2019-06-14 15:16:48 +00:00
|
|
|
|
NEW
|
|
|
|
|
AUTO 3,1
|
|
|
|
|
*--------------------------------------
|
|
|
|
|
TCP.PORT.CIFS .EQ 445
|
|
|
|
|
*--------------------------------------
|
2020-06-17 19:05:36 +00:00
|
|
|
|
S.SMB.H.PROTO .EQ 0 \xFF 'SMB'
|
|
|
|
|
S.SMB.H.CMD .EQ 4
|
|
|
|
|
S.SMB.H.CMD.TRANSACTION2 .EQ $32
|
|
|
|
|
S.SMB.H.CMD.NEGOTIATE .EQ $72
|
|
|
|
|
S.SMB.H.CMD.SESSION.SETUP.ANDX .EQ $73
|
|
|
|
|
S.SMB.H.CMD.TREE.CONNECT.ANDX .EQ $75
|
|
|
|
|
S.SMB.H.STATUS .EQ 5
|
|
|
|
|
S.SMB.H.FLAGS .EQ 9
|
|
|
|
|
S.SMB.H.FLAGS.LOCKANDREADOK .EQ 1
|
|
|
|
|
S.SMB.H.FLAGS.REPLY .EQ 128
|
|
|
|
|
S.SMB.H.FLAGS2 .EQ 10
|
|
|
|
|
S.SMB.H.FLAGS2.LONGNAMES .EQ %00000000.01000001
|
|
|
|
|
S.SMB.H.FLAGS2.EAS .EQ %00000000.00000010
|
|
|
|
|
S.SMB.H.FLAGS2.SECSIGN .EQ %00000000.00000100
|
|
|
|
|
S.SMB.H.FLAGS2.DFS .EQ %00010000.00000000
|
|
|
|
|
S.SMB.H.FLAGS2.READIFEXEC .EQ %00100000.00000000
|
|
|
|
|
S.SMB.H.FLAGS2.NTSTATUS .EQ %01000000.00000000
|
|
|
|
|
S.SMB.H.FLAGS2.UNICODE .EQ %10000000.00000000
|
|
|
|
|
S.SMB.H.PIDHI .EQ 12
|
|
|
|
|
S.SMB.H.SECFEAT .EQ 14
|
|
|
|
|
S.SMB.H.RSVD .EQ 22
|
|
|
|
|
S.SMB.H.TID .EQ 24
|
|
|
|
|
S.SMB.H.PIDLO .EQ 26
|
|
|
|
|
S.SMB.H.UID .EQ 28
|
|
|
|
|
S.SMB.H.MID .EQ 30
|
2019-06-14 15:16:48 +00:00
|
|
|
|
*
|
2020-06-17 19:05:36 +00:00
|
|
|
|
S.SMB.H .EQ 32
|
2019-06-14 15:16:48 +00:00
|
|
|
|
*--------------------------------------
|
|
|
|
|
MAN
|
|
|
|
|
SAVE INC/NET.SMB.I
|