B-51
Cisco Intrusion Prevention System Sensor CLI Configuration Guide for IPS 7.2
OL-29168-01
Appendix B Signature Engines
Service Engines
For More Information
For more information on the parameters common to all signature engines, see Master Engine,
page B-4.
For a list of the signature regular expression syntax, see Regular Expression Syntax, page B-9.
Service MSSQL Engine
The Service MSSQL engine inspects the protocol used by the Microsoft SQL server. There is one
MSSQL signature. It fires an alert when it detects an attempt to log in to an MSSQL server with the
default sa account. You can add custom signatures based on MSSQL protocol values, such as login
username and whether a password was used.
specify-regex-string
{yes | no}
(Optional) Enables using a regular expression
string:
specify-exact-match-offset—Enables the
exact match offset:
exact-match-offset—Specifies the exact
stream offset the regular expression
string must report for a match to be
valid.
specify-min-match-length—Enables the
minimum match length:
min-match-length—Specifies the
minimum number of bytes the regular
expression string must match.
specify-min-match-offset—Enables the
minimum match length:
min-match-offset—Specifies the
minimum stream offset the regular
expression string must report for a match
to be valid.
specify-max-match-offset—Enables the
maximum match offset:
max-match-offset—Specifies the
maximum stream offset the regular
expression string must report for a match
to be valid.
0 to 65535
specify-uuid {yes | no} (Optional) Enables UUID:
uuid—Specifies the MSRPC UUID field.
000001a000000000c0000
00000000046
TableB-24 Service MSRPC Engine Parameters (continued)
Parameter Description Value