Project

General

Profile

Actions

Bug #200

closed
VJ KK

smb/dcerpc attack traffic not parsed properly

Bug #200: smb/dcerpc attack traffic not parsed properly

Added by Victor Julien almost 16 years ago. Updated over 15 years ago.

Status:
Closed
Priority:
High
Assignee:
Target version:
Affected Versions:
Effort:
Difficulty:
Label:

Description

The attached pcap contains traffic generated by metasploit for ms08-067. In wireshark we can see that there is quite a bit of DCERPC traffic present, but our SMB parser never invokes the DCERPC parser.


Files

KK Updated by Kirby Kuehl over 15 years ago Actions #1

Properly handle ByteCount of 0.

WM Updated by Will Metcalf over 15 years ago Actions #2

seems that we still don't alert on sid 7209 as we should given the pcap.

KK Updated by Kirby Kuehl over 15 years ago Actions #3

The patch correctly addresses the problem where the smb parser was not correctly invoking the DCERPC parser, so I believe that this ticket should be closed. The problem with the alert not firing is probably closely related to the bug reported in Bug #206. I will look into that next.

VJ Updated by Victor Julien over 15 years ago Actions #4

  • Status changed from Assigned to Closed
  • % Done changed from 90 to 100

Patch applied, thanks Kirby.

Actions

Also available in: PDF Atom