[Oisf-users] Alerts about MS08-067

C. L. Martinez carlopmart at gmail.com
Tue Nov 5 11:59:53 UTC 2013


On Tue, Nov 5, 2013 at 11:54 AM, Peter Manev <petermanev at gmail.com> wrote:
> On Tue, Nov 5, 2013 at 12:42 PM, C. L. Martinez <carlopmart at gmail.com> wrote:
>> Hi all,
>>
>>  From time to time my suricata sensors (all of them using release
>> 1.4.6) trigger alerts about MS08-06 vulnerability in my servers and/or
>> workstations (ten or fifteen times a day).
>>
>>  I run the following nmap script
>> http://nmap.org/nsedoc/scripts/smb-check-vulns.html to check this
>> vulnerability, and result is not vulnerable. For example:
>>
>> root at debian01:/tmp# nmap --script smb-check-vulns.nse -p445 10.15.1.2
>>
>> Starting Nmap 6.00 ( http://nmap.org ) at 2013-11-05 11:38 UTC
>> Nmap scan report for mytest.server.local (10.15.1.2)
>> Host is up (0.00049s latency).
>> PORT    STATE SERVICE
>> 445/tcp open  microsoft-ds
>>
>> Host script results:
>> | smb-check-vulns:
>> |   MS08-067: NOT VULNERABLE
>> |   Conficker: Likely CLEAN
>> |   regsvc DoS: CHECK DISABLED (add '--script-args=unsafe=1' to run)
>> |   SMBv2 DoS (CVE-2009-3103): CHECK DISABLED (add
>> '--script-args=unsafe=1' to run)
>> |   MS06-025: CHECK DISABLED (remove 'safe=1' argument to run)
>> |_  MS07-029: CHECK DISABLED (remove 'safe=1' argument to run)
>>
>> Nmap done: 1 IP address (1 host up) scanned in 0.43 seconds
>>
>> Then, why this alert is triggered?? Any idea??
>
>
> What is the sig/alert that is generated ?

This one:

ET-emerging-netbios.rules:alert tcp any any -> $HOME_NET 445 (msg:"ET
NETBIOS Microsoft Windows NETAPI Stack Overflow Inbound - MS08-067
(11)"; flow:established,to_server; content:"|0B|"; offset:2; depth:1;
content:"|C8 4F 32 4B 70 16 D3 01 12 78 5A 47 BF 6E E1 88|";
reference:url,www.microsoft.com/technet/security/Bulletin/MS08-067.mspx;
reference:cve,2008-4250; reference:url,www.kb.cert.org/vuls/id/827267;
reference:url,doc.emergingthreats.net/bin/view/Main/2008701;
classtype:attempted-admin; sid:2008701; rev:5;)

and sensor alert is:

11/05/2013-08:05:11.830795  [**] [1:2008701:5] ET NETBIOS Microsoft
Windows NETAPI Stack Overflow Inbound - MS08-067 (11) [**]
[Classification: Attempted Administrator Privilege Gain] [Priority: 1]
{TCP} 10.17.23.33:1306 -> 10.15.1.2:445

> Do you alert when doing the scan (if you run the scan fro the "external net") ?

Nop, alert is triggered when workstations tries to access to file servers ..

>
>
> --
> Regards,
> Peter Manev



More information about the Oisf-users mailing list