[Snort-sigs] new rule : SMTP Elm buffer overflow attempt

rmkml rmkml at ...324...
Sat Aug 27 14:09:28 EDT 2005


Hi,

please add new rule for detect "SMTP Elm buffer overflow attempt" :

smtp.rules:alert tcp $EXTERNAL_NET any -> $SMTP_SERVERS 25 (msg:"SMTP Elm 
buffer overflow attempt"; flow:to_server,established; pcre:"/^Expires\:.{66,}/smi"; reference:bugtraq,14613; reference:cve,2005-2665; reference:osvdb,18914; classtype:misc-activity; )

Regards
Rmkml




More information about the Snort-sigs mailing list