
Zeek 패키지: CVE-2020-1350 (SIGRed) Windows DNS 서버 익스플로잇 시도를 대규모 DNS SIG/KEY 응답 분석을 통해 탐지하며, 구성 가능한 정밀도 수준을 제공합니다.
Microsoft Windows DNS 서버의 취약점 CVE-2020-1350(일명 SIGRed - CVSS 점수 10.0) 악용 시도를 탐지하기 위한 Zeek 패키지
https://research.checkpoint.com/2020/resolving-your-way-into-domain-admin-exploiting-a-17-year-old-bug-in-windows-dns-servers/
https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2020-1350
https://cve.mitre.org/cgi-bin/cvename.cgi?name=ALAS-2020-1350
| 알림 | 신뢰도 |
|---|---|
| CVE_2020_1350::CVE_2020_1350_Detected_High_Confidence CVE-2020-1350 Windows DNS 악용 (CVE10)이 탐지되었습니다 (High Confidence, 대용량 SIG/KEY 응답) 참고 링크: https://cve.mitre.org/cgi-bin/cvename.cgi?name=ALAS-2020-1350 및 https://research.checkpoint.com/2020/resolving-your-way-into-domain-admin-exploiting-a-17-year-old-bug-in-windows-dns-servers/ | High |
| 잠재적 CVE-2020-1350 Windows DNS 악용 (CVE10)이 탐지되었습니다 (대용량 DNS RRSIG/TKEY 응답). 참고 링크: https://cve.mitre.org/cgi-bin/cvename.cgi?name=ALAS-2020-1350 및 https://research.checkpoint.com/2020/resolving-your-way-into-domain-admin-exploiting-a-17-year-old-bug-in-windows-dns-servers/ | Medium/High |
| 잠재적 CVE-2020-1350 Windows DNS 악용 (CVE10)이 탐지되었습니다 (대용량 DNS 응답). 참고 링크: https://cve.mitre.org/cgi-bin/cvename.cgi?name=ALAS-2020-1350 및 https://research.checkpoint.com/2020/resolving-your-way-into-domain-admin-exploiting-a-17-year-old-bug-in-windows-dns-servers/ | Medium/High |
기본적으로 모든 알림이 활성화되어 있지만, 노이즈/성능 등의 이유로 High Fidelity 알림만 활성화하려면 scripts/CVE-2020-1350.zeek에서 옵션을 True로 변경할 수 있습니다. 즉 option only_enable_high_fidelity_notice: bool = T;