Short Name |
MS-RPC:SAMR-ACCESS-REQUEST |
---|---|
Severity |
Low |
Recommended |
No |
Category |
MS-RPC |
Release Date |
2004/09/30 |
Update Number |
1213 |
Supported Platforms |
di-5.3+, idp-4.0+, isg-3.0+, j-series-9.5+, mx-9.4+, srx-9.2+, srx-branch-9.4+, vsrx-12.1+ |
This signature detects attempts to connect to the Security Account Manager Remote (SAMR) service on Windows. Attackers can be probing your server for vulnerabilities, as a successful login to this service provides important information such as administrator account details, default domain names, open users, and active groups. However, because system administrators also use the SAMR service legitimately, this signature can also detect non-malicious activity.
Attackers may exploit the SAMR service to obtain sensitive information stored in the SAM database of a target Windows system. Once obtaining this sensitive information, attackers may be able to fully compromise the affected system.