<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic sensor not detecting msrpc_dcom_ms03_026 in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/sensor-not-detecting-msrpc-dcom-ms03-026/m-p/606236#M98407</link>
    <description>&lt;P&gt;Metasploit framework console version 1.99 contains an exploit for msrpc_dcom_ms03_026. (Microsoft RPC DCOM MSO3-026). I have set up a lab to see the alarms that would be triggered when this tool is used to attack a remote host &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The exploit is not detected by a Cisco Intrusion Prevention System, Version 5.1(1p1)S232.0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The sensor sees the packets with the command packet display &amp;lt;int&amp;gt; but no alerts are triggered. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have checked that there are no filters and that all the signatures for dcom are enabled. The snort sensor that is running in parallel has no problem alerting. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Could someone tell me if I have missed a step or is this genuine false negative? &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If someone from Cisco is willing to help troubleshoot the problem I will send the pcap file as captured from the Cisco 4250 sensor.&lt;/P&gt;</description>
    <pubDate>Sun, 10 Mar 2019 10:04:43 GMT</pubDate>
    <dc:creator>darin.marais</dc:creator>
    <dc:date>2019-03-10T10:04:43Z</dc:date>
    <item>
      <title>sensor not detecting msrpc_dcom_ms03_026</title>
      <link>https://community.cisco.com/t5/network-security/sensor-not-detecting-msrpc-dcom-ms03-026/m-p/606236#M98407</link>
      <description>&lt;P&gt;Metasploit framework console version 1.99 contains an exploit for msrpc_dcom_ms03_026. (Microsoft RPC DCOM MSO3-026). I have set up a lab to see the alarms that would be triggered when this tool is used to attack a remote host &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The exploit is not detected by a Cisco Intrusion Prevention System, Version 5.1(1p1)S232.0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The sensor sees the packets with the command packet display &amp;lt;int&amp;gt; but no alerts are triggered. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have checked that there are no filters and that all the signatures for dcom are enabled. The snort sensor that is running in parallel has no problem alerting. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Could someone tell me if I have missed a step or is this genuine false negative? &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If someone from Cisco is willing to help troubleshoot the problem I will send the pcap file as captured from the Cisco 4250 sensor.&lt;/P&gt;</description>
      <pubDate>Sun, 10 Mar 2019 10:04:43 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/sensor-not-detecting-msrpc-dcom-ms03-026/m-p/606236#M98407</guid>
      <dc:creator>darin.marais</dc:creator>
      <dc:date>2019-03-10T10:04:43Z</dc:date>
    </item>
    <item>
      <title>Re: sensor not detecting msrpc_dcom_ms03_026</title>
      <link>https://community.cisco.com/t5/network-security/sensor-not-detecting-msrpc-dcom-ms03-026/m-p/606237#M98408</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Signature 3327-6 will detect this Metasploit module, however it is disabled by default.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Description:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Subsig 6 fires when a potential buffer overflow attempt against a Windows DCOM RPC service is detected. This may indicate a system compromise.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This is a 5.x only signature.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;However, as noted in the benign triggers section for signature 3327-6:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;False positives have been reported with this signature. To help identify malicious traffic it is recommended that you look for alerts from one of the 3328-* signatures from the same source.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So one should only enable this signature for a specific cause.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We are currently investigating improving the fidelity of 3327-6 or possibly creating new protection for this module.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you have already enabled 3327-6 and this is not firing, please email me the pcap at &lt;A href="mailto:ips-signature-team@cisco.com"&gt;ips-signature-team@cisco.com&lt;/A&gt; and we will take a look.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I hope that helps, and please let us know if this does not answer your question.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;Al&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Cisco IDS/IPS Signature Development Team&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 30 Jun 2006 16:17:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/sensor-not-detecting-msrpc-dcom-ms03-026/m-p/606237#M98408</guid>
      <dc:creator>aroethli</dc:creator>
      <dc:date>2006-06-30T16:17:39Z</dc:date>
    </item>
  </channel>
</rss>

