SMB: Remote Connection from Localhost

This signature detects attempts to remotely connect to SMB shares with the NetBIOS hostname of Localhost. Because Localhost logins are not typically performed over the network, this can indicate that an attacker is trying to bypass host-based access controls.

Extended Description

Typically, localhost is not used in SMB access over the network. Detection of a remote connection to a network resource share with the localhost NetBIOS host name may indicate an attacker's attempt to bypass host-based access controls.

Short Name
SMB:CONNECT-FROM-LOCALHOST
Severity
Warning
Recommended
False
Recommended Action
None
Category
SMB
Keywords
Connection Localhost Remote from
Release Date
10/06/2004
Supported Platforms

srx-branch-12.3

srx-19.3

srx-branch-19.3

vsrx3bsd-19.2

srx-branch-19.4

vsrx-19.4

mx-12.3

mx-19.4

vmx-19.4

mx-19.3

vsrx3bsd-19.4

srx-19.4

vsrx-12.3

vmx-19.3

vsrx-19.2

srx-12.3

Sigpack Version
3375
False Positive
Unknown

Found a potential security threat?