[Snort-users] Rule ID question

Bobby Venal bobby.venal at ...11827...
Thu Sep 16 10:32:44 EDT 2010

Hi all,

Noob question here, but I saw an alert with the following:

"SID: 9003461.1: SMTP Content-Type overflow attempt"

When I search /etc/sid-msg.map, I find this entry:

"3461 || SMTP Content-Type overflow attempt || bugtraq,7419 ||
cve,2003-0113 ||

What is that prepended "900" in the log entry?  I thought it might be
GID, but I'm not seeing "900" in my gen-msg.map file.


More information about the Snort-users mailing list