Re: DNS Spoof query

2009-08-08 Thread Florian Weimer
* Daniel D. Jones: > After doing that, my Snort report from my Debian server started > showing the following: > > 62 192.168.2.10 209.170.146.89 DNS SPOOF query response with TTL of 1 > min. and no authority This Snort rule appears to be complete bogus. -- To UNSUBS

DNS Spoof query

2009-07-26 Thread Daniel D Jones
arted showing the following: 62 192.168.2.10 209.170.146.89 DNS SPOOF query response with TTL of 1 min. and no authority I'm trying to figure out if this is a false positive, a misconfiguration on my DNS server, or a sign of possible compromise. -- To UNSUBSCRIBE, email to debian