[Snort-sigs] Sid:1845 IMAP list overflow attempt

Schmehl, Paul L pauls at ...1311...
Wed Feb 26 18:56:13 EST 2003

Argh!  I saw the not, just misinterpreted what it meant.  Thanks for
clarifying it.

Paul Schmehl (pauls at ...1311...)
Adjunct Information Security Officer
The University of Texas at Dallas
AVIEN Founding Member

-----Original Message-----
From: Kenneth G. Arnold [mailto:bkarnold at ...1280...] 
Sent: Wednesday, February 26, 2003 8:25 PM
To: Schmehl, Paul L
Cc: snort-sigs at lists.sourceforge.net
Subject: RE: [Snort-sigs] Sid:1845 IMAP list overflow attempt

There is a ! character in front of the |0a| which means that there is no
|0a| character within the first 1024 bytes. This would be the case if
someone were trying to overflow something.  There would be a very large
distance to the |0a| character.

More information about the Snort-sigs mailing list