I don't understand byte_jump with from_beginning

This is a discussion on I don't understand byte_jump with from_beginning within the Snort forums, part of the System Security and Security Related category; Hi I look at rules NETBIOS SMB-DS umpnpmgr PNP_QueryResConfList unicode little endian attempt (sid=3999) alert tcp $EXTERNAL_NET any -&...


Go Back   Usenet Forums > System Security and Security Related > Snort

FAQ Members List Calendar Search Today's Posts Mark Forums Read
  #1 (permalink)  
Old 12-04-2005
yusun
 
Posts: n/a
Default I don't understand byte_jump with from_beginning


Hi I look at rules NETBIOS SMB-DS umpnpmgr PNP_QueryResConfList unicode
little endian attempt (sid=3999)
alert tcp $EXTERNAL_NET any -> $HOME_NET 445 (msg:"NETBIOS SMB-DS
umpnpmgr PNP_QueryResConfList unicode little endian attempt";
flow:established,to_server; flowbits:isset,dce.bind.umpnpmgr;
content:"|00|"; depth:1; content:"|FF|SMB%"; within:5; distance:3;
byte_test:1,&,128,6,relative; pcre:"/^.{27}/sR"; content:"&|00|";
within:2; distance:29; content:"|5C 00|P|00|I|00|P|00|E|00 5C 00 00
00|"; distance:4; nocase;
byte_jump:2,-17,relative,from_beginning,little; pcre:"/^.{4}/sR";
content:"|05|"; byte_test:1,&,16,3,relative; content:"|00|"; within:1;
distance:1; content:"6|00|"; within:2; distance:19;
reference:url,http://www.microsoft.com/technet/sec...ms05-039.mspx;
classtype:protocol-command-decode; sid:3999; rev:1;)

why after rule option
“byte_jump:2,-17,relative,from_beginning,little; pcre:"/^.{4}/sR"”,
the doe_ptr at 0x58。
I don’t understand “byte_jump:2,-17,relative,from_beginning,little;
pcre:"/^.{4}/sR"” how to work?

Reply With Quote
Reply
Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is Off
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT +1. The time now is 02:23 PM.


Powered by vBulletin® Version 3.7.3
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.0.0