""GPL SQL service_name buffer overflow attempt""

SID: 2102649

Revision: 3

Class Type: attempted-user

Metadata: created_at 2010_09_23, confidence High, updated_at 2012_09_13

Reference:

Protocol: tcp

Source Network: $EXTERNAL_NET

Source Port: any

Destination Network: $SQL_SERVERS

Destination Port: $ORACLE_PORTS

Flow: to_server,established

Contents:

  • Value: "connect_data"

  • Value: "|28|service_name="

  • Value: !"|22|"

Within: 1000

PCRE:

Special Options:

  • nocase

  • nocase

source