<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic DCE2_EVENT__SMB_BAD_NEXT_COMMAND_OFFSET in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/dce2-event-smb-bad-next-command-offset/m-p/4726145#M1095250</link>
    <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;Does anyone know if this is still considered a bug in 7.0 within the FMC? I'm seeing a lot of these events being triggered from folks copying to and from our share drive. I'm not sure if whitelisting is the best way to go or if there's another route to take. Thanks in advance for any feedback.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Tue, 22 Nov 2022 21:13:01 GMT</pubDate>
    <dc:creator>dcanady55</dc:creator>
    <dc:date>2022-11-22T21:13:01Z</dc:date>
    <item>
      <title>DCE2_EVENT__SMB_BAD_NEXT_COMMAND_OFFSET</title>
      <link>https://community.cisco.com/t5/network-security/dce2-event-smb-bad-next-command-offset/m-p/4726145#M1095250</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;Does anyone know if this is still considered a bug in 7.0 within the FMC? I'm seeing a lot of these events being triggered from folks copying to and from our share drive. I'm not sure if whitelisting is the best way to go or if there's another route to take. Thanks in advance for any feedback.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 22 Nov 2022 21:13:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/dce2-event-smb-bad-next-command-offset/m-p/4726145#M1095250</guid>
      <dc:creator>dcanady55</dc:creator>
      <dc:date>2022-11-22T21:13:01Z</dc:date>
    </item>
    <item>
      <title>Re: DCE2_EVENT__SMB_BAD_NEXT_COMMAND_OFFSET</title>
      <link>https://community.cisco.com/t5/network-security/dce2-event-smb-bad-next-command-offset/m-p/4726355#M1095261</link>
      <description>&lt;P&gt;Hi &lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/333484"&gt;@dcanady55&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;I'm not aware of any bug regarding this specific signature. There was a bug CSCvp54541 about missing signature, but that was very long time ago. It really depends what SMB server are you using, and how does it work in general. You can see more details about specific IPS rule &lt;A href="https://snort.org/rule_docs/133-59" target="_self"&gt;here&lt;/A&gt;.&lt;/P&gt;
&lt;P&gt;If you are confident that this is regular traffic, then you can suppress this one.&lt;/P&gt;
&lt;P&gt;Kind regards,&lt;/P&gt;
&lt;P&gt;Milos&lt;/P&gt;</description>
      <pubDate>Wed, 23 Nov 2022 06:49:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/dce2-event-smb-bad-next-command-offset/m-p/4726355#M1095261</guid>
      <dc:creator>Milos_Jovanovic</dc:creator>
      <dc:date>2022-11-23T06:49:37Z</dc:date>
    </item>
  </channel>
</rss>

