Hmmm... There seem to be lots of mailers sending garbage like this that
tickles this rule :(
I had 16,000 hits from 1200 different sources.
Russell
| META |
| SID |
CID |
TimeStamp |
Signature |
Sig ID |
| 6 |
10582363 |
2007-11-29 11:16:10 |
SMTP ClamAV recipient command injection attempt |
12592 |
| Sensor Hostname |
Sensor Interface |
| monitor-dmzo.isec.auckland.ac.nz |
dmz sensor |
|
| IP |
| Source Address |
Dest Address |
Ver |
Hdr Len |
TOS |
length |
ID |
flags |
offset |
TTL |
chksum |
| 199.72.18.130 |
130.216.190.11 |
4 |
5 |
0 |
75 |
63371 |
2 |
0 |
111 |
63858 |
| Resolved Source |
Resolved Dest |
| server.tescopower.com |
groucho.itss.auckland.ac.nz |
|
| TCP |
| Source Port |
Dest Port |
Seq |
Ack |
Offset |
Reserved |
Flags |
Window |
Checksum |
Urgent Ptr |
| 4400 |
25 |
484684468 |
2761840731 |
5 |
0 |
24 |
17233 |
31021 |
0 |
| Flags |
|
| RB 1 |
RB 0 |
URG |
ACK |
PSH |
RST |
SYN |
FIN |
|
|
|
X |
X |
|
|
|
|
|
-------------------------------------------------------------------------
SF.Net email is sponsored by: The Future of Linux Business White Paper
from Novell. From the desktop to the data center, Linux is going
mainstream. Let it simplify your IT future.
http://altfarm.mediaplex.com/ad/ck/8857-50307-18918-4
_______________________________________________
Snort-sigs mailing list
Snort-sigs@lists.sourceforge.net
https://lists.sourceforge.net/lists/listinfo/snort-sigs