Snort mailing list archives

FP's with sid:17239 - IMAP Alt-N MDaemon IMAP server CREATE command buffer overflow attempt


From: Eoin Miller <eoin.miller () trojanedbinaries com>
Date: Tue, 12 Oct 2010 17:20:35 +0000

  alert tcp $EXTERNAL_NET any -> $HOME_NET any (msg:"IMAP Alt-N MDaemon 
IMAP server CREATE command buffer overflow attempt"; 
flow:to_server,established; content:" CREATE "; nocase; 
isdataat:180,relative; pcre:"/^[^\r\n]{180}/R"; metadata:policy 
balanced-ips drop, policy security-ips drop, service imap; 
reference:bugtraq,14315; classtype:attempted-dos; sid:17239; rev:1;)

I really can't believe this signature, it seems like it would trigger 
WAY to often. Anyone else getting a lot of hits with this?

-- Eoin

------------------------------------------------------------------------------
Beautiful is writing same markup. Internet Explorer 9 supports
standards for HTML5, CSS3, SVG 1.1,  ECMAScript5, and DOM L2 & L3.
Spend less time writing and  rewriting code and more time creating great
experiences on the web. Be a part of the beta today.
http://p.sf.net/sfu/beautyoftheweb
_______________________________________________
Snort-users mailing list
Snort-users () lists sourceforge net
Go to this URL to change user options or unsubscribe:
https://lists.sourceforge.net/lists/listinfo/snort-users
Snort-users list archive:
http://www.geocrawler.com/redir-sf.php3?list=snort-users


Current thread: