CVE-2010-0533
published 2010-03-30CVE-2010-0533: Directory traversal vulnerability in AFP Server in Apple Mac OS X before 10.6.3 allows remote attackers to list a share root's parent directory, and read and…
PriorityP338high7.5CVSS 2.0
AVNACLAuNCPIPAP
EPSS
1.54%
72.2th percentile
Directory traversal vulnerability in AFP Server in Apple Mac OS X before 10.6.3 allows remote attackers to list a share root's parent directory, and read and modify files in that directory, via unspecified vectors.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | mac_os_x | <= 10.6.2 | — |
| apple | mac_os_x | — | — |
| apple | mac_os_x | — | — |
| apple | mac_os_x_server | <= 10.6.2 | — |
| apple | mac_os_x_server | — | — |
| apple | mac_os_x_server | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Suricata
GPL NETBIOS SMB-DS DCERPC LSASS direct bind attempt
suricata·2010-09-23
CVE-2003-0533 GPL NETBIOS SMB-DS DCERPC LSASS direct bind attempt
GPL NETBIOS SMB-DS DCERPC LSASS direct bind attempt
Rule: alert tcp $EXTERNAL_NET any -> $HOME_NET 445 (msg:"GPL NETBIOS SMB-DS DCERPC LSASS direct bind attempt"; flow:established,to_server; flowbits:set,netbios.lsass.bind.attempt; flowbits:noalert; content:"|00|"; depth:1; content:"|FF|SMB"; depth:4; offset:4; nocase; content:"|05|"; content:"|0B|"; within:1; distance:1; content:"j|28 19|9|0C B1 D0 11 9B A8 00 C0|O|D9|.|F5|"; within:16; distance:29; reference:bugtraq,10108; reference:cve,2003-0533; reference:url,www.microsoft.com/technet/security/bulletin/MS04-011.mspx; classtype:protocol-command-decode; sid:2102526; rev:9; metadata:created_at 2010_09_23, cve CVE_2003_0533, confidence Medium, signature_severity Informational, updated_at 2024_03_14;)
Suricata
GPL NETBIOS DCERPC LSASS direct bind attempt
suricata·2010-09-23
CVE-2003-0533 GPL NETBIOS DCERPC LSASS direct bind attempt
GPL NETBIOS DCERPC LSASS direct bind attempt
Rule: alert tcp $EXTERNAL_NET any -> $HOME_NET 135 (msg:"GPL NETBIOS DCERPC LSASS direct bind attempt"; flow:established,to_server; flowbits:set,netbios.lsass.bind.attempt; flowbits:noalert; content:"|00|"; depth:1; content:"|FF|SMB"; depth:4; offset:4; nocase; content:"|05|"; content:"|0B|"; within:1; distance:1; content:"j|28 19|9|0C B1 D0 11 9B A8 00 C0|O|D9|.|F5|"; within:16; distance:29; reference:bugtraq,10108; reference:cve,2003-0533; reference:url,www.microsoft.com/technet/security/bulletin/MS04-011.mspx; classtype:protocol-command-decode; sid:2102524; rev:10; metadata:created_at 2010_09_23, cve CVE_2003_0533, confidence Medium, signature_severity Informational, updated_at 2024_03_14;)
Suricata
GPL NETBIOS SMB DCERPC LSASS direct bind attempt
suricata·2010-09-23
CVE-2003-0533 GPL NETBIOS SMB DCERPC LSASS direct bind attempt
GPL NETBIOS SMB DCERPC LSASS direct bind attempt
Rule: alert tcp $EXTERNAL_NET any -> $HOME_NET 139 (msg:"GPL NETBIOS SMB DCERPC LSASS direct bind attempt"; flow:established,to_server; flowbits:set,netbios.lsass.bind.attempt; flowbits:noalert; content:"|00|"; depth:1; content:"|FF|SMB"; depth:4; offset:4; nocase; content:"|05|"; content:"|0B|"; within:1; distance:1; content:"j|28 19|9|0C B1 D0 11 9B A8 00 C0|O|D9|.|F5|"; within:16; distance:29; reference:bugtraq,10108; reference:cve,2003-0533; reference:url,www.microsoft.com/technet/security/bulletin/MS04-011.mspx; classtype:protocol-command-decode; sid:2102525; rev:9; metadata:created_at 2010_09_23, cve CVE_2003_0533, confidence Medium, signature_severity Informational, tag Description_Generated_By_Proofpoint_Nexus, updated_at 2024_03_14
Suricata
GPL NETBIOS SMB DCERPC LSASS bind attempt
suricata·2010-09-23
CVE-2003-0533 GPL NETBIOS SMB DCERPC LSASS bind attempt
GPL NETBIOS SMB DCERPC LSASS bind attempt
Rule: alert tcp $EXTERNAL_NET any -> $HOME_NET 139 (msg:"GPL NETBIOS SMB DCERPC LSASS bind attempt"; flow:established,to_server; flowbits:set,netbios.lsass.bind.attempt; flowbits:noalert; content:"|00|"; depth:1; content:"|FF|SMB%"; depth:5; offset:4; nocase; byte_test:2,^,1,5,relative; content:"&|00|"; within:2; distance:56; content:"|5C|PIPE|5C 00 05 00 0B|"; within:10; distance:4; byte_test:1,&,16,1,relative; content:"j|28 19|9|0C B1 D0 11 9B A8 00 C0|O|D9|.|F5|"; within:16; distance:29; reference:bugtraq,10108; reference:cve,2003-0533; reference:url,www.microsoft.com/technet/security/bulletin/MS04-011.mspx; classtype:protocol-command-decode; sid:2102510; rev:10; metadata:created_at 2010_09_23, cve CVE_2003_0533, confidence Medium, signature_se
Suricata
GPL NETBIOS SMB DCERPC LSASS DsRolerUpgradeDownlevelServer exploit attempt
suricata·2010-09-23
CVE-2003-0533 GPL NETBIOS SMB DCERPC LSASS DsRolerUpgradeDownlevelServer exploit attempt
GPL NETBIOS SMB DCERPC LSASS DsRolerUpgradeDownlevelServer exploit attempt
Rule: alert tcp $EXTERNAL_NET any -> $HOME_NET 139 (msg:"GPL NETBIOS SMB DCERPC LSASS DsRolerUpgradeDownlevelServer exploit attempt"; flow:established,to_server; flowbits:isset,netbios.lsass.bind.attempt; content:"|FF|SMB"; depth:4; offset:4; nocase; content:"|05|"; distance:59; content:"|00|"; within:1; distance:1; content:"|09 00|"; within:2; distance:19; reference:bugtraq,10108; reference:cve,2003-0533; reference:url,www.microsoft.com/technet/security/bulletin/MS04-011.mspx; classtype:attempted-admin; sid:2102511; rev:11; metadata:created_at 2010_09_23, cve CVE_2003_0533, signature_severity Informational, tag Description_Generated_By_Proofpoint_Nexus, updated_at 2024_03_08;)
Suricata
GPL NETBIOS SMB-DS DCERPC LSASS bind attempt
suricata·2010-09-23
CVE-2003-0533 GPL NETBIOS SMB-DS DCERPC LSASS bind attempt
GPL NETBIOS SMB-DS DCERPC LSASS bind attempt
Rule: alert tcp $EXTERNAL_NET any -> $HOME_NET 445 (msg:"GPL NETBIOS SMB-DS DCERPC LSASS bind attempt"; flow:established,to_server; flowbits:set,netbios.lsass.bind.attempt; flowbits:noalert; content:"|FF|SMB%"; depth:5; offset:4; nocase; content:"&|00|"; within:2; distance:56; content:"|5C 00|P|00|I|00|P|00|E|00 5C 00|"; within:12; distance:5; nocase; content:"|05|"; within:1; distance:2; content:"|0B|"; within:1; distance:1; byte_test:1,&,1,0,relative; content:"j|28 19|9|0C B1 D0 11 9B A8 00 C0|O|D9|.|F5|"; within:16; distance:29; reference:bugtraq,10108; reference:cve,2003-0533; reference:url,www.microsoft.com/technet/security/bulletin/MS04-011.mspx; classtype:protocol-command-decode; sid:2102512; rev:10; metadata:created_at 2010_09_23, cve C
Suricata
GPL NETBIOS DCERPC LSASS bind attempt
suricata·2010-09-23
CVE-2003-0533 GPL NETBIOS DCERPC LSASS bind attempt
GPL NETBIOS DCERPC LSASS bind attempt
Rule: alert tcp $EXTERNAL_NET any -> $HOME_NET 135 (msg:"GPL NETBIOS DCERPC LSASS bind attempt"; flow:established,to_server; flowbits:set,netbios.lsass.bind.attempt; flowbits:noalert; content:"|05|"; depth:1; content:"|00|"; within:1; distance:1; byte_test:1,&,1,0,relative; content:"j|28 19|9|0C B1 D0 11 9B A8 00 C0|O|D9|.|F5|"; within:16; distance:29; reference:bugtraq,10108; reference:cve,2003-0533; reference:url,www.microsoft.com/technet/security/bulletin/MS04-011.mspx; classtype:protocol-command-decode; sid:2102507; rev:10; metadata:created_at 2010_09_23, cve CVE_2003_0533, confidence Medium, signature_severity Informational, updated_at 2024_03_14;)
Suricata
GPL NETBIOS SMB-DS DCERPC LSASS unicode bind attempt
suricata·2010-09-23
CVE-2003-0533 GPL NETBIOS SMB-DS DCERPC LSASS unicode bind attempt
GPL NETBIOS SMB-DS DCERPC LSASS unicode bind attempt
Rule: alert tcp $EXTERNAL_NET any -> $HOME_NET 445 (msg:"GPL NETBIOS SMB-DS DCERPC LSASS unicode bind attempt"; flow:established,to_server; flowbits:set,netbios.lsass.bind.attempt; flowbits:noalert; content:"|00|"; depth:1; content:"|FF|SMB%"; depth:5; offset:4; nocase; content:"&|00|"; within:2; distance:56; content:"|5C 00|P|00|I|00|P|00|E|00 5C 00 05 00 0B|"; within:15; distance:4; byte_test:1,&,16,1,relative; content:"j|28 19|9|0C B1 D0 11 9B A8 00 C0|O|D9|.|F5|"; within:16; distance:29; reference:bugtraq,10108; reference:cve,2003-0533; reference:url,www.microsoft.com/technet/security/bulletin/MS04-011.mspx; classtype:protocol-command-decode; sid:2102513; rev:10; metadata:created_at 2010_09_23, cve CVE_2003_0533, confidence Medium,
No writeups or analysis indexed.
2010-03-30
Published