12.07.2015 Views

Symantec™ Security Gateways Reference Guide - Sawmill

Symantec™ Security Gateways Reference Guide - Sawmill

Symantec™ Security Gateways Reference Guide - Sawmill

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

458 IDS eventsSuspicious activitySMTP Malformed DataBase Event:Details:Response:Affected:SMTP_BAD_SERVER_BANNERThe SMTP server sent an unrecognized banner at the start of an SMTP session. It is possible thiscould indicate a compromised server.If seen in sufficient volume or variation, and other suspicious factors exist, audit of client andserver is recommended. Examination of the packet contents may provide some additionalinformation about the particular command.No specific targets.False Positives: It is possible this is a server configuration error.<strong>Reference</strong>sSMTP SpecificationsSMTP Malformed DataBase Event:Details:Response:Affected:SMTP_BAD_SERVER_DATAA catch all error event indicating that the data sent from the SMTP server was not recognized ascomplying with the SMTP RFCs. It is possible that this represents an attack on the SMTP server.If seen in sufficient volume or variation, and other suspicious factors exist, audit of client andserver is recommended. Examination of the packet contents may provide some additionalinformation about the particular command.No specific targets.False Positives: It is also possible that this is either something tunneling on the SMTP port or some unusualextension or data being passed over SMTP.<strong>Reference</strong>sSMTP SpecificationsSMTP Malformed DataBase Event:Details:Response:Affected:SMTP_CLIENT_BAD_BDAT_ARGThe client sent an invalid argument to the SMTP BDAT command.If seen in sufficient volume or variation, and other suspicious factors exist, audit of client andserver is recommended. Examination of the packet contents may provide some additionalinformation about the particular command.No specific targets.False Positives: It is possible that this is a mail client or server using an unofficial protocol extension or noncompliantSMTP implementation.<strong>Reference</strong>sSMTP SpecificationsSMTP Malformed DataBase Event:Details:Response:SMTP_CLIENT_DATA_BEFORE_HELOThe SMTP client sent something other than a HELO command at the start of the SMTP session.Well behaved clients should start a connection with a HELO. It is possible this represents a manualprobe of the server.If seen in sufficient volume or variation, and other suspicious factors exist, audit of client andserver is recommended. Examination of the packet contents may provide some additionalinformation about the particular command.

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!