""GPL SQL xp_cmdshell program execution""

SID: 2100681

Revision: 7

Class Type: attempted-user

Metadata: created_at 2010_09_23, updated_at 2012_09_14

Reference:

Protocol: tcp

Source Network: $EXTERNAL_NET

Source Port: any

Destination Network: $SQL_SERVERS

Destination Port: 139

Flow: to_server,established

Contents:

  • Value: "x|00|p|00|_|00|c|00|m|00|d|00|s|00|h|00|e|00|l|00|l|00|"

Offset: 32

Within:

PCRE:

Special Options:

  • nocase

source