12.07.2015 Views

Symantec™ Security Gateways Reference Guide - Sawmill

Symantec™ Security Gateways Reference Guide - Sawmill

Symantec™ Security Gateways Reference Guide - Sawmill

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

IDS eventsSuspicious activity459Affected:No specific targets.False Positives: It is also possible this is a non-compliant SMTP client implementation.<strong>Reference</strong>sSMTP SpecificationsSMTP Malformed DataBase Event:Details:Response:Affected:SMTP_CLIENT_MALFORMED_COMMANDThe client sent an SMTP command to the server that was not a recognized RFC 821 command.If seen in sufficient volume or variation, and other suspicious factors exist, audit of client andserver is recommended. Examination of the packet contents may provide some additionalinformation about the particular command.No specific targets.False Positives: It is possible this is a mail client or server using an unofficial protocol extension or non-compliantSMTP implementation.<strong>Reference</strong>sSMTP SpecificationsSMTP Malformed Domain NameBase Event:Details:Response:Affected:SMTP_CLIENT_BAD_DOMAINNAMEA domain did not conform to the RFC. This may indicate an attempt to exploit a domain handlingvulnerability on the server. If seen in sufficient volume or variation audit of client and server isrecommended.If seen in sufficient volume or variation and other suspicious factors exist audit of client and serveris recommended. Examination of the packet contents may provide some additional informationabout the particular command.No specific targets.False Positives: It is possible this is simply a user or server configuration error.<strong>Reference</strong>sSMTP Specifications

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!