Snort mailing list archives

Re: FP's with sid:17239 - IMAP Alt-N MDaemon IMAP server CREATE command buffer overflow attempt


From: Joel Esler <jesler () sourcefire com>
Date: Tue, 12 Oct 2010 16:29:38 -0400

I had one person write me off-list telling me that the rule had not been rev'd.  However, your domain is rejecting 
emails from our domain.  

I redownloaded the rulepack and verified the rule is at rev:2.  

Joel

On Oct 12, 2010, at 1:20 PM, Eoin Miller wrote:

 alert tcp $EXTERNAL_NET any -> $HOME_NET any (msg:"IMAP Alt-N MDaemon 
IMAP server CREATE command buffer overflow attempt"; 
flow:to_server,established; content:" CREATE "; nocase; 
isdataat:180,relative; pcre:"/^[^\r\n]{180}/R"; metadata:policy 
balanced-ips drop, policy security-ips drop, service imap; 
reference:bugtraq,14315; classtype:attempted-dos; sid:17239; rev:1;)

I really can't believe this signature, it seems like it would trigger 
WAY to often. Anyone else getting a lot of hits with this?

-- Eoin

------------------------------------------------------------------------------
Beautiful is writing same markup. Internet Explorer 9 supports
standards for HTML5, CSS3, SVG 1.1,  ECMAScript5, and DOM L2 & L3.
Spend less time writing and  rewriting code and more time creating great
experiences on the web. Be a part of the beta today.
http://p.sf.net/sfu/beautyoftheweb
_______________________________________________
Snort-users mailing list
Snort-users () lists sourceforge net
Go to this URL to change user options or unsubscribe:
https://lists.sourceforge.net/lists/listinfo/snort-users
Snort-users list archive:
http://www.geocrawler.com/redir-sf.php3?list=snort-users

--
Joel Esler
302-223-5974


------------------------------------------------------------------------------
Beautiful is writing same markup. Internet Explorer 9 supports
standards for HTML5, CSS3, SVG 1.1,  ECMAScript5, and DOM L2 & L3.
Spend less time writing and  rewriting code and more time creating great
experiences on the web. Be a part of the beta today.
http://p.sf.net/sfu/beautyoftheweb
_______________________________________________
Snort-users mailing list
Snort-users () lists sourceforge net
Go to this URL to change user options or unsubscribe:
https://lists.sourceforge.net/lists/listinfo/snort-users
Snort-users list archive:
http://www.geocrawler.com/redir-sf.php3?list=snort-users


Current thread: