Re: DNS Logs.
Various emails via Snort-users <[email protected]> Tue, 7 Jan 2025 10:18:13 -0700
| Newsgroups | gmane.comp.security.ids.snort.general |
|---|---|
| Message-ID | <[email protected]> |
Here are my settings: HOME_NET = [[ 192.168.10.0/24 192.168.11.0/29 192.168.17.0/24 ]] EXTERNAL_NET = '!$HOME_NET' Not sure why, all alerts stopped on 01/01/2025, after updating the rules. On 1/7/2025 9:41 AM, Joel Esler wrote: > I am betting your HOME_NET and EXTERNAL_NET may not be set correctly. > >> On Dec 19, 2024, at 12:38, Various emails via Snort-users <[email protected]> wrote: >> >> Hello Snort Community, >> >> I have a question about alerts, that started to appear in logs since late November, I think after I installed the latest version on Snort 3 but not sure. Every device on my network is slowly scanned. Is this something to be worried about? >> >> I use subscription rules. >> >> 12/18-14:21:39.031143 [**] [1:54577:4] "SERVER-OTHER Microsoft Windows DNS server remote integer overflow attempt" [**] [Classification: Attempted User Privilege Gain] [Priority: 1] [AppID: DNS] {UDP} 1.1.1.1:53 -> 192.168.10.212:52696 >> 12/18-20:36:32.853211 [**] [1:54577:4] "SERVER-OTHER Microsoft Windows DNS server remote integer overflow attempt" [**] [Classification: Attempted User Privilege Gain] [Priority: 1] [AppID: DNS] {UDP} 8.8.8.8:53 -> 192.168.10.7:59170 >> 12/18-23:08:15.699170 [**] [1:54577:4] "SERVER-OTHER Microsoft Windows DNS server remote integer overflow attempt" [**] [Classification: Attempted User Privilege Gain] [Priority: 1] [AppID: DNS] {UDP} 1.1.1.1:53 -> 192.168.17.9:55277 >> 12/19-06:15:56.963296 [**] [1:54577:4] "SERVER-OTHER Microsoft Windows DNS server remote integer overflow attempt" [**] [Classification: Attempted User Privilege Gain] [Priority: 1] [AppID: DNS] {UDP} 1.1.1.1:53 -> 192.168.17.9:36419 >> >> w@w:/var/log/snort$ snort -V >> >> ,,_ -*> Snort++ <*- >> o" )~ Version 3.5.2.0 >> '''' By Martin Roesch & The Snort Team >> http://snort.org/contact#team >> Copyright (C) 2014-2024 Cisco and/or its affiliates. All rights reserved. >> Copyright (C) 1998-2013 Sourcefire, Inc., et al. >> Using DAQ version 3.0.17 >> Using libpcap version 1.10.4 (with TPACKET_V3) >> Using LuaJIT version 2.1.1703358377 >> Using LZMA version 5.4.5 >> Using OpenSSL 3.0.13 30 Jan 2024 >> Using PCRE version 8.45 2021-06-15 >> Using ZLIB version 1.3 >> >> >> Thank you, >> >> Wojciech >> >> >> >> _______________________________________________ >> Snort-users mailing list >> [email protected] >> Go to this URL to change user options or unsubscribe: >> https://lists.snort.org/mailman/listinfo/snort-users >> >> To unsubscribe, send an email to: >> [email protected] >> >> Please visit http://blog.snort.org to stay current on all the latest Snort news! >> >> Please follow these rules: https://snort.org/faq/what-is-the-mailing-list-etiquette _______________________________________________ Snort-users mailing list [email protected] Go to this URL to change user options or unsubscribe: https://lists.snort.org/mailman/listinfo/snort-users To unsubscribe, send an email to: [email protected] Please visit http://blog.snort.org to stay current on all the latest Snort news! Please follow these rules: https://snort.org/faq/what-is-the-mailing-list-etiquette