Bad DNS protocol


Description   The Firewall has detected incorrect usage of the DNS protocol.
     
Details   The DNS protocol operates according to standards defined in the RFCs. Invalid use of this protocol will set off an alarm.

If this alarm is configured as pass and if a packet that triggers the alarms is received, the corresponding plugin will detach from the connection and no further protocol analysis will be performed.
     
Triggering conditions   A packet containing invalid use of the DNS protocol has been detected.
     
Complements   The context of the "Bad DNS protocol" alarm is detailed by the following additional messages :

"Packet too short" The analyzed packet is smaller than it should be judging by its contents.

"invalid opcode" The packet's operation code is invalid.

"maximum pipelined request reached" More than 16 consecutive requests without any reply have been seen on the same UDP pseudo-connection. In many cases this alarm is raised when a DNS server doesn't reply or reply really too slowly (> 3sec).

"invalid return code" The DNS return code is invalid.

"invalid char found in domain name" The domain name contains a character not allowed by the RFC.

"response from client" A response has been sent by the client without any query received before.

"query from server" The server has replied to a query packet with another query packet.

"emule" This is a valid DNS communication but the edonkey/emule protocol running on port 53.

"domain name must be empty in EDNS" Domain name field must be empty in EDNS (root label).

"TCP not UDP" TCP used where UDP was expected.
     
References  
     
Available since   ASQ v3.2.0
     
Protects   Microsoft Exchange and Windows SMTP Service Vulnerabilities (MS10-024)
     
Last 100 CVE   CVE-2010-0025
CVE-2010-0024


 
 
 
 
 Action 
Block


 Alarm level 
Major