""ET INFO Possible NOP Sled Observed in Large DNS over TCP Packet M2""

SID: 2030525

Revision: 1

Class Type: attempted-admin

Metadata: affected_product Windows_DNS_server, created_at 2020_07_15, performance_impact Significant, signature_severity Informational, tag possible_exploitation, updated_at 2020_07_15

Reference:

Protocol: tcp

Source Network: any

Source Port: 53

Destination Network: any

Destination Port: any

Flow: established,from_server

Contents:

  • Value: "|90 90 90 90 90 90 90 90|"

Within:

PCRE:

Special Options:

  • fast_pattern

source