alert tcp $EXTERNAL_NET any -> $HOME_NET 445 (msg:"ET EXPLOIT MS04011 Lsasrv.dll RPC exploit (
WinXP?)"; flow: to_server,established; content:"|95 14 40 00 03 00 00 00 7C 70 40 00 01|"; content:"|78 85 13 00
AB5B? A6 E9 31 31|"; classtype: misc-activity; sid: 2000033; rev:7;)
Added 2008-05-18 19:52:13 UTC
alert tcp $EXTERNAL_NET any -> $HOME_NET 445 (msg:"ET EXPLOIT MS04011 Lsasrv.dll RPC exploit (
WinXP?)"; flow: to_server,established; content:"|95 14 40 00 03 00 00 00 7C 70 40 00 01|"; content:"|78 85 13 00
AB5B? A6 E9 31 31|"; classtype: misc-activity; sid: 2000033; rev:7;)
Added 2008-05-18 19:52:13 UTC
alert tcp any any -> any 445 (msg:"ET EXPLOIT MS04011 Lsasrv.dll RPC exploit (
WinXP?)"; flow: to_server,established; content:"|95 14 40 00 03 00 00 00 7C 70 40 00 01|"; content:"|78 85 13 00
AB5B? A6 E9 31 31|"; classtype: misc-activity; sid: 2000033; rev:6;)
Added 2008-01-25 10:56:37 UTC
alert tcp any any -> any 445 (msg:"ET EXPLOIT MS04011 Lsasrv.dll RPC exploit (
WinXP?)"; flow: to_server,established; content:"|95 14 40 00 03 00 00 00 7C 70 40 00 01|"; content:"|78 85 13 00
AB5B? A6 E9 31 31|"; classtype: misc-activity; sid: 2000033; rev:6;)
Added 2008-01-25 10:56:37 UTC
alert tcp any any -> any 445 (msg: "BLEEDING-EDGE EXPLOIT MS04011 Lsasrv.dll RPC exploit (
WinXP?)"; flow: to_server,established; content:"|95 14 40 00 03 00 00 00 7C 70 40 00 01|"; content:"|78 85 13 00
AB5B? A6 E9 31 31|"; classtype: misc-activity; sid: 2000033; rev:5; )