""ET NETBIOS Microsoft Windows NETAPI Stack Overflow Inbound - MS08-067 (4)""

SID: 2008693

Revision: 5

Class Type: attempted-admin

Metadata: created_at 2010_07_30, cve CVE_2008_4250, updated_at 2010_07_30

Reference:

Protocol: udp

Source Network: any

Source Port: any

Destination Network: $HOME_NET

Destination Port: 139

Flow:

Contents:

  • Value: "|1F 00|"

  • Value: "|C8 4F 32 4B 70 16 D3 01 12 78 5A 47 BF 6E E1 88|"

  • Value: "|00 2E 00 2E 00 2F 00 2E 00 2E 00 2F|"

Within:

PCRE:

Special Options:

source