TCP port 25 attacks include:
- Reconnaissance
- Access
- DOS
The following are Mail Attack
Signatures: 
- 3100—smail attack (severity 5,
access): This signature is triggered on the very common "smail"
attack against e-mail servers. This attack attempts to cause
e-mail servers to execute programs on the attacker's behalf. May
result in system compromise.
- 3101—sendmail invalid recipient
(severity 5, access): This signature is triggered on any mail
message with a "pipe" ( | ) symbol in the recipient
field. This attack attempts to cause e-mail servers to execute
programs on the attacker's behalf. May result in system
compromise.
- 3102—sendmail invalid sender
(severity 5, access): This signature is triggered by any mail
message with a "pipe" ( | ) symbol in the
"From:" field. This attack attempts to cause e-mail
servers to execute programs on the attacker's behalf. May result
in system compromise.
- 3103—sendmail reconnaissance
(severity 1, reconnaissance): This signature is triggered when
"expn" or "vrfy" commands are issued to the
SMTP port. This indicates that your network may be under
reconnaissance.
- 3104—Archaic sendmail attacks
(severity 1, information): This signature is triggered when
"wiz" or "debug" commands are sent to the SMTP
port. This indicates that a student of computer security history
has decided to make a feeble attempt at compromising your system.
- 3105—sendmail decode alias
(severity 3, access): This signature is triggered by any mail
message with ': decode@' in the header. This may indicate an
attempt to illegally access system resources. System compromise is
possible.
- 3106—sendmail SPAM (severity 3,
DoS): Counts number of Rcpt to: lines in a single mail message and
alarms after a user-definable maximum has been exceeded (default
is 250).
- 3107—Majordomo exec bug (severity
5, access): A bug in the Majordomo program will allow remote users
to execute arbitrary commands at the privilege level of the
server.
- 3108—MIME overflow bug (severity
5, access): Fires when an SMTP mail message has a MIME
"Content-" field that is excessively long. The token
"MimeContentMaxLen" defines the longest valid header
length for MIME Content-... Header tokens. It defaults to 200 and
is settable to any value greater or equal to 76.
- 3109—Qmail Length Crash (severity
5, DoS): This signature is triggered when an attempt is made to
pass an overly long command string to a mail server.
|