Re: DNS Logs.
"Vitalii Serhiiovych Horbatov -X \(vhorbato - SOFTSERVE INC at Cisco\) via Snort-users" <[email protected]> Tue, 7 Jan 2025 14:48:20 +0000
| Newsgroups | gmane.comp.security.ids.snort.general |
|---|---|
| Message-ID | <MW4PR11MB8290483830E8514B0CC0604BDB112@MW4PR11MB8290.namprd11.prod.outlook.com> |
--===============6179743928127115471== Content-Language: en-GB Content-Type: multipart/alternative; boundary="_000_MW4PR11MB8290483830E8514B0CC0604BDB112MW4PR11MB8290namp_" --_000_MW4PR11MB8290483830E8514B0CC0604BDB112MW4PR11MB8290namp_ Content-Type: text/plain; charset="us-ascii" Content-Transfer-Encoding: quoted-printable Hi Wojciech! Can you please provide the initial version that you used (the one without a= ny alerts)? I don't see any changes in that rule during that timeframe, so it could be = triggered by either changes in Snort 3 or changes in your network traffic. The rule aims to detect https://nvd.nist.gov/vuln/detail/cve-2020-1350 whic= h is of a CRITICAL score, so it can be something to be worried about. I suggest you to check rule description(https://snort.org/rule_docs/1-54577= ) and CVE description, and analyze some traffic captures, to understand if = alerts are valid or false positives. Thanks, Vitalii! From: Snort-users <[email protected]> on behalf of Variou= s emails via Snort-users <[email protected]> Date: Thursday, 19 December 2024 at 19:44 To: [email protected] <[email protected]> Subject: [Snort-users] DNS Logs. Hello Snort Community, I have a question about alerts, that started to appear in logs since late November, I think after I installed the latest version on Snort 3 but not sure. Every device on my network is slowly scanned. Is this something to be worried about? I use subscription rules. 12/18-14:21:39.031143 [**] [1:54577:4] "SERVER-OTHER Microsoft Windows DNS server remote integer overflow attempt" [**] [Classification: Attempted User Privilege Gain] [Priority: 1] [AppID: DNS] {UDP} 1.1.1.1:53 -> 192.168.10.212:52696 12/18-20:36:32.853211 [**] [1:54577:4] "SERVER-OTHER Microsoft Windows DNS server remote integer overflow attempt" [**] [Classification: Attempted User Privilege Gain] [Priority: 1] [AppID: DNS] {UDP} 8.8.8.8:53 -> 192.168.10.7:59170 12/18-23:08:15.699170 [**] [1:54577:4] "SERVER-OTHER Microsoft Windows DNS server remote integer overflow attempt" [**] [Classification: Attempted User Privilege Gain] [Priority: 1] [AppID: DNS] {UDP} 1.1.1.1:53 -> 192.168.17.9:55277 12/19-06:15:56.963296 [**] [1:54577:4] "SERVER-OTHER Microsoft Windows DNS server remote integer overflow attempt" [**] [Classification: Attempted User Privilege Gain] [Priority: 1] [AppID: DNS] {UDP} 1.1.1.1:53 -> 192.168.17.9:36419 w@w:/var/log/snort$ snort -V ,,_ -*> Snort++ <*- o" )~ Version 3.5.2.0 '''' By Martin Roesch & The Snort Team http://snort.org/contact#team Copyright (C) 2014-2024 Cisco and/or its affiliates. All rights reserved. Copyright (C) 1998-2013 Sourcefire, Inc., et al. Using DAQ version 3.0.17 Using libpcap version 1.10.4 (with TPACKET_V3) Using LuaJIT version 2.1.1703358377 Using LZMA version 5.4.5 Using OpenSSL 3.0.13 30 Jan 2024 Using PCRE version 8.45 2021-06-15 Using ZLIB version 1.3 Thank you, Wojciech _______________________________________________ Snort-users mailing list [email protected] Go to this URL to change user options or unsubscribe: https://lists.snort.org/mailman/listinfo/snort-users To unsubscribe, send an email to: [email protected] Please visit http://blog.snort.org to stay current on all the latest Snort = news! Please follow these rules: https://snort.org/faq/what-is-the-mailing-list-e= tiquette --_000_MW4PR11MB8290483830E8514B0CC0604BDB112MW4PR11MB8290namp_ Content-Type: text/html; charset="us-ascii" Content-Transfer-Encoding: quoted-printable <html xmlns:o=3D"urn:schemas-microsoft-com:office:office" xmlns:w=3D"urn:sc= hemas-microsoft-com:office:word" xmlns:m=3D"http://schemas.microsoft.com/of= fice/2004/12/omml" xmlns=3D"http://www.w3.org/TR/REC-html40"> <head> <meta http-equiv=3D"Content-Type" content=3D"text/html; charset=3Dus-ascii"= > <meta name=3D"Generator" content=3D"Microsoft Word 15 (filtered medium)"> <style><!-- /* Font Definitions */ @font-face {font-family:"Cambria Math"; panose-1:2 4 5 3 5 4 6 3 2 4;} @font-face {font-family:Calibri; panose-1:2 15 5 2 2 2 4 3 2 4;} @font-face {font-family:Aptos; panose-1:2 11 0 4 2 2 2 2 2 4;} @font-face {font-family:"Helvetica Neue Light"; panose-1:2 0 4 3 0 0 0 2 0 4;} /* Style Definitions */ p.MsoNormal, li.MsoNormal, div.MsoNormal {margin:0cm; font-size:12.0pt; font-family:"Aptos",sans-serif;} a:link, span.MsoHyperlink {mso-style-priority:99; color:blue; text-decoration:underline;} p.p1, li.p1, div.p1 {mso-style-name:p1; margin:0cm; font-size:10.5pt; font-family:"Helvetica Neue Light"; color:black;} .MsoChpDefault {mso-style-type:export-only; font-size:10.0pt; mso-ligatures:none;} @page WordSection1 {size:612.0pt 792.0pt; margin:72.0pt 72.0pt 72.0pt 72.0pt;} div.WordSection1 {page:WordSection1;} --></style> </head> <body lang=3D"en-UA" link=3D"blue" vlink=3D"purple" style=3D"word-wrap:brea= k-word"> <div class=3D"WordSection1"> <p class=3D"p1"><span lang=3D"EN-US" style=3D"font-size:11.0pt;font-family:= "Aptos",sans-serif;color:windowtext">Hi Wojciech!<br> <br> Can you please provide the initial version that you used (the one without a= ny alerts)?<o:p></o:p></span></p> <p class=3D"p1"><span lang=3D"EN-US" style=3D"font-size:11.0pt;font-family:= "Aptos",sans-serif;color:windowtext">I don't see any changes in t= hat rule during that timeframe, so it could be triggered by either changes = in Snort 3 or changes in your network traffic.<br> <br> The rule aims to detect <a href=3D"https://nvd.nist.gov/vuln/detail/cve-202= 0-1350"> https://nvd.nist.gov/vuln/detail/cve-2020-1350</a> which is of a CRITICAL s= core, so it can be something to be worried about.<br> I suggest you to check rule description(<a href=3D"https://snort.org/rule_d= ocs/1-54577">https://snort.org/rule_docs/1-54577</a>) and CVE description, = and analyze some traffic captures, to understand if alerts are valid or fal= se positives.<o:p></o:p></span></p> <p class=3D"MsoNormal"><span lang=3D"EN-US" style=3D"font-size:11.0pt"><br> Thanks,<br> Vitalii!<o:p></o:p></span></p> <p class=3D"MsoNormal"><span style=3D"font-size:11.0pt;font-family:"Ca= libri",sans-serif;mso-fareast-language:EN-US"><o:p> </o:p></span>= </p> <div id=3D"mail-editor-reference-message-container"> <div> <div> <div style=3D"border:none;border-top:solid #B5C4DF 1.0pt;padding:3.0pt 0cm = 0cm 0cm"> <p class=3D"MsoNormal" style=3D"margin-bottom:12.0pt"><b><span style=3D"col= or:black">From: </span></b><span style=3D"color:black">Snort-users <snort-users-bounces@= lists.snort.org> on behalf of Various emails via Snort-users <snort-u= [email protected]><br> <b>Date: </b>Thursday, 19 December 2024 at 19:44<br> <b>To: </b>[email protected] <[email protected]><= br> <b>Subject: </b>[Snort-users] DNS Logs.<o:p></o:p></span></p> </div> <div> <p class=3D"MsoNormal"><span style=3D"font-size:11.0pt">Hello Snort Communi= ty,<br> <br> I have a question about alerts, that started to appear in logs since <br> late November, I think after I installed the latest version on Snort 3 <br> but not sure. Every device on my network is slowly scanned. Is this <= br> something to be worried about?<br> <br> I use subscription rules.<br> <br> 12/18-14:21:39.031143 [**] [1:54577:4] "SERVER-OTHER Microsoft Windows= <br> DNS server remote integer overflow attempt" [**] [Classification: <br> Attempted User Privilege Gain] [Priority: 1] [AppID: DNS] {UDP} <br> 1.1.1.1:53 -> 192.168.10.212:52696<br> 12/18-20:36:32.853211 [**] [1:54577:4] "SERVER-OTHER Microsoft Windows= <br> DNS server remote integer overflow attempt" [**] [Classification: <br> Attempted User Privilege Gain] [Priority: 1] [AppID: DNS] {UDP} <br> 8.8.8.8:53 -> 192.168.10.7:59170<br> 12/18-23:08:15.699170 [**] [1:54577:4] "SERVER-OTHER Microsoft Windows= <br> DNS server remote integer overflow attempt" [**] [Classification: <br> Attempted User Privilege Gain] [Priority: 1] [AppID: DNS] {UDP} <br> 1.1.1.1:53 -> 192.168.17.9:55277<br> 12/19-06:15:56.963296 [**] [1:54577:4] "SERVER-OTHER Microsoft Windows= <br> DNS server remote integer overflow attempt" [**] [Classification: <br> Attempted User Privilege Gain] [Priority: 1] [AppID: DNS] {UDP} <br> 1.1.1.1:53 -> 192.168.17.9:36419<br> <br> w@w:/var/log/snort$ snort -V<br> <br> ,,_ -*> Snort++ <*-<br> o" )~ Version 3.5.2.0<br> '''' By Martin Roesch & The Snort = Team<br> </span><= a href=3D"http://snort.org/contact#team"><span style=3D"font-size:11.0pt">h= ttp://snort.org/contact#team</span></a><span style=3D"font-size:11.0pt"><br= > Copyrigh= t (C) 2014-2024 Cisco and/or its affiliates. All <br> rights reserved.<br> Copyrigh= t (C) 1998-2013 Sourcefire, Inc., et al.<br> Using DA= Q version 3.0.17<br> Using li= bpcap version 1.10.4 (with TPACKET_V3)<br> Using Lu= aJIT version 2.1.1703358377<br> Using LZ= MA version 5.4.5<br> Using Op= enSSL 3.0.13 30 Jan 2024<br> Using PC= RE version 8.45 2021-06-15<br> Using ZL= IB version 1.3<br> <br> <br> Thank you,<br> <br> Wojciech<br> <br> <br> <br> _______________________________________________<br> Snort-users mailing list<br> [email protected]<br> Go to this URL to change user options or unsubscribe:<br> </span><a href=3D"https://lists.snort.org/mailman/listinfo/snort-users"><sp= an style=3D"font-size:11.0pt">https://lists.snort.org/mailman/listinfo/snor= t-users</span></a><span style=3D"font-size:11.0pt"><br> <br> To unsubscribe, send an email to= :<br> [email protected]= g<br> <br> Please visit </span><a href=3D"http://blog.snort.org"><span style=3D"font-s= ize:11.0pt">http://blog.snort.org</span></a><span style=3D"font-size:11.0pt= "> to stay current on all the latest Snort news!<br> <br> Please follow these rules: </span><a href=3D"https://snort.org/faq/what-is-= the-mailing-list-etiquette"><span style=3D"font-size:11.0pt">https://snort.= org/faq/what-is-the-mailing-list-etiquette</span></a><span style=3D"font-si= ze:11.0pt"><o:p></o:p></span></p> </div> </div> </div> </div> </div> </body> </html> --_000_MW4PR11MB8290483830E8514B0CC0604BDB112MW4PR11MB8290namp_-- --===============6179743928127115471== Content-Type: text/plain; charset="us-ascii" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit Content-Disposition: inline _______________________________________________ Snort-users mailing list [email protected] Go to this URL to change user options or unsubscribe: https://lists.snort.org/mailman/listinfo/snort-users To unsubscribe, send an email to: [email protected] Please visit http://blog.snort.org to stay current on all the latest Snort news! Please follow these rules: https://snort.org/faq/what-is-the-mailing-list-etiquette --===============6179743928127115471==--