cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
431
Views
0
Helpful
3
Replies

signature 5858-1, DNS Server RPC Interface Buffer Overflow

mhellman
Level 7
Level 7

All the documentation seems to suggest that this overflow occurs on ports >1023. Why do all the subsigs all check 139,445?

http://tools.cisco.com/MySDN/Intelligence/viewThreat.x?threatId=5392

3 Replies 3

mhellman
Level 7
Level 7

After doing a little more reading, it would appear that an authenticated attack can occur over ports 139,445. An unauthenticated attack can occur over ports >1023. So, is 5858-0 designed to provide coverage for the unauthenticated attack (I can't tell because lots of info is hidden)?

Yes, you would be correct.

thanks.

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community:

Review Cisco Networking products for a $25 gift card