Re: DNS Cache Poisoning attack

Joel Esler <[email protected]>
Newsgroups gmane.comp.security.ids
Message-ID <[email protected]>
There are Shared Object rules available for the DNS Cache Poisoning  
attack that are VRT certified available via subscription at www.snort.org 
.

J

On Jul 16, 2008, at 10:38 PM, Ravi Chunduru wrote:

> Does anybody have snort or Intrupro-IPS signature(s) to detect DNS
> Cache Poisoning attack?
> Also, is there any PoC to simulate the attack and test the
> effectiveness of signature(s)?
>
> thanks
> Ravi
>
> ------------------------------------------------------------------------
> Test Your IDS
>
> Is your IDS deployed correctly?
> Find out quickly and easily by testing it
> with real-world attacks from CORE IMPACT.
> Go to http://www.coresecurity.com/index.php5?module=Form&action=impact&campaign=intro_sfw
> to learn more.
> ------------------------------------------------------------------------
>


------------------------------------------------------------------------
Test Your IDS

Is your IDS deployed correctly?
Find out quickly and easily by testing it 
with real-world attacks from CORE IMPACT.
Go to http://www.coresecurity.com/index.php5?module=Form&action=impact&campaign=intro_sfw 
to learn more.
------------------------------------------------------------------------
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.