cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
255
Views
1
Helpful
2
Replies

ethereal or tcpdump filter for WindowsLocSrv

darin.marais
Level 4
Level 4

I am busy analyzing the alarm “Windows Locator Service Overflow” with in our network. The signature says that it will trigger when with the following parameters

8 - MinMatchLength = 2000

11 - ServicePorts = 139,445

I would like to see an example of when this alarm has triggererd and then corilate that with the “iplog” capture that has been taken during the same period.

Can anyone on the list tell me what the ethereal or tcpdump filter should look like in order to filter these packets to the display?

Would eth.len > 2000 work?

2 Replies 2

klwiley
Cisco Employee
Cisco Employee

Is this on a 3.1 sensor?

it is indeed!

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: