This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

IPS Alarm SERVER-OTHER Kerberos 5 build_principal_va denial of service attempt

Hallo zusammen,

habe auf 2 unterschiedlichen SG's (9.711) jeweils die selbe IPS Meldung:

SERVER-OTHER Kerberos 5 build_principal_va denial of service attempt

In der Beschreibung der Sid 1-59640 steht nur

"This rule detects a crafted Kerberos TGS-REQ that can cause denial of service and crash the Kerberos."

Was sagt mir das genau? Handelt es sich eventuell um einen false Positive ?

Vielen Dank schon mal

/André



This thread was automatically locked due to age.
  • Hallo André,

    What are the srcip and dstip in the messages?  If you prefer, obfuscate IPs like 84.XX.YY.121, 10.X.Y.100, 192.168.X.200 and 172.2X.Y.51.  That lets us see immediately which IPs are local and which are identical.

    Cheers - Bob

     
    Sophos UTM Community Moderator
    Sophos Certified Architect - UTM
    Sophos Certified Engineer - XG
    Gold Solution Partner since 2005
    MediaSoft, Inc. USA