6.7 6000 Series—Cross-Protocol Signatures
6.7.3 DNS attack signatures
The following are DNS attack signatures:
  • 6050—-DNS HINFO Request (severity 3, access): This signature is triggered by an attempt to access HINFO records from a DNS server. The Domain Name Service (DNS) includes an optional record type that allows for system information to be recorded and retrieved. This information typically includes the OS and hardware platform for the system. There is very little utility in including this record in the database, and it provides attackers with valuable targeting information. It is suggested that this record not be included in your DNS database for this reason. This is indicative that your network may be under reconnaissance.
  • 6051—DNS Zone Transfer Request (severity 1, information): This signature is triggered by normal DNS zone transfers, in which the source port is 53. Zone transfers are the method by which secondary DNS servers update their DNS records. All DNS records are transferred at once from the primary to secondary server. This transfers records only for the zone specified. This is indicative that your network may be under reconnaissance.
  • 6052—DNS Zone Transfer from other port (severity 5, reconnaissance): This signature is triggered by an illegitimate DNS zone transfer, in which the source port is not equal to 53. Zone transfers are the method by which secondary DNS servers update their DNS records. All DNS records are transferred at once from the primary to secondary server. This transfers records only for the zone specified. Because of the access method this is indicative that your network most probably is under reconnaissance. This may be the prelude to more serious attacks.
  • 6053—DNS request for all records (severity 3, access): This signature is triggered by a DNS request for all records. This is similar to a zone transfer in that it provides a method for transferring DNS records from a server to another requesting host. The primary difference is that all DNS records are transferred, not just those specific to a particular zone. This is indicative that your network may be under reconnaissance.
  • 6054—DNS Version Request (severity 3, informational): This alarm triggers when a request for the version of a DNS server is detected. Numerous versions of the popular BIND DNS server contain buffer overflow vulnerabilities, and scanners have been written to detect the presence of vulnerable DNS servers.
  • 6055—DNS Inverse Query Buffer Overflow (severity 5, access): This alarm triggers when an IQUERY request arrives with a data section that is larger than 255 characters.
  • 6056—BIND NXT Buffer Overflow (severity 5, access): This alarm triggers when a DNS server response arrives that has a long NXT resource where the length of the resource data is greater than 2069 bytes OR the length of the TCP stream containing the NXT resource is greater than 3000 bytes.
  • 6057—BIND SIG Buffer Overflow (severity 5, access): This alarm triggers when a DNS server response arrives that has a long SIG resource where the length of the resource data is greater than 2069 bytes OR the length of the TCP stream containing the SIG resource is greater than 3000 bytes.