Re: LOGS: GIAC GCIA Version 3.4 Practical Detect Roch Decoste

Daniel Wesemann <[email protected]>
Newsgroups gmane.comp.security.intrusions
Message-ID <[email protected]>
>                 DETECT #1:  DNS Named Version Attempt

> sent also appear to be random.  Up to this point there is no evidence of
> scripting involved to conduct these reconnaissance attacks.

hm. but also no evidence to the contrary, or is there? the attacker could
have an unsorted list of DNS servers to check, for example?

> The only discrepancy identified in the analysis of these two packets is
> that they both have the same DNSid of 4660.  Both nslookup and dig

which is indeed "odd"... well spotted.

> b) The attacker is already aware of this network's basic layout

not necessarily, i've seen the same type of lazy scan going simply against
those servers publicly listed as the DNS servers. it's kinda hard to hide
your DNS server :-)

overall, well done!

good luck,
-daniel, gcia

_______________________________________________
Intrusions mailing list
[email protected]
http://www.dshield.org/mailman/listinfo/intrusions
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.