""ET INFO Possible NOP Sled Observed in Large DNS over TCP Packet M1""

SID: 2030524

Revision: 1

Class Type: attempted-admin

Metadata: affected_product Windows_DNS_server, created_at 2020_07_15, performance_impact Significant, signature_severity Informational, tag possible_exploitation, updated_at 2020_07_15

Reference:

Protocol: tcp

Source Network: any

Source Port: any

Destination Network: any

Destination Port: 53

Flow: established,to_server

Contents:

  • Value: "|90 90 90 90 90 90 90 90|"

Within:

PCRE:

Special Options:

  • fast_pattern

source