6.4 3000 Series—TCP Signatures
6.4.7 Mail Attack signatures
TCP port 25 attacks include:
  • Reconnaissance
  • Access
  • DOS

The following are Mail Attack Signatures:

  • 3100—smail attack (severity 5, access): This signature is triggered on the very common "smail" attack against e-mail servers. This attack attempts to cause e-mail servers to execute programs on the attacker's behalf. May result in system compromise.
  • 3101—sendmail invalid recipient (severity 5, access): This signature is triggered on any mail message with a "pipe" ( | ) symbol in the recipient field. This attack attempts to cause e-mail servers to execute programs on the attacker's behalf. May result in system compromise.
  • 3102—sendmail invalid sender (severity 5, access): This signature is triggered by any mail message with a "pipe" ( | ) symbol in the "From:" field. This attack attempts to cause e-mail servers to execute programs on the attacker's behalf. May result in system compromise.
  • 3103—sendmail reconnaissance (severity 1, reconnaissance): This signature is triggered when "expn" or "vrfy" commands are issued to the SMTP port. This indicates that your network may be under reconnaissance.
  • 3104—Archaic sendmail attacks (severity 1, information): This signature is triggered when "wiz" or "debug" commands are sent to the SMTP port. This indicates that a student of computer security history has decided to make a feeble attempt at compromising your system.
  • 3105—sendmail decode alias (severity 3, access): This signature is triggered by any mail message with ': decode@' in the header. This may indicate an attempt to illegally access system resources. System compromise is possible.
  • 3106—sendmail SPAM (severity 3, DoS): Counts number of Rcpt to: lines in a single mail message and alarms after a user-definable maximum has been exceeded (default is 250).
  • 3107—Majordomo exec bug (severity 5, access): A bug in the Majordomo program will allow remote users to execute arbitrary commands at the privilege level of the server.
  • 3108—MIME overflow bug (severity 5, access): Fires when an SMTP mail message has a MIME "Content-" field that is excessively long. The token "MimeContentMaxLen" defines the longest valid header length for MIME Content-... Header tokens. It defaults to 200 and is settable to any value greater or equal to 76.
  • 3109—Qmail Length Crash (severity 5, DoS): This signature is triggered when an attempt is made to pass an overly long command string to a mail server.