Bug #4767
closed
Rule error in SMB dce_iface and dce_opnum keywords
Added by Eloy Pérez about 3 years ago.
Updated over 2 years ago.
Description
The SMB dce_iface and dce_opnum keywords don't match.
Following rule and the associated pcap can be used to test this behavior:
alert smb any any -> any any (\
msg: "SMB-DCE EnumPrinterDrivers";\
dce_iface: 12345678-1234-abcd-ef00-0123456789ab;\
dce_opnum: 10;\
sid: 1;\
)
Files
- Related to Bug #4769: dcerpc dce_iface just match a packet added
- Related to Bug #3109: dcerpc engine not generating alerts added
- Status changed from New to Assigned
- Target version set to 7.0.0-beta1
- Label Needs backport to 5.0, Needs backport to 6.0 added
- Copied to Bug #4925: Rule error in SMB dce_iface and dce_opnum keywords (6.0.x backport) added
- Copied to Bug #4926: Rule error in SMB dce_iface and dce_opnum keywords (5.0.x backport) added
- Status changed from Assigned to Closed
- Label deleted (
Needs backport to 5.0, Needs backport to 6.0)
Also available in: Atom
PDF