Project

General

Profile

Actions

Feature #1158

closed

Parser DNS TXT data parsing and logging

Added by Christie Bunlon over 10 years ago. Updated over 10 years ago.

Status:
Closed
Priority:
Normal
Assignee:
Target version:
Effort:
Difficulty:
Label:

Description

I am trying to detect DNS Tunneling.
For this I use the DNS logger in Suricata 2.0.
But when TXT answers have lot of data, the DNS logger say '<no data>'.


Files

dns.log (45 KB) dns.log Log DNS trafic Christie Bunlon, 04/01/2014 04:06 AM
90dns22.pcap (30.7 KB) 90dns22.pcap DNS Tunneling Trafic Christie Bunlon, 04/01/2014 04:06 AM
Actions #1

Updated by Christie Bunlon over 10 years ago

Sorry is not the parser but the DNS logger.

Actions #2

Updated by Victor Julien over 10 years ago

  • Status changed from New to Assigned
  • Assignee set to Victor Julien
  • Target version set to 2.0.1rc1

I think this is only matter of extending the dns loggers. If it turns out to be more involved it will likely go into 2.1.

Actions #3

Updated by Victor Julien over 10 years ago

  • Target version changed from 2.0.1rc1 to 2.0.2
Actions #4

Updated by Victor Julien over 10 years ago

  • % Done changed from 0 to 50
Actions #5

Updated by Victor Julien over 10 years ago

  • Tracker changed from Bug to Feature
  • Subject changed from Parser DNS no parsing TXT data to Parser DNS TXT data parsing and logging
Actions #6

Updated by Christie Bunlon over 10 years ago

I have tested it but it seems still not working,saying again <no data> with 90dns22.pcap

Actions #7

Updated by Victor Julien over 10 years ago

I'm not getting any 'no data' with this branch, are you sure you tested the branch from pull request 967?

Actions #8

Updated by Christie Bunlon over 10 years ago

Sorry, i made a mistake with my suricata.

It's logging correctly the answers now.

Thank you for your help. You can close the ticket. :)

Actions #9

Updated by Victor Julien over 10 years ago

  • Status changed from Assigned to Closed
  • % Done changed from 50 to 100
Actions

Also available in: Atom PDF