Re: Alerts of the ICMP relationship with smtp connection?
From: Paulo (listassec_at_yahoo.com)
Date: 06/10/05
- Previous message: David Gillett: "RE: IP announce DOS"
- Next in thread: Micheal Espinola Jr: "Re: Alerts of the ICMP relationship with smtp connection?"
- Reply: Micheal Espinola Jr: "Re: Alerts of the ICMP relationship with smtp connection?"
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ] [ attachment ]
Date: Fri, 10 Jun 2005 05:44:44 -0700 (PDT) To: SecurityBasics SF <security-basics@securityfocus.com>
Hi,
I have a new information about this case. The receiver
mail server is a Merak Mail Server Software 8.0.3.
Does someone know this server? Does it make ICMP
request during the receiving of the e-mail?
Thanks again.
--- Paulo <listassec@yahoo.com> wrote:
> Hi,
>
> I am using Snort version Version 2.3.2 (Build 12).
> I have in my snort logs the alerts:
>
> 366 - ICMP Ping *nix
> 384 - ICMP Ping
> 368 - Ping BSDtype
>
> I investigated my others systems logs and in the
> time
> that this alert is recorded is the same that
> registered smtp connection in the maillog arquive
> from
> my postfix server.
>
> The source IP address in snort's log is equal the
> destination IP address in the maillog to smtp
> connection.
>
> My smtp server is a Postfix version 1.1.3.
>
> This alerts can to be generated by my mail server
> when
> it sends mails?
>
> Is this alerts a false positive?
>
> Thanks by help
>
>
> __________________________________________________
> Do You Yahoo!?
> Tired of spam? Yahoo! Mail has the best spam
> protection around
> http://mail.yahoo.com
>
__________________________________
Yahoo! Mail Mobile
Take Yahoo! Mail with you! Check email on your mobile phone.
http://mobile.yahoo.com/learn/mail
- Previous message: David Gillett: "RE: IP announce DOS"
- Next in thread: Micheal Espinola Jr: "Re: Alerts of the ICMP relationship with smtp connection?"
- Reply: Micheal Espinola Jr: "Re: Alerts of the ICMP relationship with smtp connection?"
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ] [ attachment ]
Relevant Pages
|