SMB: Brute Force Login Attempt

This protocol anomaly detects multiple login/authentication failures between a unique pair of hosts within a short period of time. Vulnerability scanners and programs like enum that perform dictionary based or password-guessing attacks will likely trigger this attack. The number of login failures to trigger this attack can be configured in the Sensor Settings Rulebase of your Security Policy.

Extended Description

This is a protocol anomaly.

Short Name
SMB:ERROR:GRIND
Severity
Major
Recommended
True
Recommended Action
Drop
Category
SMB
Keywords
grind smb
Release Date
01/28/2004
Supported Platforms

srx-branch-12.3

srx-19.3

srx-branch-19.3

vsrx3bsd-19.2

srx-branch-19.4

vsrx-19.4

mx-12.3

mx-19.4

vmx-19.4

mx-19.3

vsrx3bsd-19.4

srx-19.4

vsrx-12.3

vmx-19.3

vsrx-19.2

srx-12.3

Sigpack Version
3324
False Positive
Unknown

Found a potential security threat?