1
	{mso-style-name:p1;
	margin:0cm;
	font-size:10.5pt;
	font-family:"Helvetica Neue Light";
	color:black;}
.MsoChpDefault
	{mso-style-type:export-only;
	font-size:10.0pt;
	mso-ligatures:none;}
@page WordSection1
	{size:612.0pt 792.0pt;
	margin:72.0pt 72.0pt 72.0pt 72.0pt;}
div.WordSection1
	{page:WordSection1;}
--></style>
</head>
<body lang=3D"en-UA" link=3D"blue" vlink=3D"purple" style=3D"word-wrap:brea=
k-word">
<div class=3D"WordSection1">
<p class=3D"p1"><span lang=3D"EN-US" style=3D"font-size:11.0pt;font-family:=
&quot;Aptos&quot;,sans-serif;color:windowtext">Hi Wojciech!<br>
<br>
Can you please provide the initial version that you used (the one without a=
ny alerts)?<o:p></o:p></span></p>
<p class=3D"p1"><span lang=3D"EN-US" style=3D"font-size:11.0pt;font-family:=
&quot;Aptos&quot;,sans-serif;color:windowtext">I don't see any changes in t=
hat rule during that timeframe, so it could be triggered by either changes =
in Snort 3 or changes in your network traffic.<br>
<br>
The rule aims to detect <a href=3D"https://nvd.nist.gov/vuln/detail/cve-202=
0-1350">
https://nvd.nist.gov/vuln/detail/cve-2020-1350</a> which is of a CRITICAL s=
core, so it can be something to be worried about.<br>
I suggest you to check rule description(<a href=3D"https://snort.org/rule_d=
ocs/1-54577">https://snort.org/rule_docs/1-54577</a>) and CVE description, =
and analyze some traffic captures, to understand if alerts are valid or fal=
se positives.<o:p></o:p></span></p>
<p class=3D"MsoNormal"><span lang=3D"EN-US" style=3D"font-size:11.0pt"><br>
Thanks,<br>
Vitalii!<o:p></o:p></span></p>
<p class=3D"MsoNormal"><span style=3D"font-size:11.0pt;font-family:&quot;Ca=
libri&quot;,sans-serif;mso-fareast-language:EN-US"><o:p>&nbsp;</o:p></span>=
</p>
<div id=3D"mail-editor-reference-message-container">
<div>
<div>
<div style=3D"border:none;border-top:solid #B5C4DF 1.0pt;padding:3.0pt 0cm =
0cm 0cm">
<p class=3D"MsoNormal" style=3D"margin-bottom:12.0pt"><b><span style=3D"col=
or:black">From:
</span></b><span style=3D"color:black">Snort-users &lt;snort-users-bounces@=
lists.snort.org&gt; on behalf of Various emails via Snort-users &lt;snort-u=
[email protected]&gt;<br>
<b>Date: </b>Thursday, 19 December 2024 at 19:44<br>
<b>To: </b>[email protected] &lt;[email protected]&gt;<=
br>
<b>Subject: </b>[Snort-users] DNS Logs.<o:p></o:p></span></p>
</div>
<div>
<p class=3D"MsoNormal"><span style=3D"font-size:11.0pt">Hello Snort Communi=
ty,<br>
<br>
I have a question about alerts, that started to appear in logs since <br>
late November, I think after I installed the latest version on Snort 3 <br>
but not sure. Every device on my network&nbsp; is slowly scanned. Is this <=
br>
something to be worried about?<br>
<br>
I use subscription rules.<br>
<br>
12/18-14:21:39.031143 [**] [1:54577:4] &quot;SERVER-OTHER Microsoft Windows=
 <br>
DNS server remote integer overflow attempt&quot; [**] [Classification: <br>
Attempted User Privilege Gain] [Priority: 1] [AppID: DNS] {UDP} <br>
1.1.1.1:53 -&gt; 192.168.10.212:52696<br>
12/18-20:36:32.853211 [**] [1:54577:4] &quot;SERVER-OTHER Microsoft Windows=
 <br>
DNS server remote integer overflow attempt&quot; [**] [Classification: <br>
Attempted User Privilege Gain] [Priority: 1] [AppID: DNS] {UDP} <br>
8.8.8.8:53 -&gt; 192.168.10.7:59170<br>
12/18-23:08:15.699170 [**] [1:54577:4] &quot;SERVER-OTHER Microsoft Windows=
 <br>
DNS server remote integer overflow attempt&quot; [**] [Classification: <br>
Attempted User Privilege Gain] [Priority: 1] [AppID: DNS] {UDP} <br>
1.1.1.1:53 -&gt; 192.168.17.9:55277<br>
12/19-06:15:56.963296 [**] [1:54577:4] &quot;SERVER-OTHER Microsoft Windows=
 <br>
DNS server remote integer overflow attempt&quot; [**] [Classification: <br>
Attempted User Privilege Gain] [Priority: 1] [AppID: DNS] {UDP} <br>
1.1.1.1:53 -&gt; 192.168.17.9:36419<br>
<br>
w@w:/var/log/snort$ snort -V<br>
<br>
&nbsp;&nbsp;&nbsp; ,,_&nbsp;&nbsp;&nbsp;&nbsp; -*&gt; Snort++ &lt;*-<br>
&nbsp;&nbsp; o&quot;&nbsp; )~&nbsp;&nbsp; Version 3.5.2.0<br>
&nbsp;&nbsp;&nbsp; ''''&nbsp;&nbsp;&nbsp; By Martin Roesch &amp; The Snort =
Team<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; </span><=
a href=3D"http://snort.org/contact#team"><span style=3D"font-size:11.0pt">h=
ttp://snort.org/contact#team</span></a><span style=3D"font-size:11.0pt"><br=
>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; Copyrigh=
t (C) 2014-2024 Cisco and/or its affiliates. All <br>
rights reserved.<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; Copyrigh=
t (C) 1998-2013 Sourcefire, Inc., et al.<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; Using DA=
Q version 3.0.17<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; Using li=
bpcap version 1.10.4 (with TPACKET_V3)<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; Using Lu=
aJIT version 2.1.1703358377<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; Using LZ=
MA version 5.4.5<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; Using Op=
enSSL 3.0.13 30 Jan 2024<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; Using PC=
RE version 8.45 2021-06-15<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; Using ZL=
IB version 1.3<br>
<br>
<br>
Thank you,<br>
<br>
Wojciech<br>
<br>
<br>
<br>
_______________________________________________<br>
Snort-users mailing list<br>
[email protected]<br>
Go to this URL to change user options or unsubscribe:<br>
</span><a href=3D"https://lists.snort.org/mailman/listinfo/snort-users"><sp=
an style=3D"font-size:11.0pt">https://lists.snort.org/mailman/listinfo/snor=
t-users</span></a><span style=3D"font-size:11.0pt"><br>
<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; To unsubscribe, send an email to=
:<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; [email protected]=
g<br>
<br>
Please visit </span><a href=3D"http://blog.snort.org"><span style=3D"font-s=
ize:11.0pt">http://blog.snort.org</span></a><span style=3D"font-size:11.0pt=
"> to stay current on all the latest Snort news!<br>
<br>
Please follow these rules: </span><a href=3D"https://snort.org/faq/what-is-=
the-mailing-list-etiquette"><span style=3D"font-size:11.0pt">https://snort.=
org/faq/what-is-the-mailing-list-etiquette</span></a><span style=3D"font-si=
ze:11.0pt"><o:p></o:p></span></p>
</div>
</div>
</div>
</div>
</div>
</body>
</html>

--_000_MW4PR11MB8290483830E8514B0CC0604BDB112MW4PR11MB8290namp_--

--===============6179743928127115471==
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
Content-Disposition: inline

_______________________________________________
Snort-users mailing list
[email protected]
Go to this URL to change user options or unsubscribe:
https://lists.snort.org/mailman/listinfo/snort-users

	To unsubscribe, send an email to:
	[email protected]

Please visit http://blog.snort.org to stay current on all the latest Snort news!

Please follow these rules: https://snort.org/faq/what-is-the-mailing-list-etiquette

--===============6179743928127115471==--