Project

General

Profile

Actions

Bug #200

closed

smb/dcerpc attack traffic not parsed properly

Added by Victor Julien over 14 years ago. Updated over 14 years ago.

Status:
Closed
Priority:
High
Assignee:
Target version:
Affected Versions:
Effort:
Difficulty:
Label:

Description

The attached pcap contains traffic generated by metasploit for ms08-067. In wireshark we can see that there is quite a bit of DCERPC traffic present, but our SMB parser never invokes the DCERPC parser.


Files

Actions

Also available in: Atom PDF