Mailing List Archive


[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

[tlug] DNS zone transfer



I'm getting the following logs from snort every 5 minutes. This all started
about 3 days ago.  

Jan 30 11:44:02 mick snort: [1:255:2] DNS zone transfer [Classification:
Attempted Information Leak] [Priority: 2]: {TCP} x.x.x.x:2310 -> y.y.y.y:53
Jan 30 11:48:59 mick snort: [1:255:2] DNS zone transfer [Classification:
Attempted Information Leak] [Priority: 2]: {TCP} x.x.x.x:2313 -> y.y.y.y:53

Both the target and source have NS services running. I don't see why the above
should be considered bad or harmful. 
Could someone enlighten me before I disable this snort rule?


Home | Main Index | Thread Index

Home Page Mailing List Linux and Japan TLUG Members Links