""ET EXPLOIT Possible Zerologon NetrServerAuthenticate with 0x00 Client Credentials (CVE-2020-1472)""

SID: 2030871

Revision: 3

Class Type: attempted-admin

Metadata: affected_product Windows_XP_Vista_7_8_10_Server_32_64_Bit, attack_target Server, created_at 2020_09_14, cve CVE_2020_1472, deployment Perimeter, deployment Internal, signature_severity Major, updated_at 2020_09_18

Reference:

  • cve

  • 2020-1472

Protocol: tcp

Source Network: any

Source Port: any

Destination Network: [$HTTP_SERVERS,$HOME_NET]

Destination Port: ![139,445]

Flow: established,to_server

Contents:

  • Value: "|00|"

Offset: 2

  • Value: "|1a 00|"

  • Value: "|5c 00 5c 00|"

  • Value: "|24 00 00 00 06 00|"

  • Value: "|00 00 00 00 00 00 00 00|"

Within: 50

PCRE:

Special Options:

  • fast_pattern

source