Snort mailing list archives

Rule ID question


From: Bobby Venal <bobby.venal () gmail com>
Date: Thu, 16 Sep 2010 08:32:44 -0600

Hi all,

Noob question here, but I saw an alert with the following:

"SID: 9003461.1: SMTP Content-Type overflow attempt"

When I search /etc/sid-msg.map, I find this entry:

"3461 || SMTP Content-Type overflow attempt || bugtraq,7419 ||
cve,2003-0113 ||
url,www.microsoft.com/technet/security/bulletin/MS03-015.mspx"

What is that prepended "900" in the log entry?  I thought it might be
GID, but I'm not seeing "900" in my gen-msg.map file.




Thanks,
Bobby

------------------------------------------------------------------------------
Start uncovering the many advantages of virtual appliances
and start using them to simplify application deployment and
accelerate your shift to cloud computing.
http://p.sf.net/sfu/novell-sfdev2dev
_______________________________________________
Snort-users mailing list
Snort-users () lists sourceforge net
Go to this URL to change user options or unsubscribe:
https://lists.sourceforge.net/lists/listinfo/snort-users
Snort-users list archive:
http://www.geocrawler.com/redir-sf.php3?list=snort-users


Current thread: