|
|||||||||||
|
RE: [Snort-sigs] Issue with rule sid 255
From: Geoff Craig <GCraig(at)quilogy.com>
Date: Fri Apr 25 2003 - 09:53:43 EDT
Attached are two windump files (I set the snaplen to 1500). I totally agree with you in that the offset should work, but we are talking MS DNS servers here. *wink* PS The dumps are from a lab so you will see IP's etc.
-----Original Message-----
On Tue, Apr 22, 2003 at 10:50:08AM -0500, Geoff Craig wrote:
Can you send pcap for that? IFAIK, the zone transfer query type should actually be at least 16 bytes from the beginning of the packet. 2 bytes (length) + 2 bytes (transaction id) + 2 bytes (flags) + 2 bytes (questions) + 2 bytes (answer RRs) + 2 bytes (authority RRs) + 2 bytes (additional RRs) + 1 byte (count for the first label) [0]
We look for the label terminating byte (0x00) followed by the AXFR
request
Can you send me pcap for what this does? [0] since this is a zone transfer, they have to ask for the zone, so we know there is going to be at least one label. -brian This sf.net email is sponsored by:ThinkGeek Welcome to geek heaven. http://thinkgeek.com/sf Snort-sigs mailing list Snort-sigs@lists.sourceforge.net https://lists.sourceforge.net/lists/listinfo/snort-sigsReceived on Fri Apr 25 10:32:50 2003 This archive was generated by hypermail 2.1.8 : Wed Aug 23 2006 - 14:08:27 EDT |
||||||||||
|
|||||||||||