This application requires Javascript for optimal performance.

oversized_msg

Alias(es)

DNS.Oversized.Message

Release Date

Sep 11, 2006

Severity

low

Impact

This is an anomaly, which may indicate potential attack attempts.

Description

This signature indicates a DNS protocol anomaly. It indicates detection of an oversized Domain Name Service (DNS) message.

DNS is a system that translates between human-readable host or domain names (e.g. www.fortinet.com) and machine-understandable Internet Protocol addresses. RFC 1035 specifies that the maximum size of a DNS message should not exceed 512 bytes.

Affected Products

Any unprotected DNS server may be vulnerable.

Recommended Actions

N/A

Coverage

IPS
VCM

Reference/s

http://www.faqs.org/rfcs/rfc1035.html

Reference: VID-13091