<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Can anyone explain this vulnerability in more detail &amp;quot;Service Enum Through SMB ServiceEnum2&amp;quot; in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/can-anyone-explain-this-vulnerability-in-more-detail-quot/m-p/15038#M11025</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I am trying to find more detail on what this vulnerability is and what could possibly be triggering it in a Windows Server environment.&amp;nbsp; I am thinking that it might be a mis-configured service or application native to Windows Server but looking for a system expert to confirm or deny that theory.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;When I look it up in the Threat Vault all it says is the flowing (which is far from helpful):&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;H1 style="font-size: 2em; color: #000000; font-family: Arial, Helvetica, sans-serif; background-color: #ffffff;"&gt;Service Enum Through SMB ServiceEnum2&lt;/H1&gt;&lt;H2 style="font-size: 1.2em; color: #000000; padding-bottom: 5px; border-bottom-width: 1px; border-bottom-style: solid; border-bottom-color: #cccccc; font-family: Arial, Helvetica, sans-serif; background-color: #ffffff;"&gt;Overview&lt;/H2&gt;&lt;TABLE style="border: 1px solid #aaaaaa; color: #252525; font-family: Arial, Helvetica, sans-serif; font-size: 12px; background-color: #ffffff;"&gt;&lt;TBODY&gt;&lt;TR class="spaceunder" style="background-color: #d6e1e7;"&gt;&lt;TD style="padding-top: 5px; padding-bottom: 5px; border-left-width: 1px; border-left-style: solid; border-left-color: #aaaaaa; border-right-width: 1px; border-right-style: solid; border-right-color: #aaaaaa;"&gt;Attack Name&lt;/TD&gt;&lt;TD class="detail-field" style="padding-top: 5px; padding-bottom: 5px; border-left-width: 1px; border-left-style: solid; border-left-color: #aaaaaa; border-right-width: 1px; border-right-style: solid; border-right-color: #aaaaaa;"&gt;Service Enum Through SMB ServiceEnum2&lt;/TD&gt;&lt;/TR&gt;&lt;TR class="spaceunder"&gt;&lt;TD style="padding-top: 5px; padding-bottom: 5px; border-left-width: 1px; border-left-style: solid; border-left-color: #aaaaaa; border-right-width: 1px; border-right-style: solid; border-right-color: #aaaaaa;"&gt;Description&lt;/TD&gt;&lt;TD style="padding-top: 5px; padding-bottom: 5px; border-left-width: 1px; border-left-style: solid; border-left-color: #aaaaaa; border-right-width: 1px; border-right-style: solid; border-right-color: #aaaaaa;"&gt;Remote Enum Service Through SMB By ServiceEnum2 function number&lt;/TD&gt;&lt;/TR&gt;&lt;TR class="spaceunder" style="background-color: #d6e1e7;"&gt;&lt;TD style="padding-top: 5px; padding-bottom: 5px; border-left-width: 1px; border-left-style: solid; border-left-color: #aaaaaa; border-right-width: 1px; border-right-style: solid; border-right-color: #aaaaaa;"&gt;Threat ID&lt;/TD&gt;&lt;TD style="padding-top: 5px; padding-bottom: 5px; border-left-width: 1px; border-left-style: solid; border-left-color: #aaaaaa; border-right-width: 1px; border-right-style: solid; border-right-color: #aaaaaa;"&gt;30867&lt;/TD&gt;&lt;/TR&gt;&lt;TR class="spaceunder"&gt;&lt;TD style="padding-top: 5px; padding-bottom: 5px; border-left-width: 1px; border-left-style: solid; border-left-color: #aaaaaa; border-right-width: 1px; border-right-style: solid; border-right-color: #aaaaaa;"&gt;References&lt;/TD&gt;&lt;TD style="padding-top: 5px; padding-bottom: 5px; border-left-width: 1px; border-left-style: solid; border-left-color: #aaaaaa; border-right-width: 1px; border-right-style: solid; border-right-color: #aaaaaa;"&gt;&lt;A href="https://threatvault.paloaltonetworks.com/Home/ThreatDetail/30867" style="color: #505abc; text-decoration: underline;" target="_blank"&gt;https://threatvault.paloaltonetworks.com/Home/ThreatDetail/30867&lt;/A&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR class="spaceunder" style="background-color: #d6e1e7;"&gt;&lt;TD style="padding-top: 5px; padding-bottom: 5px; border-left-width: 1px; border-left-style: solid; border-left-color: #aaaaaa; border-right-width: 1px; border-right-style: solid; border-right-color: #aaaaaa;"&gt;Severity&lt;/TD&gt;&lt;TD style="padding-top: 5px; padding-bottom: 5px; border-left-width: 1px; border-left-style: solid; border-left-color: #aaaaaa; border-right-width: 1px; border-right-style: solid; border-right-color: #aaaaaa;"&gt;informational&lt;/TD&gt;&lt;/TR&gt;&lt;TR class="spaceunder"&gt;&lt;TD style="padding-top: 5px; padding-bottom: 5px; border-left-width: 1px; border-left-style: solid; border-left-color: #aaaaaa; border-right-width: 1px; border-right-style: solid; border-right-color: #aaaaaa;"&gt;Category&lt;/TD&gt;&lt;TD style="padding-top: 5px; padding-bottom: 5px; border-left-width: 1px; border-left-style: solid; border-left-color: #aaaaaa; border-right-width: 1px; border-right-style: solid; border-right-color: #aaaaaa;"&gt;info-leak&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 01 Feb 2013 17:19:03 GMT</pubDate>
    <dc:creator>u11712</dc:creator>
    <dc:date>2013-02-01T17:19:03Z</dc:date>
    <item>
      <title>Can anyone explain this vulnerability in more detail "Service Enum Through SMB ServiceEnum2"</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/can-anyone-explain-this-vulnerability-in-more-detail-quot/m-p/15038#M11025</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I am trying to find more detail on what this vulnerability is and what could possibly be triggering it in a Windows Server environment.&amp;nbsp; I am thinking that it might be a mis-configured service or application native to Windows Server but looking for a system expert to confirm or deny that theory.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;When I look it up in the Threat Vault all it says is the flowing (which is far from helpful):&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;H1 style="font-size: 2em; color: #000000; font-family: Arial, Helvetica, sans-serif; background-color: #ffffff;"&gt;Service Enum Through SMB ServiceEnum2&lt;/H1&gt;&lt;H2 style="font-size: 1.2em; color: #000000; padding-bottom: 5px; border-bottom-width: 1px; border-bottom-style: solid; border-bottom-color: #cccccc; font-family: Arial, Helvetica, sans-serif; background-color: #ffffff;"&gt;Overview&lt;/H2&gt;&lt;TABLE style="border: 1px solid #aaaaaa; color: #252525; font-family: Arial, Helvetica, sans-serif; font-size: 12px; background-color: #ffffff;"&gt;&lt;TBODY&gt;&lt;TR class="spaceunder" style="background-color: #d6e1e7;"&gt;&lt;TD style="padding-top: 5px; padding-bottom: 5px; border-left-width: 1px; border-left-style: solid; border-left-color: #aaaaaa; border-right-width: 1px; border-right-style: solid; border-right-color: #aaaaaa;"&gt;Attack Name&lt;/TD&gt;&lt;TD class="detail-field" style="padding-top: 5px; padding-bottom: 5px; border-left-width: 1px; border-left-style: solid; border-left-color: #aaaaaa; border-right-width: 1px; border-right-style: solid; border-right-color: #aaaaaa;"&gt;Service Enum Through SMB ServiceEnum2&lt;/TD&gt;&lt;/TR&gt;&lt;TR class="spaceunder"&gt;&lt;TD style="padding-top: 5px; padding-bottom: 5px; border-left-width: 1px; border-left-style: solid; border-left-color: #aaaaaa; border-right-width: 1px; border-right-style: solid; border-right-color: #aaaaaa;"&gt;Description&lt;/TD&gt;&lt;TD style="padding-top: 5px; padding-bottom: 5px; border-left-width: 1px; border-left-style: solid; border-left-color: #aaaaaa; border-right-width: 1px; border-right-style: solid; border-right-color: #aaaaaa;"&gt;Remote Enum Service Through SMB By ServiceEnum2 function number&lt;/TD&gt;&lt;/TR&gt;&lt;TR class="spaceunder" style="background-color: #d6e1e7;"&gt;&lt;TD style="padding-top: 5px; padding-bottom: 5px; border-left-width: 1px; border-left-style: solid; border-left-color: #aaaaaa; border-right-width: 1px; border-right-style: solid; border-right-color: #aaaaaa;"&gt;Threat ID&lt;/TD&gt;&lt;TD style="padding-top: 5px; padding-bottom: 5px; border-left-width: 1px; border-left-style: solid; border-left-color: #aaaaaa; border-right-width: 1px; border-right-style: solid; border-right-color: #aaaaaa;"&gt;30867&lt;/TD&gt;&lt;/TR&gt;&lt;TR class="spaceunder"&gt;&lt;TD style="padding-top: 5px; padding-bottom: 5px; border-left-width: 1px; border-left-style: solid; border-left-color: #aaaaaa; border-right-width: 1px; border-right-style: solid; border-right-color: #aaaaaa;"&gt;References&lt;/TD&gt;&lt;TD style="padding-top: 5px; padding-bottom: 5px; border-left-width: 1px; border-left-style: solid; border-left-color: #aaaaaa; border-right-width: 1px; border-right-style: solid; border-right-color: #aaaaaa;"&gt;&lt;A href="https://threatvault.paloaltonetworks.com/Home/ThreatDetail/30867" style="color: #505abc; text-decoration: underline;" target="_blank"&gt;https://threatvault.paloaltonetworks.com/Home/ThreatDetail/30867&lt;/A&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR class="spaceunder" style="background-color: #d6e1e7;"&gt;&lt;TD style="padding-top: 5px; padding-bottom: 5px; border-left-width: 1px; border-left-style: solid; border-left-color: #aaaaaa; border-right-width: 1px; border-right-style: solid; border-right-color: #aaaaaa;"&gt;Severity&lt;/TD&gt;&lt;TD style="padding-top: 5px; padding-bottom: 5px; border-left-width: 1px; border-left-style: solid; border-left-color: #aaaaaa; border-right-width: 1px; border-right-style: solid; border-right-color: #aaaaaa;"&gt;informational&lt;/TD&gt;&lt;/TR&gt;&lt;TR class="spaceunder"&gt;&lt;TD style="padding-top: 5px; padding-bottom: 5px; border-left-width: 1px; border-left-style: solid; border-left-color: #aaaaaa; border-right-width: 1px; border-right-style: solid; border-right-color: #aaaaaa;"&gt;Category&lt;/TD&gt;&lt;TD style="padding-top: 5px; padding-bottom: 5px; border-left-width: 1px; border-left-style: solid; border-left-color: #aaaaaa; border-right-width: 1px; border-right-style: solid; border-right-color: #aaaaaa;"&gt;info-leak&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 01 Feb 2013 17:19:03 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/can-anyone-explain-this-vulnerability-in-more-detail-quot/m-p/15038#M11025</guid>
      <dc:creator>u11712</dc:creator>
      <dc:date>2013-02-01T17:19:03Z</dc:date>
    </item>
    <item>
      <title>Re: Can anyone explain this vulnerability in more detail "Service Enum Through SMB ServiceEnum2"</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/can-anyone-explain-this-vulnerability-in-more-detail-quot/m-p/15039#M11026</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Someone or something tried to list which users are logged in to your server by using the SMB ServiceEnum2 function.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This is classified as informational so its in most cases nothing bad.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;But it can be worth investigating which ipaddresses performs these lookups and perhaps whitelist those and then trigger an alert if someone else other than these sourceip's performs such enumeration (for example an intruder).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;For more information (similar stuff):&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="active_link" href="http://nmap.org/nsedoc/scripts/smb-enum-users.html" title="http://nmap.org/nsedoc/scripts/smb-enum-users.html"&gt;http://nmap.org/nsedoc/scripts/smb-enum-users.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="http://www.secuobs.com/plugs/18585.shtml" title="http://www.secuobs.com/plugs/18585.shtml"&gt; - SMB enum services over \srvsvc infos SecuObs - L'observatoire de la s&amp;amp;eacute;curite internet - Site d'informations professionnelles francophone sur la s&amp;amp;eacute;curit&amp;amp;eacute; informatique&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 01 Feb 2013 19:01:33 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/can-anyone-explain-this-vulnerability-in-more-detail-quot/m-p/15039#M11026</guid>
      <dc:creator>mikand</dc:creator>
      <dc:date>2013-02-01T19:01:33Z</dc:date>
    </item>
  </channel>
</rss>

