cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
423
Views
0
Helpful
2
Replies

MS04-007

pbobby
Level 1
Level 1

Using the two variations of the ms04-007 poc code I've found, I created a custom signature to detect the ASN overflow.

string.tcp engine

ports: 135-139,445

regex: \xA1\x05\x23\x03\x03\x01\x07

Works with both variations so far

2 Replies 2

mcerha
Level 3
Level 3

We are in the process of creating an emergency signature update to address this problem. It will hopefully be out sometime this evening. I will post here when the update is ready.

Signature S70 is being uploaded to CCO. It should be available shortly.