[Snort-users] FP's with sid:17239 - IMAP Alt-N MDaemon IMAP server CREATE command buffer overflow attempt

Joel Esler jesler at ...1935...
Tue Oct 12 16:29:38 EDT 2010

I had one person write me off-list telling me that the rule had not been rev'd.  However, your domain is rejecting emails from our domain.  

I redownloaded the rulepack and verified the rule is at rev:2.  


On Oct 12, 2010, at 1:20 PM, Eoin Miller wrote:

>  alert tcp $EXTERNAL_NET any -> $HOME_NET any (msg:"IMAP Alt-N MDaemon 
> IMAP server CREATE command buffer overflow attempt"; 
> flow:to_server,established; content:" CREATE "; nocase; 
> isdataat:180,relative; pcre:"/^[^\r\n]{180}/R"; metadata:policy 
> balanced-ips drop, policy security-ips drop, service imap; 
> reference:bugtraq,14315; classtype:attempted-dos; sid:17239; rev:1;)
> I really can't believe this signature, it seems like it would trigger 
> WAY to often. Anyone else getting a lot of hits with this?
> -- Eoin
> ------------------------------------------------------------------------------
> Beautiful is writing same markup. Internet Explorer 9 supports
> standards for HTML5, CSS3, SVG 1.1,  ECMAScript5, and DOM L2 & L3.
> Spend less time writing and  rewriting code and more time creating great
> experiences on the web. Be a part of the beta today.
> http://p.sf.net/sfu/beautyoftheweb
> _______________________________________________
> Snort-users mailing list
> Snort-users at lists.sourceforge.net
> Go to this URL to change user options or unsubscribe:
> https://lists.sourceforge.net/lists/listinfo/snort-users
> Snort-users list archive:
> http://www.geocrawler.com/redir-sf.php3?list=snort-users

Joel Esler

More information about the Snort-users mailing list