Re: LOGS: GIAC GCIA Version 3.4 Practical Detect Roch Decoste
Daniel Wesemann <[email protected]>
| Newsgroups | gmane.comp.security.intrusions |
|---|---|
| Message-ID | <[email protected]> |
> DETECT #1: DNS Named Version Attempt > sent also appear to be random. Up to this point there is no evidence of > scripting involved to conduct these reconnaissance attacks. hm. but also no evidence to the contrary, or is there? the attacker could have an unsorted list of DNS servers to check, for example? > The only discrepancy identified in the analysis of these two packets is > that they both have the same DNSid of 4660. Both nslookup and dig which is indeed "odd"... well spotted. > b) The attacker is already aware of this network's basic layout not necessarily, i've seen the same type of lazy scan going simply against those servers publicly listed as the DNS servers. it's kinda hard to hide your DNS server :-) overall, well done! good luck, -daniel, gcia _______________________________________________ Intrusions mailing list [email protected] http://www.dshield.org/mailman/listinfo/intrusions