cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
433
Views
0
Helpful
3
Replies

signature 5858-1, DNS Server RPC Interface Buffer Overflow

mhellman
Level 7
Level 7

All the documentation seems to suggest that this overflow occurs on ports >1023. Why do all the subsigs all check 139,445?

http://tools.cisco.com/MySDN/Intelligence/viewThreat.x?threatId=5392

3 Replies 3

mhellman
Level 7
Level 7

After doing a little more reading, it would appear that an authenticated attack can occur over ports 139,445. An unauthenticated attack can occur over ports >1023. So, is 5858-0 designed to provide coverage for the unauthenticated attack (I can't tell because lots of info is hidden)?

Yes, you would be correct.

thanks.

Review Cisco Networking products for a $25 gift card