lists.openwall.net   lists  /  announce  owl-users  owl-dev  john-users  john-dev  passwdqc-users  yescrypt  popa3d-users  /  oss-security  kernel-hardening  musl  sabotage  tlsify  passwords  /  crypt-dev  xvendor  /  Bugtraq  Full-Disclosure  linux-kernel  linux-netdev  linux-ext4  linux-hardening  linux-cve-announce  PHC 
Open Source and information security mailing list archives
 
Hash Suite: Windows password security audit tool. GUI, reports in PDF.
[<prev] [next>] [<thread-prev] [thread-next>] [day] [month] [year] [list]
Message-ID: <590053051.1065208060@[192.168.2.119]>
From: pauls at utdallas.edu (Paul Schmehl)
Subject: [Snort-sigs] Re: Mystery DNS Changes

--On Thursday, October 02, 2003 6:29 AM -0500 Paul Tinsley 
<pdt@...khammer.org> wrote:

> Someone brought to my attention that I neglected udp (thank you Adam),
> sorry about that I was in a hurry when I posted this, there is another
> just like the tcp one that says udp :)  Both are being triggered by the
> clients affected as one would expect, so for full coverage, do both.

Wouldn't it make more sense to use:

alert ip $HOME_NET any > $MAL_DNS 53 blah, blah, blah....instead of having 
two rules?

(That's what I'm using, and it's working fine.)

Paul Schmehl (pauls@...allas.edu)
Adjunct Information Security Officer
The University of Texas at Dallas
AVIEN Founding Member
http://www.utdallas.edu


Powered by blists - more mailing lists

Powered by Openwall GNU/*/Linux Powered by OpenVZ