SMB: Name Lookup

This protocol anomaly is the \pipe\lsarpc (Local Security Authority) named pipe transaction used to execute the LookupAccountName function. Programs such as user2sid and Hyena use this named pipe transaction to validate usernames on the target host. This type of traffic is common between domain controllers. This protocol anomaly should be used to inspect WAN traffic only.

Short Name
SMB:ENUM:NAME-LOOKUP
Severity
Warning
Recommended
False
Recommended Action
None
Category
SMB
Keywords
WAN lookup name smb user2sid
Release Date
01/29/2004
Supported Platforms

srx-branch-12.3

srx-19.3

srx-branch-19.3

vsrx3bsd-19.2

srx-branch-19.4

vsrx-19.4

mx-12.3

mx-19.4

vmx-19.4

mx-19.3

vsrx3bsd-19.4

srx-19.4

vsrx-12.3

vmx-19.3

vsrx-19.2

srx-12.3

Sigpack Version
3324
False Positive
Unknown

Found a potential security threat?