""GPL RPC STATD TCP monitor mon_name format string exploit attempt""
SID: 2101916
Revision: 10
Class Type: attempted-admin
Metadata: created_at 2010_09_23, cve CVE_2000_0666, updated_at 2011_04_26
Reference:
-
cve
-
2000-0666
Protocol: tcp
Source Network: $EXTERNAL_NET
Source Port: any
Destination Network: $HOME_NET
Destination Port: any
Flow: to_server,established
Contents:
-
Value: "|00 01 86 B8|" Depth: 4 Offset: 16
-
Value: "|00 00 00 02|"
-
Value: "|00 00 00 00|" Depth: 4 Offset: 8
Within: 4
PCRE:
Special Options: