Re: DNS Logs.

Thalia Montreux via Snort-users <[email protected]> Wed, 8 Jan 2025 04:31:59 -0600
Newsgroups gmane.comp.security.ids.snort.general
Message-ID <CAL6BM4hVRHsY12ouYydVk2A3TDnrhJmAvaxKPSahOZhK=a1jgA@mail.gmail.com>
--===============6803848377929009724==
Content-Type: multipart/alternative; boundary="000000000000cf19ae062b2f5f4b"

--000000000000cf19ae062b2f5f4b
Content-Type: text/plain; charset="UTF-8"

I would really like to see how your network traffic flows from public to
private

On Tue, Jan 7, 2025, 11:38 AM Various emails via Snort-users <
[email protected]> wrote:

> Here are my settings:
>
> HOME_NET = [[ 192.168.10.0/24 192.168.11.0/29 192.168.17.0/24 ]]
>
> EXTERNAL_NET = '!$HOME_NET'
>
>
> Not sure why, all alerts stopped on 01/01/2025, after updating the rules.
>
> On 1/7/2025 9:41 AM, Joel Esler wrote:
> > I am betting your HOME_NET and EXTERNAL_NET may not be set correctly.
> >
> >> On Dec 19, 2024, at 12:38, Various emails via Snort-users <
> [email protected]> wrote:
> >>
> >> Hello Snort Community,
> >>
> >> I have a question about alerts, that started to appear in logs since
> late November, I think after I installed the latest version on Snort 3 but
> not sure. Every device on my network  is slowly scanned. Is this something
> to be worried about?
> >>
> >> I use subscription rules.
> >>
> >> 12/18-14:21:39.031143 [**] [1:54577:4] "SERVER-OTHER Microsoft Windows
> DNS server remote integer overflow attempt" [**] [Classification: Attempted
> User Privilege Gain] [Priority: 1] [AppID: DNS] {UDP} 1.1.1.1:53 ->
> 192.168.10.212:52696
> >> 12/18-20:36:32.853211 [**] [1:54577:4] "SERVER-OTHER Microsoft Windows
> DNS server remote integer overflow attempt" [**] [Classification: Attempted
> User Privilege Gain] [Priority: 1] [AppID: DNS] {UDP} 8.8.8.8:53 ->
> 192.168.10.7:59170
> >> 12/18-23:08:15.699170 [**] [1:54577:4] "SERVER-OTHER Microsoft Windows
> DNS server remote integer overflow attempt" [**] [Classification: Attempted
> User Privilege Gain] [Priority: 1] [AppID: DNS] {UDP} 1.1.1.1:53 ->
> 192.168.17.9:55277
> >> 12/19-06:15:56.963296 [**] [1:54577:4] "SERVER-OTHER Microsoft Windows
> DNS server remote integer overflow attempt" [**] [Classification: Attempted
> User Privilege Gain] [Priority: 1] [AppID: DNS] {UDP} 1.1.1.1:53 ->
> 192.168.17.9:36419
> >>
> >> w@w:/var/log/snort$ snort -V
> >>
> >>     ,,_     -*> Snort++ <*-
> >>    o"  )~   Version 3.5.2.0
> >>     ''''    By Martin Roesch & The Snort Team
> >>             http://snort.org/contact#team
> >>             Copyright (C) 2014-2024 Cisco and/or its affiliates. All
> rights reserved.
> >>             Copyright (C) 1998-2013 Sourcefire, Inc., et al.
> >>             Using DAQ version 3.0.17
> >>             Using libpcap version 1.10.4 (with TPACKET_V3)
> >>             Using LuaJIT version 2.1.1703358377
> >>             Using LZMA version 5.4.5
> >>             Using OpenSSL 3.0.13 30 Jan 2024
> >>             Using PCRE version 8.45 2021-06-15
> >>             Using ZLIB version 1.3
> >>
> >>
> >> Thank you,
> >>
> >> Wojciech
> >>
> >>
> >>
> >> _______________________________________________
> >> Snort-users mailing list
> >> [email protected]
> >> Go to this URL to change user options or unsubscribe:
> >> https://lists.snort.org/mailman/listinfo/snort-users
> >>
> >>      To unsubscribe, send an email to:
> >>      [email protected]
> >>
> >> Please visit http://blog.snort.org to stay current on all the latest
> Snort news!
> >>
> >> Please follow these rules:
> https://snort.org/faq/what-is-the-mailing-list-etiquette
> _______________________________________________
> Snort-users mailing list
> [email protected]
> Go to this URL to change user options or unsubscribe:
> https://lists.snort.org/mailman/listinfo/snort-users
>
>         To unsubscribe, send an email to:
>         [email protected]
>
> Please visit http://blog.snort.org to stay current on all the latest
> Snort news!
>
> Please follow these rules:
> https://snort.org/faq/what-is-the-mailing-list-etiquette
>

--000000000000cf19ae062b2f5f4b
Content-Type: text/html; charset="UTF-8"
Content-Transfer-Encoding: quoted-printable

<p dir=3D"ltr">I would really like to see how your network traffic flows fr=
om public to private </p>
<br><div class=3D"gmail_quote gmail_quote_container"><div dir=3D"ltr" class=
=3D"gmail_attr">On Tue, Jan 7, 2025, 11:38 AM Various emails via Snort-user=
s &lt;<a href=3D"mailto:[email protected]">[email protected]=
t.org</a>&gt; wrote:<br></div><blockquote class=3D"gmail_quote" style=3D"ma=
rgin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex">Here are my se=
ttings:<br>
<br>
HOME_NET =3D [[ <a href=3D"http://192.168.10.0/24" rel=3D"noreferrer norefe=
rrer" target=3D"_blank">192.168.10.0/24</a> <a href=3D"http://192.168.11.0/=
29" rel=3D"noreferrer noreferrer" target=3D"_blank">192.168.11.0/29</a> <a =
href=3D"http://192.168.17.0/24" rel=3D"noreferrer noreferrer" target=3D"_bl=
ank">192.168.17.0/24</a> ]]<br>
<br>
EXTERNAL_NET =3D &#39;!$HOME_NET&#39;<br>
<br>
<br>
Not sure why, all alerts stopped on 01/01/2025, after updating the rules.<b=
r>
<br>
On 1/7/2025 9:41 AM, Joel Esler wrote:<br>
&gt; I am betting your HOME_NET and EXTERNAL_NET may not be set correctly.<=
br>
&gt;<br>
&gt;&gt; On Dec 19, 2024, at 12:38, Various emails via Snort-users &lt;<a h=
ref=3D"mailto:[email protected]" target=3D"_blank" rel=3D"norefer=
rer">[email protected]</a>&gt; wrote:<br>
&gt;&gt;<br>
&gt;&gt; Hello Snort Community,<br>
&gt;&gt;<br>
&gt;&gt; I have a question about alerts, that started to appear in logs sin=
ce late November, I think after I installed the latest version on Snort 3 b=
ut not sure. Every device on my network=C2=A0 is slowly scanned. Is this so=
mething to be worried about?<br>
&gt;&gt;<br>
&gt;&gt; I use subscription rules.<br>
&gt;&gt;<br>
&gt;&gt; 12/18-14:21:39.031143 [**] [1:54577:4] &quot;SERVER-OTHER Microsof=
t Windows DNS server remote integer overflow attempt&quot; [**] [Classifica=
tion: Attempted User Privilege Gain] [Priority: 1] [AppID: DNS] {UDP} <a hr=
ef=3D"http://1.1.1.1:53" rel=3D"noreferrer noreferrer" target=3D"_blank">1.=
1.1.1:53</a> -&gt; <a href=3D"http://192.168.10.212:52696" rel=3D"noreferre=
r noreferrer" target=3D"_blank">192.168.10.212:52696</a><br>
&gt;&gt; 12/18-20:36:32.853211 [**] [1:54577:4] &quot;SERVER-OTHER Microsof=
t Windows DNS server remote integer overflow attempt&quot; [**] [Classifica=
tion: Attempted User Privilege Gain] [Priority: 1] [AppID: DNS] {UDP} <a hr=
ef=3D"http://8.8.8.8:53" rel=3D"noreferrer noreferrer" target=3D"_blank">8.=
8.8.8:53</a> -&gt; <a href=3D"http://192.168.10.7:59170" rel=3D"noreferrer =
noreferrer" target=3D"_blank">192.168.10.7:59170</a><br>
&gt;&gt; 12/18-23:08:15.699170 [**] [1:54577:4] &quot;SERVER-OTHER Microsof=
t Windows DNS server remote integer overflow attempt&quot; [**] [Classifica=
tion: Attempted User Privilege Gain] [Priority: 1] [AppID: DNS] {UDP} <a hr=
ef=3D"http://1.1.1.1:53" rel=3D"noreferrer noreferrer" target=3D"_blank">1.=
1.1.1:53</a> -&gt; <a href=3D"http://192.168.17.9:55277" rel=3D"noreferrer =
noreferrer" target=3D"_blank">192.168.17.9:55277</a><br>
&gt;&gt; 12/19-06:15:56.963296 [**] [1:54577:4] &quot;SERVER-OTHER Microsof=
t Windows DNS server remote integer overflow attempt&quot; [**] [Classifica=
tion: Attempted User Privilege Gain] [Priority: 1] [AppID: DNS] {UDP} <a hr=
ef=3D"http://1.1.1.1:53" rel=3D"noreferrer noreferrer" target=3D"_blank">1.=
1.1.1:53</a> -&gt; <a href=3D"http://192.168.17.9:36419" rel=3D"noreferrer =
noreferrer" target=3D"_blank">192.168.17.9:36419</a><br>
&gt;&gt;<br>
&gt;&gt; w@w:/var/log/snort$ snort -V<br>
&gt;&gt;<br>
&gt;&gt;=C2=A0 =C2=A0 =C2=A0,,_=C2=A0 =C2=A0 =C2=A0-*&gt; Snort++ &lt;*-<br=
>
&gt;&gt;=C2=A0 =C2=A0 o&quot;=C2=A0 )~=C2=A0 =C2=A0Version 3.5.2.0<br>
&gt;&gt;=C2=A0 =C2=A0 =C2=A0&#39;&#39;&#39;&#39;=C2=A0 =C2=A0 By Martin Roe=
sch &amp; The Snort Team<br>
&gt;&gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0<a href=3D"http://s=
nort.org/contact#team" rel=3D"noreferrer noreferrer" target=3D"_blank">http=
://snort.org/contact#team</a><br>
&gt;&gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0Copyright (C) 2014-=
2024 Cisco and/or its affiliates. All rights reserved.<br>
&gt;&gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0Copyright (C) 1998-=
2013 Sourcefire, Inc., et al.<br>
&gt;&gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0Using DAQ version 3=
.0.17<br>
&gt;&gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0Using libpcap versi=
on 1.10.4 (with TPACKET_V3)<br>
&gt;&gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0Using LuaJIT versio=
n 2.1.1703358377<br>
&gt;&gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0Using LZMA version =
5.4.5<br>
&gt;&gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0Using OpenSSL 3.0.1=
3 30 Jan 2024<br>
&gt;&gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0Using PCRE version =
8.45 2021-06-15<br>
&gt;&gt;=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0Using ZLIB version =
1.3<br>
&gt;&gt;<br>
&gt;&gt;<br>
&gt;&gt; Thank you,<br>
&gt;&gt;<br>
&gt;&gt; Wojciech<br>
&gt;&gt;<br>
&gt;&gt;<br>
&gt;&gt;<br>
&gt;&gt; _______________________________________________<br>
&gt;&gt; Snort-users mailing list<br>
&gt;&gt; <a href=3D"mailto:[email protected]" target=3D"_blank" r=
el=3D"noreferrer">[email protected]</a><br>
&gt;&gt; Go to this URL to change user options or unsubscribe:<br>
&gt;&gt; <a href=3D"https://lists.snort.org/mailman/listinfo/snort-users" r=
el=3D"noreferrer noreferrer" target=3D"_blank">https://lists.snort.org/mail=
man/listinfo/snort-users</a><br>
&gt;&gt;<br>
&gt;&gt;=C2=A0 =C2=A0 =C2=A0 To unsubscribe, send an email to:<br>
&gt;&gt;=C2=A0 =C2=A0 =C2=A0 <a href=3D"mailto:[email protected]=
t.org" target=3D"_blank" rel=3D"noreferrer">[email protected]=
rg</a><br>
&gt;&gt;<br>
&gt;&gt; Please visit <a href=3D"http://blog.snort.org" rel=3D"noreferrer n=
oreferrer" target=3D"_blank">http://blog.snort.org</a> to stay current on a=
ll the latest Snort news!<br>
&gt;&gt;<br>
&gt;&gt; Please follow these rules: <a href=3D"https://snort.org/faq/what-i=
s-the-mailing-list-etiquette" rel=3D"noreferrer noreferrer" target=3D"_blan=
k">https://snort.org/faq/what-is-the-mailing-list-etiquette</a><br>
_______________________________________________<br>
Snort-users mailing list<br>
<a href=3D"mailto:[email protected]" target=3D"_blank" rel=3D"nor=
eferrer">[email protected]</a><br>
Go to this URL to change user options or unsubscribe:<br>
<a href=3D"https://lists.snort.org/mailman/listinfo/snort-users" rel=3D"nor=
eferrer noreferrer" target=3D"_blank">https://lists.snort.org/mailman/listi=
nfo/snort-users</a><br>
<br>
=C2=A0 =C2=A0 =C2=A0 =C2=A0 To unsubscribe, send an email to:<br>
=C2=A0 =C2=A0 =C2=A0 =C2=A0 <a href=3D"mailto:[email protected]=
.org" target=3D"_blank" rel=3D"noreferrer">[email protected]=
g</a><br>
<br>
Please visit <a href=3D"http://blog.snort.org" rel=3D"noreferrer noreferrer=
" target=3D"_blank">http://blog.snort.org</a> to stay current on all the la=
test Snort news!<br>
<br>
Please follow these rules: <a href=3D"https://snort.org/faq/what-is-the-mai=
ling-list-etiquette" rel=3D"noreferrer noreferrer" target=3D"_blank">https:=
//snort.org/faq/what-is-the-mailing-list-etiquette</a><br>
</blockquote></div>

--000000000000cf19ae062b2f5f4b--

--===============6803848377929009724==
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
Content-Disposition: inline

_______________________________________________
Snort-users mailing list
[email protected]
Go to this URL to change user options or unsubscribe:
https://lists.snort.org/mailman/listinfo/snort-users

	To unsubscribe, send an email to:
	[email protected]

Please visit http://blog.snort.org to stay current on all the latest Snort news!

Please follow these rules: https://snort.org/faq/what-is-the-mailing-list-etiquette

--===============6803848377929009724==--