Project

General

Profile

Actions

Bug #4767

closed

Rule error in SMB dce_iface and dce_opnum keywords

Added by Eloy Pérez 12 months ago. Updated 3 months ago.

Status:
Closed
Priority:
Normal
Assignee:
Target version:
Affected Versions:
Effort:
Difficulty:
Label:

Description

The SMB dce_iface and dce_opnum keywords don't match.

Following rule and the associated pcap can be used to test this behavior:

alert smb any any -> any any (\
      msg: "SMB-DCE EnumPrinterDrivers";\
      dce_iface: 12345678-1234-abcd-ef00-0123456789ab;\
      dce_opnum: 10;\
      sid: 1;\
      )


Files

test-smb-dcerpc.pcapng (13.4 KB) test-smb-dcerpc.pcapng Pcap with SMB DCERPC traffic to test Eloy Pérez, 10/20/2021 09:56 AM

Subtasks 2 (0 open2 closed)

Bug #4925: Rule error in SMB dce_iface and dce_opnum keywords (6.0.x backport)ClosedEloy PérezActions
Bug #4926: Rule error in SMB dce_iface and dce_opnum keywords (5.0.x backport)ClosedVictor JulienActions

Related issues 2 (0 open2 closed)

Related to Bug #4769: dcerpc dce_iface just match a packetClosedEloy PérezActions
Related to Bug #3109: dcerpc engine not generating alertsClosedShivani BhardwajActions
Actions #1

Updated by Victor Julien 11 months ago

  • Related to Bug #4769: dcerpc dce_iface just match a packet added
Actions #2

Updated by Victor Julien 11 months ago

  • Related to Bug #3109: dcerpc engine not generating alerts added
Actions #3

Updated by Shivani Bhardwaj 9 months ago

  • Status changed from New to Assigned
  • Target version set to 7.0rc1
  • Label Needs backport to 5.0, Needs backport to 6.0 added
Actions #4

Updated by Shivani Bhardwaj 9 months ago

  • Copied to Bug #4925: Rule error in SMB dce_iface and dce_opnum keywords (6.0.x backport) added
Actions #5

Updated by Shivani Bhardwaj 9 months ago

  • Copied to Bug #4926: Rule error in SMB dce_iface and dce_opnum keywords (5.0.x backport) added
Actions #6

Updated by Shivani Bhardwaj 8 months ago

  • Status changed from Assigned to Closed
Actions #7

Updated by Victor Julien 3 months ago

  • Label deleted (Needs backport to 5.0, Needs backport to 6.0)
Actions

Also available in: Atom PDF