[Snort-users] Rule ID question

Bobby Venal bobby.venal at ...11827...
Thu Sep 16 10:32:44 EDT 2010


Hi all,

Noob question here, but I saw an alert with the following:

"SID: 9003461.1: SMTP Content-Type overflow attempt"

When I search /etc/sid-msg.map, I find this entry:

"3461 || SMTP Content-Type overflow attempt || bugtraq,7419 ||
cve,2003-0113 ||
url,www.microsoft.com/technet/security/bulletin/MS03-015.mspx"

What is that prepended "900" in the log entry?  I thought it might be
GID, but I'm not seeing "900" in my gen-msg.map file.




Thanks,
Bobby




More information about the Snort-users mailing list