Matt Kettler mkettler at ...189...
Fri Apr 4 13:31:05 EST 2003

He's actually looking for a signature for the latest sendmail exploit (CERT 
CA-2003-12) . As far as I know, nobody's written a signature.

Since this is a buffer-overflow in mime decoding, I don't think a 
general-case snort rule for this exploit will be possible. There's too many 
permutations possible for a simple signature to detect it. It might be 
possible to write a dedicated preprocessor to examine it.

However, should a given rootkit or worm start exploiting this, it should be 
easy to signature that particular form of exploit for the issue.

Really, with the max mime header length option in the latest sendmail, this 
should be sufficient on it's own to detect attack attempts against a single 
server, but doesn't give you network-wide visibility.

