Re: DNS Logs.

Various emails via Snort-users <[email protected]> Tue, 7 Jan 2025 10:18:13 -0700
Newsgroups gmane.comp.security.ids.snort.general
Message-ID <[email protected]>
Here are my settings:

HOME_NET = [[ 192.168.10.0/24 192.168.11.0/29 192.168.17.0/24 ]]

EXTERNAL_NET = '!$HOME_NET'


Not sure why, all alerts stopped on 01/01/2025, after updating the rules.

On 1/7/2025 9:41 AM, Joel Esler wrote:
> I am betting your HOME_NET and EXTERNAL_NET may not be set correctly.
>
>> On Dec 19, 2024, at 12:38, Various emails via Snort-users <[email protected]> wrote:
>>
>> Hello Snort Community,
>>
>> I have a question about alerts, that started to appear in logs since late November, I think after I installed the latest version on Snort 3 but not sure. Every device on my network  is slowly scanned. Is this something to be worried about?
>>
>> I use subscription rules.
>>
>> 12/18-14:21:39.031143 [**] [1:54577:4] "SERVER-OTHER Microsoft Windows DNS server remote integer overflow attempt" [**] [Classification: Attempted User Privilege Gain] [Priority: 1] [AppID: DNS] {UDP} 1.1.1.1:53 -> 192.168.10.212:52696
>> 12/18-20:36:32.853211 [**] [1:54577:4] "SERVER-OTHER Microsoft Windows DNS server remote integer overflow attempt" [**] [Classification: Attempted User Privilege Gain] [Priority: 1] [AppID: DNS] {UDP} 8.8.8.8:53 -> 192.168.10.7:59170
>> 12/18-23:08:15.699170 [**] [1:54577:4] "SERVER-OTHER Microsoft Windows DNS server remote integer overflow attempt" [**] [Classification: Attempted User Privilege Gain] [Priority: 1] [AppID: DNS] {UDP} 1.1.1.1:53 -> 192.168.17.9:55277
>> 12/19-06:15:56.963296 [**] [1:54577:4] "SERVER-OTHER Microsoft Windows DNS server remote integer overflow attempt" [**] [Classification: Attempted User Privilege Gain] [Priority: 1] [AppID: DNS] {UDP} 1.1.1.1:53 -> 192.168.17.9:36419
>>
>> w@w:/var/log/snort$ snort -V
>>
>>     ,,_     -*> Snort++ <*-
>>    o"  )~   Version 3.5.2.0
>>     ''''    By Martin Roesch & The Snort Team
>>             http://snort.org/contact#team
>>             Copyright (C) 2014-2024 Cisco and/or its affiliates. All rights reserved.
>>             Copyright (C) 1998-2013 Sourcefire, Inc., et al.
>>             Using DAQ version 3.0.17
>>             Using libpcap version 1.10.4 (with TPACKET_V3)
>>             Using LuaJIT version 2.1.1703358377
>>             Using LZMA version 5.4.5
>>             Using OpenSSL 3.0.13 30 Jan 2024
>>             Using PCRE version 8.45 2021-06-15
>>             Using ZLIB version 1.3
>>
>>
>> Thank you,
>>
>> Wojciech
>>
>>
>>
>> _______________________________________________
>> Snort-users mailing list
>> [email protected]
>> Go to this URL to change user options or unsubscribe:
>> https://lists.snort.org/mailman/listinfo/snort-users
>>
>> 	To unsubscribe, send an email to:
>> 	[email protected]
>>
>> Please visit http://blog.snort.org to stay current on all the latest Snort news!
>>
>> Please follow these rules: https://snort.org/faq/what-is-the-mailing-list-etiquette
_______________________________________________
Snort-users mailing list
[email protected]
Go to this URL to change user options or unsubscribe:
https://lists.snort.org/mailman/listinfo/snort-users

	To unsubscribe, send an email to:
	[email protected]

Please visit http://blog.snort.org to stay current on all the latest Snort news!

Please follow these rules: https://snort.org/faq/what-is-the-mailing-list-etiquette