OZYMAN-DNS-TUNNEL

This signature detects an Ozyman DNS tunnel that is used to tunnel traffic through DNS requests.

Short Name
OZYMAN-DNS-TUNNEL
Category
Remote-Access
SubCategory
Tunneling
Risk
5
Release Date
1999-12-31
Supported Platforms

Available to all SRX running 12.3X48+

Available to all MX running 20.2R1+

Available to all vSRX running 20.3R1+

Port
UDP/80,TCP/102,UDP/53,UDP/554,TCP/995,TCP/443,UDP/5060,TCP/80,TCP/554,TCP/587,TCP/5060,TCP/53,3128,UDP/443,TCP/465,8000,TCP/993,TCP/1080,8080
Application Group
junos-approot:applications:remote-access:tunneling

Found a potential security threat?