#alert udp 61.63.0.0/16 any -> $HOME_NET 53:2048 (msg: "BLEEDING-EDGE CURRENT EVENTS Possible Unknown MS DNS exploit udp - Please report any hits to
bleeding@bleedingthreats.net"; reference:url,www.dshield.org/diary.html?storyid=2584; classtype:attempted-admin; sid:2003539; rev:3;)
Added 2007-04-10 10:15:37 UTC
No new information yet. Thanks for the reports so far. If you get something that looks like more than a regular dns query please let us know.
--
MattJonkman - 10 Apr 2007
alert udp 61.63.0.0/16 any -> $HOME_NET 53:2048 (msg: "BLEEDING-EDGE CURRENT EVENTS Possible Unknown MS DNS exploit udp - Please report any hits to
bleeding@bleedingthreats.net"; reference:url,www.dshield.org/diary.html?storyid=2584; classtype:attempted-admin; sid:2003539; rev:3;)
Added 2007-04-07 18:15:19 UTC
alert udp 61.63.0.0/16 any -> $HOME_NET 53 (msg: "BLEEDING-EDGE CURRENT EVENTS Possible Unknown MS DNS exploit - Please report any hits to
bleeding@bleedingthreats.net"; reference:url,www.dshield.org/diary.html?storyid=2584; classtype:attempted-admin; sid:2003539; rev:2;)
Added 2007-04-07 09:45:17 UTC
alert udp 61.63.0.0/18 any -> $HOME_NET 53 (msg: "BLEEDING-EDGE CURRENT EVENTS Possible Unknown MS DNS exploit - Please report any hits to
bleeding@bleedingthreats.net"; reference:url,www.dshield.org/diary.html?storyid=2584; classtype:attempted-admin; sid:2003539; rev:1;)
Added 2007-04-07 09:00:20 UTC