GPL NETBIOS DCERPC Remote Activation bind attempt


Query · suricata

flow:to_server,established;
content:"|05|";
content:"|0B|"; within:1; distance:1;
byte_test:1,&,1,0,relative;
content:"|B8|J|9F|M|1C|}|CF 11 86 1E 00| |AF|n|7C|W"; within:16; distance:29;
tag:session,5,packets;
Raw source GPL NETBIOS DCERPC Remote Activation bind attempt · Suricata
Esc
Published by Emerging Threats Open ↗, licensed under BSD 3-Clause ↗. Line breaks added for readability; the rule is otherwise unchanged.
alert tcp $EXTERNAL_NET any -> $HOME_NET 135 (
    msg:"GPL NETBIOS DCERPC Remote Activation bind attempt";
    flow:to_server,established;
    content:"|05|";
    content:"|0B|"; within:1; distance:1;
    byte_test:1,&,1,0,relative;
    content:"|B8|J|9F|M|1C|}|CF 11 86 1E 00| |AF|n|7C|W"; within:16; distance:29;
    tag:session,5,packets;
    reference:bugtraq,8234;
    reference:bugtraq,8458;
    reference:cve,2003-0528;
    reference:cve,2003-0605;
    reference:cve,2003-0715;
    reference:nessus,11798;
    reference:nessus,11835;
    reference:url,www.microsoft.com/technet/security/bulletin/MS03-039.mspx;
    classtype:attempted-admin;
    sid:2102251; rev:16;
    metadata:created_at 2010_09_23, cve CVE_2003_0528, signature_severity Informational, updated_at 2019_07_26;
)

Detection rules belong to the projects that publish them and remain under their own licenses. This site indexes and links to them; it claims no rights in them.