alert udp any 53 -> $HOME_NET any (msg:"ET CURRENT_EVENTS Excessive NXDOMAIN Responses (not authoritative)"; byte_test:1,&,128,2; byte_test:1,&,3, 1,relative; threshold: type both, track by_src, count 100, seconds 10; classtype:bad-unknown; sid:2008466; rev:8;)

Added 2008-07-24 11:52:36 UTC


alert udp any 53 -> $HOME_NET any (msg:"ET CURRENT_EVENTS Excessive NXDOMAIN Responses (not authoritative)"; byte_test:1,&,128,2; byte_test:1,&,3, 1,relative; threshold: type both, track by_src, count 100, seconds 10; classtype:bad-unknown; sid:2008466; rev:8;)

Added 2008-07-24 11:52:36 UTC


alert udp any 53 -> $HOME_NET any (msg:"ET CURRENT_EVENTS Excessive NXDOMAIN Responses"; content:"|81 83|"; offset:2; depth:4; threshold: type both, track by_src, count 100, seconds 10; classtype:bad-unknown; sid:2008466; rev:7;)

Added 2008-07-24 11:44:46 UTC


alert udp any 53 -> $HOME_NET any (msg:"ET CURRENT_EVENTS Excessive NXDOMAIN Responses"; content:"|81 83|"; offset:2; depth:4; threshold: type both, track by_src, count 100, seconds 10; classtype:bad-unknown; sid:2008466; rev:7;)

Added 2008-07-24 11:44:46 UTC


alert udp any 53 -> $HOME_NET any (msg:"ET CURRENT_EVENTS Excessive NXDOMAIN Responses"; content:"|81 83|"; offset:2; depth:4; threshold: type both, track by_dst, count 100, seconds 10; classtype:bad-unknown; sid:2008466; rev:7;)

Added 2008-07-24 11:43:47 UTC


alert udp any 53 -> $HOME_NET any (msg:"ET CURRENT_EVENTS Excessive NXDOMAIN Responses"; content:"|81 83|"; offset:2; depth:4; threshold: type both, track by_dst, count 100, seconds 10; classtype:bad-unknown; sid:2008466; rev:7;)

Added 2008-07-24 11:43:47 UTC


alert udp any 53 -> $HOME_NET any (msg:"ET CURRENT_EVENTS Excessive NXDOMAIN Responses"; byte_test: 1, &, 128, 2; byte_test: 1, &, 3, 1,relative; threshold: type both, track by_dst, count 100, seconds 5; classtype:bad-unknown; sid:2008466; rev:6;)

Added 2008-07-24 10:24:49 UTC


alert udp any 53 -> $HOME_NET any (msg:"ET CURRENT_EVENTS Excessive NXDOMAIN Responses"; byte_test: 1, &, 128, 2; byte_test: 1, &, 3, 1,relative; threshold: type both, track by_dst, count 100, seconds 5; classtype:bad-unknown; sid:2008466; rev:6;)

Added 2008-07-24 10:24:49 UTC


alert udp any 53 -> $HOME_NET any (msg:"ET CURRENT_EVENTS Excessive NXDOMAIN Responses"; byte_test: 1, &, 128, 2; byte_test: 1, &, 3, 1,relative; threshold: type both, track by_dst, count 100, seconds 5; sid:2008466; rev:3;)

Added 2008-07-24 09:22:27 UTC


alert udp any 53 -> $HOME_NET any (msg:"ET CURRENT_EVENTS Excessive NXDOMAIN Responses"; byte_test: 1, &, 128, 2; byte_test: 1, &, 3, 1,relative; threshold: type both, track by_dst, count 100, seconds 5; sid:2008466; rev:3;)

Added 2008-07-24 09:22:27 UTC


alert udp any any -> $HOME_NET 53 (msg:"ET CURRENT_EVENTS Excessive NXDOMAIN Responses"; byte_test: 1, &, 128, 2; byte_test: 1, &, 3, 1,relative; threshold: type both, track by_dst, count 100, seconds 5; sid:2008466; rev:2;)

Added 2008-07-24 09:00:21 UTC


alert udp any any -> $HOME_NET 53 (msg:"ET CURRENT_EVENTS Excessive NXDOMAIN Responses"; byte_test: 1, &, 128, 2; byte_test: 1, &, 3, 1,relative; threshold: type both, track by_dst, count 100, seconds 5; sid:2008466; rev:2;)

Added 2008-07-24 09:00:21 UTC


alert udp $EXTERNAL_NET any -> $HOME_NET 53 (msg:"ET CURRENT_EVENTS Excessive NXDOMAIN Responses"; byte_test: 1, &, 128, 2; byte_test: 1, &, 3, 1,relative; threshold: type both, track by_dst, count 100, seconds 5; sid:2008466; rev:1;)

Added 2008-07-24 08:00:23 UTC


Topic revision: r1 - 2008-07-24 - TWikiGuest
 
This site is powered by the TWiki collaboration platform Powered by Perl This site is powered by the TWiki collaboration platformCopyright © Emerging Threats