Short Name |
SMB:CONNECT-FROM-LOCALHOST |
---|---|
Severity |
Low |
Recommended |
No |
Category |
SMB |
Release Date |
2004/10/06 |
Update Number |
1213 |
Supported Platforms |
di-5.3+, idp-4.0+, isg-3.0+, j-series-9.5+, mx-9.4+, srx-9.2+, srx-branch-9.4+, vsrx-12.1+ |
This signature detects attempts to remotely connect to SMB shares with the NetBIOS hostname of Localhost. Because Localhost logins are not typically performed over the network, this can indicate that an attacker is trying to bypass host-based access controls.
Typically, localhost is not used in SMB access over the network. Detection of a remote connection to a network resource share with the localhost NetBIOS host name may indicate an attacker's attempt to bypass host-based access controls.