""ET SCAN MYSQL 4.1 brute force root login attempt""

SID: 2002842

Revision: 4

Class Type: protocol-command-decode

Metadata: created_at 2010_07_30, updated_at 2010_07_30

Reference:

Protocol: tcp

Source Network: $EXTERNAL_NET

Source Port: any

Destination Network: $SQL_SERVERS

Destination Port: 3306

Flow: to_server,established

Contents:

  • Value: "|01|" Depth: 4 Offset: 3

  • Value: "root|00|"

Within: 5

PCRE:

Special Options:

  • nocase

source