
Détection de tentatives d'exploitation du serveur DNS Microsoft Windows via CVE-2020-1350 (alias SIGRed)
Un paquet Zeek pour la détection des tentatives d'exploitation du serveur DNS Microsoft Windows via CVE-2020-1350 (AKA SIGRed - score CVE de 10.0)
https://research.checkpoint.com/2020/resolving-your-way-into-domain-admin-exploiting-a-17-year-old-bug-in-windows-dns-servers/
https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2020-1350
https://cve.mitre.org/cgi-bin/cvename.cgi?name=ALAS-2020-1350
Par défaut, toutes les notifications sont activées. Cependant, si vous souhaitez n'activer que la notification haute fidélité (en raison du bruit/des performances ou d'autres raisons), vous pouvez modifier l'option dans scripts/CVE-2020-1350.zeek sur True, c'est-à-dire option only_enable_high_fidelity_notice: bool = T;