next up previous contents
Next: Configuration Up: Preprocessors Previous: Example Configuration from snort.conf   Contents


The DNS preprocessor decodes DNS Responses and can detect the following exploits: DNS Client RData Overflow, Obsolete Record Types, and Experimental Record Types.

DNS looks at DNS Response traffic over UDP and TCP and it requires Stream preprocessor to be enabled for TCP decoding.


Eugene Misnik 2013-05-08