Snort - the de facto standard for intrusion detection/prevention
next up previous contents
Next: Configuration Up: Preprocessors Previous: Default Configuration from snort.conf   Contents


DNS

The DNS preprocessor decodes DNS Responses and can detect the following exploits: DNS Client RData Overflow, Obsolete Record Types, and Experimental Record Types.

DNS looks are DNS Response traffic over UDP and TCP and it requires Stream preprocessor to be enabled for TCP decoding.



Subsections

Steven Sturges 2007-10-04