Re: LOGS: GIAC GCIA Version 3.4 Practical Detect Roch Decoste

Dana Webber <[email protected]>
Newsgroups gmane.comp.security.intrusions
Message-ID <[email protected]>
What was the attackers OS?

On Monday 30 August 2004 09:44, you wrote:

> msg:"DNS named ver..."   - Title of the alert.
> 3) Probability the source address was spoofed
> ---------------------------------------------
> Very low.  This is a reconnaissance type probe generated using a UDP
> packet.  UDP packets can very easily be spoofed, however should the
> attacker have spoofed the source IP address any responses generated by the
> victim would never be seen by the attacker. Unless, both the recipient and
> the attacker are on the same collision domain.

How do you know that the attacker is not trying to "set up" an innocent person to 
get them in trouble.?

> 4) Description of the attack
> ----------------------------
> The attack consisted of a single UDP packet which queried a DNS server for
> its BIND version.  The same request was sent to two distinct hosts
> approximately 4 minutes apart (refer to section 1B for a detailed view of
> the two packets).  An analysis of the packets did not reveal any
> abnormalities from the IP and UDP headers.  The source IP id and port
> numbers are different in both cases and the absolute time at which the
> packets were sent also appear to be random.  Up to this point there is no
> evidence of scripting involved to conduct these reconnaissance attacks.
>
> The only discrepancy identified in the analysis of these two packets is
> that they both have the same DNSid of 4660.  Both nslookup and dig
> utilities were thoroughly tested in a lab network in an effort to recreate
> these packet anomalies, however none of these had the functionality to
> allow a user to specify a DNSid number.
>
> A very interesting tool was uncovered during the research phase of this
> detect.  NETWOX, authored by Laurent Constantin, is a toolset providing
> over 150 amalgamated utilities to help resolve network problems.  One of
> the tools enabled users to obtain a BIND DNS server's version number.  It
> allowed the user to specify values for a multitude of fields in the DNS
> query packet, however it did not provide the ability to specify a DNSid.
>
> When tested in a lab environment NETWOX behaved in the same fashion as dig
> and nslookup.  It did not leave any distinguishable fingerprints The DNSid
> value (4660) has also been identified in many other binary log files made
> available on the SANS website.  I spent quite a bit of time researching
> this oddity, unfortunately the only information which could be found where
> past GCIA detects posing the same question.  The following links point to
> GCIA detects produced by Kahleong Fong and Steve Gamble, both of which
> encountered the same question, 'why is the DNSid set to 4660 for multiple
> BIND version queries?':
> http://www.dshield.org/pipermail/intrusions/2003-March/007104.php
> http://cert.uni-stuttgart.de/archive/intrusions/2003/07/msg00273.html

What about hping2 ?

-- 
Dana Webber
[email protected]
http://dunrobin.dyn.dhs.org

Getting a computer system to work is like banging your head against a brick wall until the wall falls down. 

_______________________________________________
Intrusions mailing list
[email protected]
http://www.dshield.org/mailman/listinfo/intrusions
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.