Rule

--
Sid
133-8

--
Summary:
This event is generated when the dcerpc2 preprocessor detects anomalous network traffic.

--
Impact:
Unknown. This is an indication of anomalous behaviour between networked assets.

--
Detailed Information:
This event is generated when the dcerpc2 preprocessor detects anomalous network traffic.

Many SMB commands have a field containing an offset from the beginning of the SMB header to where the data the command is carrying starts. If this offset places a pointer before data that has already been processed or after the end of payload, the preprocessor will generate this event.

This event can be controlled using the ((dce2)) configuration options.

--
Affected Systems:
All systems using NetBIOS DCERPC or SMB file and print sharing

--
Attack Scenarios:
An attacker would need to specially craft an SMB header that does not correctly indicate the start of the command data payload.

--
Ease of Attack:
Simple.

--
False Positives:
None known.

--
False Negatives:
None known.

--
Corrective Action:


--
Contributors:
Sourcefire Vulnerability Research Team


--
Additional References:


--
