Forum Discussion
DNS logging profile - response OK but query are empty
Hi Nathan,
thx for your answer. The setting was already enabled ../
2018-12-11 12:55:20 xxx qid 3880 to 10.61996: [NOERROR qr,rd,ra,do] response: insights.nutanix.com. 300 IN A 206.169.130.226; 2018-12-11 12:55:20 xxx qid 3880 from 10.061996: view none: query: null invalid invalid + (10.%0)
I can anyway 'correlate' query and response via the QID. But I'm still wondering if it will work in case of attempts of data exfiltration via DNS, when an answer is not needed (if you query thisisthedataiwanttoexfiltrate.mydomainonlyusedtologdnsquery.com for example).
I made an attempts to a non existing subdomain of an existing domain. The response with nxdomain is not logged :(
Br,
Ben
Help guide the future of your DevCentral Community!
What tools do you use to collaborate? (1min - anonymous)Recent Discussions
Related Content
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com
