
Zeek-Paket zur Erkennung von Exploit-Versuchen für CVE-2020-1350 (SIGRed) gegen Windows-DNS-Server durch Analyse großer DNS-SIG/KEY-Antworten mit konfigurierbaren Genauigkeitsstufen.
Ein Zeek-Paket zur Erkennung von Versuchen, den Microsoft Windows-DNS-Server über CVE-2020-1350 (auch bekannt als SIGRed – CVE-Score von 10.0) auszunutzen.
https://research.checkpoint.com/2020/resolving-your-way-into-domain-admin-exploiting-a-17-year-old-bug-in-windows-dns-servers/
https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2020-1350
https://cve.mitre.org/cgi-bin/cvename.cgi?name=ALAS-2020-1350
| Notice | Zuverlässigkeit |
|---|
| CVE_2020_1350::CVE_2020_1350_Detected_High_Confidence CVE-2020-1350 Windows-DNS-Exploit (CVE10) wurde erkannt (hohe Konfidenz, große SIG/KEY-Antwort). Siehe Links: https://cve.mitre.org/cgi-bin/cvename.cgi?name=ALAS-2020-1350 und https://research.checkpoint.com/2020/resolving-your-way-into-domain-admin-exploiting-a-17-year-old-bug-in-windows-dns-servers/ | Hoch |
| Es wurde ein potenzieller CVE-2020-1350 Windows-DNS-Exploit (CVE10) erkannt (große DNS-RRSIG/TKEY-Antwort). Siehe Links: https://cve.mitre.org/cgi-bin/cvename.cgi?name=ALAS-2020-1350 und https://research.checkpoint.com/2020/resolving-your-way-into-domain-admin-exploiting-a-17-year-old-bug-in-windows-dns-servers/ | Mittel/Hoch |
| Es wurde ein potenzieller CVE-2020-1350 Windows-DNS-Exploit (CVE10) erkannt (große DNS-Antwort). Siehe Links: https://cve.mitre.org/cgi-bin/cvename.cgi?name=ALAS-2020-1350 und https://research.checkpoint.com/2020/resolving-your-way-into-domain-admin-exploiting-a-17-year-old-bug-in-windows-dns-servers/ | Mittel/Hoch |
Standardmäßig sind alle Notices aktiviert. Wenn Sie jedoch nur die Notice mit hoher Zuverlässigkeit aktivieren möchten (aufgrund von Rauschen/Performance oder anderen Gründen), können Sie die Option in scripts/CVE-2020-1350.zeek auf True ändern, d. h. option only_enable_high_fidelity_notice: bool = T;