SMB overflow attacks

From: KF (dotslash@snosoft.com)
Date: 08/26/02


Date: Mon, 26 Aug 2002 16:02:45 -0400
From: KF <dotslash@snosoft.com>
To: vuln-dev@security-focus.com, incidents@security-focus.com, full-disclosure@lists.netsys.com

Does anyone have log entries from a confirmed attack based on the recent
SMB overflows?

http://online.securityfocus.com/bid/5556 and
http://online.securityfocus.com/advisories/4416

I have a client with some unusual log entries related to lanman and SMB
headers.... the log issues are similar to the following article:

http://support.microsoft.com/default.aspx?scid=kb;[LN];Q321733

After applying the fix mentioned in the security-focus bid the server
seemed to be happy... this makes me think the reason the server
was arrgivated is related to a DoS attack on SMB.

I just need something solid to either trace back to an attacker or a
confirmation that I was even attacked.

-KF

----------------------------------------------------------------------------
This list is provided by the SecurityFocus ARIS analyzer service.
For more information on this free incident handling, management
and tracking system please see: http://aris.securityfocus.com



Relevant Pages

  • [Full-Disclosure] SMB overflow attacks
    ... Does anyone have log entries from a confirmed attack based on the recent ... I have a client with some unusual log entries related to lanman and SMB ...
    (Full-Disclosure)
  • [Full-Disclosure] SMB overflow attacks
    ... Does anyone have log entries from a confirmed attack based on the recent ... I have a client with some unusual log entries related to lanman and SMB ...
    (Full-Disclosure)
  • Re: SMB Brute Force
    ... approaches than trying to connect to network shares via SMB. ... if this is what you are trying to accomplish than why would ... wanting to use a brute force password attack over the network is because ... If you want to write your own every Win32 programming ...
    (Focus-Microsoft)
  • Re: Suspicious IIS log file entries! Help!!
    ... this looks like an unsuccessful worm attempt. ... the log entries such as 404 means that the attack was unsuccessful. ... give a 200 even though the attack may not have been successful. ...
    (microsoft.public.win2000.security)