""GPL EXPLOIT login buffer non-evasive overflow attempt""

SID: 2103274

Revision: 4

Class Type: attempted-admin

Metadata: created_at 2010_09_23, cve CVE_2001_0797, updated_at 2012_07_27

Reference:

  • cve

  • 2001-0797

Protocol: tcp

Source Network: $EXTERNAL_NET

Source Port: any

Destination Network: $TELNET_SERVERS

Destination Port: 23

Flow: to_server,established

Contents:

  • Value: "|FF FA|'|00 00|"

Within:

PCRE: "/T.?T.?Y.?P.?R.?O.?M.?P.?T/RBi"

Special Options:

  • rawbytes

source