Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Passivedns dos not log large TXT records #131

Open
rvaglid opened this issue May 25, 2023 · 0 comments
Open

Passivedns dos not log large TXT records #131

rvaglid opened this issue May 25, 2023 · 0 comments

Comments

@rvaglid
Copy link

rvaglid commented May 25, 2023

We are testing some Splunk detections and it seems that large TXT-records are not logged at all by passivedns.

The following TXT-records is 2048 chars, which is the max for a TXT record.
$ nslookup -q=TXT mobydick.vaglid.net

The DNS reply gets split into different strings as expected both by Windows and Linux resolvers, but no logs appear in the passivedns logs.

The following TXT-record is 277 chars. For this DNS reply the first 256 chars gets logged by passivedns, but not the second segment.
$nslookup -q=TXT txttest.vaglid.net

[*] PassiveDNS 1.2.0
[*] By Edward Bjarte Fjellskål <[email protected]>
[*] Using libpcap version 1.5.3
[*] Using ldns version 1.6.16

Cheers,
Rolf

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant