I'm seeing regular FPs for this rule on sessions to our mail server
from several different sites.
Russell
| META |
| SID |
CID |
TimeStamp |
Signature |
Sig ID |
| 6 |
5890854 |
2007-05-12 02:32:03 |
SMTP SSLv3 openssl get shared ciphers overflow attempt |
8435 |
| Sensor Hostname |
Sensor Interface |
| monitor-dmzo.isec.auckland.ac.nz |
dmz sensor |
|
| IP |
| Source Address |
Dest Address |
Ver |
Hdr Len |
TOS |
length |
ID |
flags |
offset |
TTL |
chksum |
| 202.83.76.34 |
130.216.190.13 |
4 |
5 |
0 |
130 |
34926 |
2 |
0 |
111 |
11180 |
| Resolved Source |
Resolved Dest |
| smart-e.com.au |
harpo.itss.auckland.ac.nz |
|
| TCP |
| Source Port |
Dest Port |
Seq |
Ack |
Offset |
Reserved |
Flags |
Window |
Checksum |
Urgent Ptr |
| 1609 |
25 |
1364059628 |
3379635126 |
5 |
0 |
24 |
17318 |
56262 |
0 |
| Flags |
|
| RB 1 |
RB 0 |
URG |
ACK |
PSH |
RST |
SYN |
FIN |
|
|
|
X |
X |
|
|
|
|
| DATA |
16030000550100005103
0046447E1DA2E4F42BEB
23C1DEB23AE5A56892CF
ADBCD6DDA774D96786FF
5E077A00002A00160013
000A0066000700050004
00650064006300620061
00600015001200090014
00110008000600030100
|
....U...Q.
.FD~....+.
#...:..h..
.....t.g..
^.z..*....
...f......
.e.d.c.b.a
.`........
..........
|
|
|
-------------------------------------------------------------------------
This SF.net email is sponsored by DB2 Express
Download DB2 Express C - the FREE version of DB2 express and take
control of your XML. No limits. Just data. Click to get it now.
http://sourceforge.net/powerbar/db2/
_______________________________________________
Snort-sigs mailing list
Snort-sigs@lists.sourceforge.net
https://lists.sourceforge.net/lists/listinfo/snort-sigs