03-21-2008 08:42 AM - edited 03-10-2019 04:02 AM
All the documentation seems to suggest that this overflow occurs on ports >1023. Why do all the subsigs all check 139,445?
http://tools.cisco.com/MySDN/Intelligence/viewThreat.x?threatId=5392
03-21-2008 09:03 AM
After doing a little more reading, it would appear that an authenticated attack can occur over ports 139,445. An unauthenticated attack can occur over ports >1023. So, is 5858-0 designed to provide coverage for the unauthenticated attack (I can't tell because lots of info is hidden)?
03-21-2008 10:12 AM
Yes, you would be correct.
03-21-2008 10:14 AM
thanks.
Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: