[**] [1:1448:11] MISC MS Terminal server request [**] [Classification: Generic Protocol Command Decode] [Priority: 3] 08/31-09:15:01.368936 0:10:5A:1B:82:CA -> 0:E:A6:C4:97:D4 type:0x800 len:0x66 xxx.xxx.xxx.xxx:33122 -> xxx.xxx.xxx.xxx:3389 TCP TTL:64 TOS:0x0 ID:56977 IpLen:20 DgmLen:88 DF ***AP*** Seq: 0x10A68685 Ack: 0xF918F598 Win: 0x2E TcpLen: 32 TCP Options (3) => NOP NOP TS: 340809740 0 [Xref => http://www.microsoft.com/technet/security/bulletin/MS01-040.mspx][Xref => http://cve.mitre.org/cgi-bin/cvename.cgi?name=2001-0540][Xref => http://www.securityfocus.com/bid/3099] [**] [1:2418:3] MISC MS Terminal Server no encryption session initiation attmept [**] [Classification: Attempted Denial of Service] [Priority: 2] 08/31-09:15:01.434378 0:10:5A:1B:82:CA -> 0:E:A6:C4:97:D4 type:0x800 len:0x1D8 xxx.xxx.xxx.xxx:33122 -> xxx.xxx.xxx.xxx:3389 TCP TTL:64 TOS:0x0 ID:56979 IpLen:20 DgmLen:458 DF ***AP*** Seq: 0x10A686A9 Ack: 0xF918F5A3 Win: 0x2E TcpLen: 32 TCP Options (3) => NOP NOP TS: 340809805 1485069 [Xref => http://www.microsoft.com/technet/security/bulletin/MS01-052.mspx]