Feature #2198
open
Extend the DNS parser to accept dns_response keyword in signatures
Added by Anonymous over 7 years ago.
Updated over 5 years ago.
Description
For A and AAAA records it would be interesting to match on the IP received from the DNS resolver.
In particular this could be useful to check for potentially sink-holed domains.
Related issues
1 (1 open — 0 closed)
- Tracker changed from Bug to Feature
- Target version changed from 70 to TBD
Since you assigned yourself, do you want to submit that?
Andreas Herz wrote:
Since you assigned yourself, do you want to submit that?
Yes, it is in the pipeline.
Do you want me to focus on a Rust implentation?
Depends on what you prefer, IMHO it would be nice to have it in Rust.
- Related to Feature #2448: Add additional buffers for DNS Responses added
- Assignee changed from Anonymous to Stian Bergseth
- Assignee changed from Stian Bergseth to Community Ticket
Also available in: Atom
PDF