Re: DNS Logs.
Thalia Montreux via Snort-users <[email protected]> Wed, 8 Jan 2025 04:31:59 -0600
| Newsgroups | gmane.comp.security.ids.snort.general |
|---|---|
| Message-ID | <CAL6BM4hVRHsY12ouYydVk2A3TDnrhJmAvaxKPSahOZhK=a1jgA@mail.gmail.com> |
--===============6803848377929009724== Content-Type: multipart/alternative; boundary="000000000000cf19ae062b2f5f4b" --000000000000cf19ae062b2f5f4b Content-Type: text/plain; charset="UTF-8" I would really like to see how your network traffic flows from public to private On Tue, Jan 7, 2025, 11:38 AM Various emails via Snort-users < [email protected]> wrote: > Here are my settings: > > HOME_NET = [[ 192.168.10.0/24 192.168.11.0/29 192.168.17.0/24 ]] > > EXTERNAL_NET = '!$HOME_NET' > > > Not sure why, all alerts stopped on 01/01/2025, after updating the rules. > > On 1/7/2025 9:41 AM, Joel Esler wrote: > > I am betting your HOME_NET and EXTERNAL_NET may not be set correctly. > > > >> On Dec 19, 2024, at 12:38, Various emails via Snort-users < > [email protected]> wrote: > >> > >> Hello Snort Community, > >> > >> I have a question about alerts, that started to appear in logs since > late November, I think after I installed the latest version on Snort 3 but > not sure. Every device on my network is slowly scanned. Is this something > to be worried about? > >> > >> I use subscription rules. > >> > >> 12/18-14:21:39.031143 [**] [1:54577:4] "SERVER-OTHER Microsoft Windows > DNS server remote integer overflow attempt" [**] [Classification: Attempted > User Privilege Gain] [Priority: 1] [AppID: DNS] {UDP} 1.1.1.1:53 -> > 192.168.10.212:52696 > >> 12/18-20:36:32.853211 [**] [1:54577:4] "SERVER-OTHER Microsoft Windows > DNS server remote integer overflow attempt" [**] [Classification: Attempted > User Privilege Gain] [Priority: 1] [AppID: DNS] {UDP} 8.8.8.8:53 -> > 192.168.10.7:59170 > >> 12/18-23:08:15.699170 [**] [1:54577:4] "SERVER-OTHER Microsoft Windows > DNS server remote integer overflow attempt" [**] [Classification: Attempted > User Privilege Gain] [Priority: 1] [AppID: DNS] {UDP} 1.1.1.1:53 -> > 192.168.17.9:55277 > >> 12/19-06:15:56.963296 [**] [1:54577:4] "SERVER-OTHER Microsoft Windows > DNS server remote integer overflow attempt" [**] [Classification: Attempted > User Privilege Gain] [Priority: 1] [AppID: DNS] {UDP} 1.1.1.1:53 -> > 192.168.17.9:36419 > >> > >> w@w:/var/log/snort$ snort -V > >> > >> ,,_ -*> Snort++ <*- > >> o" )~ Version 3.5.2.0 > >> '''' By Martin Roesch & The Snort Team > >> http://snort.org/contact#team > >> Copyright (C) 2014-2024 Cisco and/or its affiliates. All > rights reserved. > >> Copyright (C) 1998-2013 Sourcefire, Inc., et al. > >> Using DAQ version 3.0.17 > >> Using libpcap version 1.10.4 (with TPACKET_V3) > >> Using LuaJIT version 2.1.1703358377 > >> Using LZMA version 5.4.5 > >> Using OpenSSL 3.0.13 30 Jan 2024 > >> Using PCRE version 8.45 2021-06-15 > >> Using ZLIB version 1.3 > >> > >> > >> Thank you, > >> > >> Wojciech > >> > >> > >> > >> _______________________________________________ > >> Snort-users mailing list > >> [email protected] > >> Go to this URL to change user options or unsubscribe: > >> https://lists.snort.org/mailman/listinfo/snort-users > >> > >> To unsubscribe, send an email to: > >> [email protected] > >> > >> Please visit http://blog.snort.org to stay current on all the latest > Snort news! > >> > >> Please follow these rules: > https://snort.org/faq/what-is-the-mailing-list-etiquette > _______________________________________________ > Snort-users mailing list > [email protected] > Go to this URL to change user options or unsubscribe: > https://lists.snort.org/mailman/listinfo/snort-users > > To unsubscribe, send an email to: > [email protected] > > Please visit http://blog.snort.org to stay current on all the latest > Snort news! > > Please follow these rules: > https://snort.org/faq/what-is-the-mailing-list-etiquette > --000000000000cf19ae062b2f5f4b Content-Type: text/html; charset="UTF-8" Content-Transfer-Encoding: quoted-printable <p dir=3D"ltr">I would really like to see how your network traffic flows fr= om public to private </p> <br><div class=3D"gmail_quote gmail_quote_container"><div dir=3D"ltr" class= =3D"gmail_attr">On Tue, Jan 7, 2025, 11:38 AM Various emails via Snort-user= s <<a href=3D"mailto:[email protected]">[email protected]= t.org</a>> wrote:<br></div><blockquote class=3D"gmail_quote" style=3D"ma= rgin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex">Here are my se= ttings:<br> <br> HOME_NET =3D [[ <a href=3D"http://192.168.10.0/24" rel=3D"noreferrer norefe= rrer" target=3D"_blank">192.168.10.0/24</a> <a href=3D"http://192.168.11.0/= 29" rel=3D"noreferrer noreferrer" target=3D"_blank">192.168.11.0/29</a> <a = href=3D"http://192.168.17.0/24" rel=3D"noreferrer noreferrer" target=3D"_bl= ank">192.168.17.0/24</a> ]]<br> <br> EXTERNAL_NET =3D '!$HOME_NET'<br> <br> <br> Not sure why, all alerts stopped on 01/01/2025, after updating the rules.<b= r> <br> On 1/7/2025 9:41 AM, Joel Esler wrote:<br> > I am betting your HOME_NET and EXTERNAL_NET may not be set correctly.<= br> ><br> >> On Dec 19, 2024, at 12:38, Various emails via Snort-users <<a h= ref=3D"mailto:[email protected]" target=3D"_blank" rel=3D"norefer= rer">[email protected]</a>> wrote:<br> >><br> >> Hello Snort Community,<br> >><br> >> I have a question about alerts, that started to appear in logs sin= ce late November, I think after I installed the latest version on Snort 3 b= ut not sure. Every device on my network=C2=A0 is slowly scanned. Is this so= mething to be worried about?<br> >><br> >> I use subscription rules.<br> >><br> >> 12/18-14:21:39.031143 [**] [1:54577:4] "SERVER-OTHER Microsof= t Windows DNS server remote integer overflow attempt" [**] [Classifica= tion: Attempted User Privilege Gain] [Priority: 1] [AppID: DNS] {UDP} <a hr= ef=3D"http://1.1.1.1:53" rel=3D"noreferrer noreferrer" target=3D"_blank">1.= 1.1.1:53</a> -> <a href=3D"http://192.168.10.212:52696" rel=3D"noreferre= r noreferrer" target=3D"_blank">192.168.10.212:52696</a><br> >> 12/18-20:36:32.853211 [**] [1:54577:4] "SERVER-OTHER Microsof= t Windows DNS server remote integer overflow attempt" [**] [Classifica= tion: Attempted User Privilege Gain] [Priority: 1] [AppID: DNS] {UDP} <a hr= ef=3D"http://8.8.8.8:53" rel=3D"noreferrer noreferrer" target=3D"_blank">8.= 8.8.8:53</a> -> <a href=3D"http://192.168.10.7:59170" rel=3D"noreferrer = noreferrer" target=3D"_blank">192.168.10.7:59170</a><br> >> 12/18-23:08:15.699170 [**] [1:54577:4] "SERVER-OTHER Microsof= t Windows DNS server remote integer overflow attempt" [**] [Classifica= tion: Attempted User Privilege Gain] [Priority: 1] [AppID: DNS] {UDP} <a hr= ef=3D"http://1.1.1.1:53" rel=3D"noreferrer noreferrer" target=3D"_blank">1.= 1.1.1:53</a> -> <a href=3D"http://192.168.17.9:55277" rel=3D"noreferrer = noreferrer" target=3D"_blank">192.168.17.9:55277</a><br> >> 12/19-06:15:56.963296 [**] [1:54577:4] "SERVER-OTHER Microsof= t Windows DNS server remote integer overflow attempt" [**] [Classifica= tion: Attempted User Privilege Gain] [Priority: 1] [AppID: DNS] {UDP} <a hr= ef=3D"http://1.1.1.1:53" rel=3D"noreferrer noreferrer" target=3D"_blank">1.= 1.1.1:53</a> -> <a href=3D"http://192.168.17.9:36419" rel=3D"noreferrer = noreferrer" target=3D"_blank">192.168.17.9:36419</a><br> >><br> >> w@w:/var/log/snort$ snort -V<br> >><br> >>=C2=A0 =C2=A0 =C2=A0,,_=C2=A0 =C2=A0 =C2=A0-*> Snort++ <*-<br= > >>=C2=A0 =C2=A0 o"=C2=A0 )~=C2=A0 =C2=A0Version 3.5.2.0<br> >>=C2=A0 =C2=A0 =C2=A0''''=C2=A0 =C2=A0 By Martin Roe= sch & The Snort Team<br> >>=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0<a href=3D"http://s= nort.org/contact#team" rel=3D"noreferrer noreferrer" target=3D"_blank">http= ://snort.org/contact#team</a><br> >>=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0Copyright (C) 2014-= 2024 Cisco and/or its affiliates. All rights reserved.<br> >>=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0Copyright (C) 1998-= 2013 Sourcefire, Inc., et al.<br> >>=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0Using DAQ version 3= .0.17<br> >>=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0Using libpcap versi= on 1.10.4 (with TPACKET_V3)<br> >>=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0Using LuaJIT versio= n 2.1.1703358377<br> >>=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0Using LZMA version = 5.4.5<br> >>=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0Using OpenSSL 3.0.1= 3 30 Jan 2024<br> >>=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0Using PCRE version = 8.45 2021-06-15<br> >>=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0Using ZLIB version = 1.3<br> >><br> >><br> >> Thank you,<br> >><br> >> Wojciech<br> >><br> >><br> >><br> >> _______________________________________________<br> >> Snort-users mailing list<br> >> <a href=3D"mailto:[email protected]" target=3D"_blank" r= el=3D"noreferrer">[email protected]</a><br> >> Go to this URL to change user options or unsubscribe:<br> >> <a href=3D"https://lists.snort.org/mailman/listinfo/snort-users" r= el=3D"noreferrer noreferrer" target=3D"_blank">https://lists.snort.org/mail= man/listinfo/snort-users</a><br> >><br> >>=C2=A0 =C2=A0 =C2=A0 To unsubscribe, send an email to:<br> >>=C2=A0 =C2=A0 =C2=A0 <a href=3D"mailto:[email protected]= t.org" target=3D"_blank" rel=3D"noreferrer">[email protected]= rg</a><br> >><br> >> Please visit <a href=3D"http://blog.snort.org" rel=3D"noreferrer n= oreferrer" target=3D"_blank">http://blog.snort.org</a> to stay current on a= ll the latest Snort news!<br> >><br> >> Please follow these rules: <a href=3D"https://snort.org/faq/what-i= s-the-mailing-list-etiquette" rel=3D"noreferrer noreferrer" target=3D"_blan= k">https://snort.org/faq/what-is-the-mailing-list-etiquette</a><br> _______________________________________________<br> Snort-users mailing list<br> <a href=3D"mailto:[email protected]" target=3D"_blank" rel=3D"nor= eferrer">[email protected]</a><br> Go to this URL to change user options or unsubscribe:<br> <a href=3D"https://lists.snort.org/mailman/listinfo/snort-users" rel=3D"nor= eferrer noreferrer" target=3D"_blank">https://lists.snort.org/mailman/listi= nfo/snort-users</a><br> <br> =C2=A0 =C2=A0 =C2=A0 =C2=A0 To unsubscribe, send an email to:<br> =C2=A0 =C2=A0 =C2=A0 =C2=A0 <a href=3D"mailto:[email protected]= .org" target=3D"_blank" rel=3D"noreferrer">[email protected]= g</a><br> <br> Please visit <a href=3D"http://blog.snort.org" rel=3D"noreferrer noreferrer= " target=3D"_blank">http://blog.snort.org</a> to stay current on all the la= test Snort news!<br> <br> Please follow these rules: <a href=3D"https://snort.org/faq/what-is-the-mai= ling-list-etiquette" rel=3D"noreferrer noreferrer" target=3D"_blank">https:= //snort.org/faq/what-is-the-mailing-list-etiquette</a><br> </blockquote></div> --000000000000cf19ae062b2f5f4b-- --===============6803848377929009724== Content-Type: text/plain; charset="us-ascii" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit Content-Disposition: inline _______________________________________________ Snort-users mailing list [email protected] Go to this URL to change user options or unsubscribe: https://lists.snort.org/mailman/listinfo/snort-users To unsubscribe, send an email to: [email protected] Please visit http://blog.snort.org to stay current on all the latest Snort news! Please follow these rules: https://snort.org/faq/what-is-the-mailing-list-etiquette --===============6803848377929009724==--