Snort.org home  
Got Source? About Snort About Sourcefire Snort FAQ
Sourcefire Network Security - the creators of Snort

Snort Forums Archive

Archive Home » General Security Discussion » Help about spoolss AddPrinterEx

Please note that the categories listed below represent an archived version of our forums pages. To view the current version and be able to post and reply to threads, please register and login here to go to the full forums pages.

[ Notice: Full Version of This Topic ]

Help about spoolss AddPrinterEx


Posted by martbuo on August 30, 2006 05:27:35

Hello

I get lots of alerts from SNORT about spoolss AddPrinterEx overflow attempt, but can't find anything malicious behind this activity. I checked source hosts and found nothing with AV or spyware programs. Do we have some sort of unknown trojan/worm/virus on hosts or is this false positive ? Who may tell me is this a real security threat behind this ?

Typical packet is :

000 : 00 00 02 52 FF 53 4D 42 25 00 00 00 00 18 03 80 ...R.SMB%.......
010 : D1 80 00 00 00 00 00 00 00 00 00 00 00 08 00 98 ................
020 : 00 08 C0 00 10 00 00 FE 01 00 00 00 04 00 00 00 ................
030 : 00 00 00 00 00 00 00 00 00 54 00 FE 01 54 00 02 .........T...T..
040 : 00 26 00 00 40 0F 02 5C 5C 00 50 00 49 00 50 00 .&..@..\\.P.I.P.
050 : 45 00 5C 00 00 00 00 00 05 00 00 03 10 00 00 00 E.\.............
060 : FE 01 00 00 01 00 00 00 E6 01 00 00 00 00 46 00 ..............F.
070 : 98 FE 2D 03 09 00 00 00 00 00 00 00 09 00 00 00 ..-.............
080 : 5C 00 5C 00 44 00 46 00 52 00 53 00 35 00 36 00 \.\.D.F.R.S.5.6.
090 : 00 00 C9 11 01 00 00 00 01 00 00 00 50 FE 2D 03 ............P.-.
0a0 : 18 08 00 00 E4 F5 2D 03 24 FC 2D 03 20 D2 CA 02 ......-.$.-. ...
0b0 : 51 00 00 00 00 00 00 00 51 00 00 00 5C 00 5C 00 Q.......Q...\.\.
0c0 : 4F 00 4E 00 59 00 58 00 5C 00 77 00 66 00 72 00 O.N.Y.X.\.w.f.r.
0d0 : 73 00 74 00 6B 00 31 00 2C 00 48 00 50 00 20 00 s.t.k.1.,.H.P. .
0e0 : 4C 00 61 00 73 00 65 00 72 00 4A 00 65 00 74 00 L.a.s.e.r.J.e.t.
0f0 : 20 00 34 00 30 00 35 00 30 00 20 00 53 00 65 00 .4.0.5.0. .S.e.
100 : 72 00 69 00 65 00 73 00 20 00 50 00 53 00 2C 00 r.i.e.s. .P.S.,.
110 : 42 00 6C 00 64 00 67 00 2E 00 20 00 33 00 20 00 B.l.d.g... .3. .
120 : 53 00 2E 00 20 00 50 00 72 00 6F 00 62 00 65 00 S... .P.r.o.b.e.
130 : 20 00 6E 00 65 00 78 00 74 00 20 00 74 00 6F 00 .n.e.x.t. .t.o.
140 : 20 00 74 00 68 00 65 00 20 00 4F 00 6C 00 69 00 .t.h.e. .O.l.i.
150 : 20 00 49 00 6E 00 6B 00 65 00 72 00 00 00 00 00 .I.n.k.e.r.....
160 : 0F 00 00 00 00 00 00 00 0F 00 00 00 5C 00 5C 00 ............\.\.
170 : 4F 00 4E 00 59 00 58 00 5C 00 77 00 66 00 72 00 O.N.Y.X.\.w.f.r.
180 : 73 00 74 00 6B 00 31 00 00 00 00 00 2D 00 00 00 s.t.k.1.....-...
190 : 00 00 00 00 2D 00 00 00 48 00 50 00 20 00 4C 00 ....-...H.P. .L.
1a0 : 4A 00 34 00 30 00 35 00 30 00 20 00 2D 00 20 00 J.4.0.5.0. .-. .
1b0 : 32 00 34 00 4D 00 62 00 20 00 72 00 61 00 6D 00 2.4.M.b. .r.a.m.
1c0 : 20 00 2D 00 20 00 41 00 6C 00 73 00 6F 00 20 00 .-. .A.l.s.o. .
1d0 : 61 00 20 00 44 00 41 00 5A 00 45 00 4C 00 20 00 a. .D.A.Z.E.L. .
1e0 : 2D 00 20 00 4E 00 54 00 53 00 4E 00 35 00 41 00 -. .N.T.S.N.5.A.
1f0 : 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................
200 : 00 00 00 00 01 00 00 00 01 00 00 00 1C F5 2D 03 ..............-.
210 : 1C 00 00 00 70 03 C7 02 10 F3 2D 03 65 05 00 00 ....p.....-.e...
220 : 02 00 00 00 00 00 00 00 00 00 00 00 07 00 00 00 ................
230 : 00 00 00 00 07 00 00 00 5C 00 5C 00 4F 00 4E 00 ........\.\.O.N.
240 : 59 00 58 00 00 00 00 00 01 00 00 00 00 00 00 00 Y.X.............
250 : 01 00 00 00 00 00 ......

With best regards
Martynas

Posted by Joel_Esler on August 30, 2006 06:15:56

Please read the documentation that accompanies the rule.

Posted by martbuo on August 30, 2006 06:20:28

Hello

Yes, I did. This gives me no clue why hosts are sending packets, that triggers rule !

Here is description from doc, but I can't find security threat behind.

Summary:
This event is generated when an attempt is made to exploit a known vulnerability in Microsoft systems using the Print Spooler Service. In particular this rule generates an event when an attempt is made to exploit the function "AddPrinterEx" via the "spoolss" component.

--
Impact:
Serious. Execution of arbitrary code leading to unauthorized administrative access to the target host.

With best regards
Martynas

Posted by martbuo on August 30, 2006 06:25:36

Maybe it is not clear, that I am seeking on the source host what can cause this activity ? I own source host and target host - need to understand if it's false positive, or unknown security threat behind.

Martynas