Journal: Wrote my first snort rule!
Wrote my first snort rule! It detects if someone is trying to capture credentials via the auxiliary/server/capture/smb module.
More information about this type of attack is here:
http://www.packetstan.com/2011/03/nbns-spoofing-on-your-way-to-world.html;
Rule:
alert tcp any 445 -> any any (msg:"SMB Metasploit credential capture attempt!"; reference: url,http://www.metasploit.com/modules/auxiliary/server/capture/smb; reference: url,http://www.packetstan.com/2011/03/nbns-spoofing-on-your-way-to-world.html; content:"|11 22 33 44 55 66 77 88|"; classtype:attempted-user; offset: 73; depth: 8; flow: to_client; sid: 123000001; rev:1;)