Re: LOGS: GIAC GCIA Version 3.4 Practical Detect Roch Decoste
Dana Webber <[email protected]>
| Newsgroups | gmane.comp.security.intrusions |
|---|---|
| Message-ID | <[email protected]> |
What was the attackers OS? On Monday 30 August 2004 09:44, you wrote: > msg:"DNS named ver..." - Title of the alert. > 3) Probability the source address was spoofed > --------------------------------------------- > Very low. This is a reconnaissance type probe generated using a UDP > packet. UDP packets can very easily be spoofed, however should the > attacker have spoofed the source IP address any responses generated by the > victim would never be seen by the attacker. Unless, both the recipient and > the attacker are on the same collision domain. How do you know that the attacker is not trying to "set up" an innocent person to get them in trouble.? > 4) Description of the attack > ---------------------------- > The attack consisted of a single UDP packet which queried a DNS server for > its BIND version. The same request was sent to two distinct hosts > approximately 4 minutes apart (refer to section 1B for a detailed view of > the two packets). An analysis of the packets did not reveal any > abnormalities from the IP and UDP headers. The source IP id and port > numbers are different in both cases and the absolute time at which the > packets were sent also appear to be random. Up to this point there is no > evidence of scripting involved to conduct these reconnaissance attacks. > > The only discrepancy identified in the analysis of these two packets is > that they both have the same DNSid of 4660. Both nslookup and dig > utilities were thoroughly tested in a lab network in an effort to recreate > these packet anomalies, however none of these had the functionality to > allow a user to specify a DNSid number. > > A very interesting tool was uncovered during the research phase of this > detect. NETWOX, authored by Laurent Constantin, is a toolset providing > over 150 amalgamated utilities to help resolve network problems. One of > the tools enabled users to obtain a BIND DNS server's version number. It > allowed the user to specify values for a multitude of fields in the DNS > query packet, however it did not provide the ability to specify a DNSid. > > When tested in a lab environment NETWOX behaved in the same fashion as dig > and nslookup. It did not leave any distinguishable fingerprints The DNSid > value (4660) has also been identified in many other binary log files made > available on the SANS website. I spent quite a bit of time researching > this oddity, unfortunately the only information which could be found where > past GCIA detects posing the same question. The following links point to > GCIA detects produced by Kahleong Fong and Steve Gamble, both of which > encountered the same question, 'why is the DNSid set to 4660 for multiple > BIND version queries?': > http://www.dshield.org/pipermail/intrusions/2003-March/007104.php > http://cert.uni-stuttgart.de/archive/intrusions/2003/07/msg00273.html What about hping2 ? -- Dana Webber [email protected] http://dunrobin.dyn.dhs.org Getting a computer system to work is like banging your head against a brick wall until the wall falls down. _______________________________________________ Intrusions mailing list [email protected] http://www.dshield.org/mailman/listinfo/intrusions