The following are DNS attack signatures:
- 6050—-DNS HINFO Request (severity
3, access): This signature is triggered by an attempt to access
HINFO records from a DNS server. The Domain Name Service (DNS)
includes an optional record type that allows for system
information to be recorded and retrieved. This information typically includes the OS and hardware platform for the system.
There is very little utility in including this record
in the database, and it provides attackers with valuable targeting
information. It is suggested that this record not be included in
your DNS database for this reason. This is indicative that your
network may be under reconnaissance.
- 6051—DNS Zone Transfer Request
(severity 1, information): This signature is triggered by normal
DNS zone transfers, in which the source port is 53. Zone transfers
are the method by which secondary DNS servers update their DNS
records. All DNS records are transferred at once from the primary
to secondary server. This transfers records only for the zone
specified. This is indicative that your network may be under
reconnaissance.
- 6052—DNS Zone Transfer from other
port (severity 5, reconnaissance): This signature is triggered by
an illegitimate DNS zone transfer, in which the source port is not
equal to 53. Zone transfers are the method by which secondary DNS
servers update their DNS records. All DNS records are transferred
at once from the primary to secondary server. This transfers
records only for the zone specified. Because of the access method
this is indicative that your network most probably is under
reconnaissance. This may be the prelude to more serious attacks.
- 6053—DNS request for all records
(severity 3, access): This signature is triggered by a DNS request
for all records. This is similar to a zone transfer in that it provides a method for transferring DNS records from a server to another requesting host.
The primary difference is that all DNS records are transferred, not just those specific to a particular zone.
This
is indicative that your network may be under reconnaissance.
- 6054—DNS Version Request (severity
3, informational): This alarm triggers when a request for the
version of a DNS server is detected. Numerous versions of the
popular BIND DNS server contain buffer overflow vulnerabilities,
and scanners have been written to detect the presence of
vulnerable DNS servers.
- 6055—DNS Inverse Query Buffer
Overflow (severity 5, access): This alarm triggers when an IQUERY
request arrives with a data section that is larger than 255
characters.
- 6056—BIND NXT Buffer Overflow
(severity 5, access): This alarm triggers when a DNS server
response arrives that has a long NXT resource where the length of
the resource data is greater than 2069 bytes OR the length of the
TCP stream containing the NXT resource is greater than 3000 bytes.
- 6057—BIND SIG Buffer Overflow
(severity 5, access): This alarm triggers when a DNS server
response arrives that has a long SIG resource where the length of
the resource data is greater than 2069 bytes OR the length of the
TCP stream containing the SIG resource is greater than 3000 bytes.
|
|