alert tcp any any -> $HOME_NET 445 (
msg:"ET NETBIOS Microsoft Windows NETAPI Stack Overflow Inbound - MS08-067 - Known Exploit Instance (2)";
flow:established,to_server;
content:"|00 2e 00 2e 00 2f 00 2e 00 2e 00 2f 00 30 30 30 30 30 30 30 30 30 30 30 30 30 30 30 30 30 30 87|";
reference:url,www.microsoft.com/technet/security/Bulletin/MS08-067.mspx;
reference:cve,2008-4250;
reference:url,www.kb.cert.org/vuls/id/827267;
classtype:attempted-admin;
sid:2008721; rev:5;
metadata:created_at 2010_07_30, cve CVE_2008_4250, confidence Medium, signature_severity Major, updated_at 2019_07_26;
)