03-21-2008 08:42 AM - edited 03-10-2019 04:02 AM
All the documentation seems to suggest that this overflow occurs on ports >1023. Why do all the subsigs all check 139,445?
http://tools.cisco.com/MySDN/Intelligence/viewThreat.x?threatId=5392
03-21-2008 09:03 AM
After doing a little more reading, it would appear that an authenticated attack can occur over ports 139,445. An unauthenticated attack can occur over ports >1023. So, is 5858-0 designed to provide coverage for the unauthenticated attack (I can't tell because lots of info is hidden)?
03-21-2008 10:12 AM
Yes, you would be correct.
03-21-2008 10:14 AM
thanks.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide