[Snort-sigs] Sid:1845 IMAP list overflow attempt

Schmehl, Paul L pauls at ...1311...
Wed Feb 26 18:56:13 EST 2003


Argh!  I saw the not, just misinterpreted what it meant.  Thanks for
clarifying it.

Paul Schmehl (pauls at ...1311...)
Adjunct Information Security Officer
The University of Texas at Dallas
AVIEN Founding Member
http://www.utdallas.edu/~pauls/



-----Original Message-----
From: Kenneth G. Arnold [mailto:bkarnold at ...1280...] 
Sent: Wednesday, February 26, 2003 8:25 PM
To: Schmehl, Paul L
Cc: snort-sigs at lists.sourceforge.net
Subject: RE: [Snort-sigs] Sid:1845 IMAP list overflow attempt


There is a ! character in front of the |0a| which means that there is no
|0a| character within the first 1024 bytes. This would be the case if
someone were trying to overflow something.  There would be a very large
distance to the |0a| character.




More information about the Snort-sigs mailing list