<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Non-SMTP Session Start Question in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/non-smtp-session-start-question/m-p/615721#M88461</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Not in my case. I have the Sig 5748/3  set to "None", but Sig 5748/0 still fires on the "XXXX" command.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 17 Jan 2008 21:12:32 GMT</pubDate>
    <dc:creator>hannatest</dc:creator>
    <dc:date>2008-01-17T21:12:32Z</dc:date>
    <item>
      <title>Non-SMTP Session Start Question</title>
      <link>https://community.cisco.com/t5/network-security/non-smtp-session-start-question/m-p/615713#M88355</link>
      <description>&lt;P&gt;I'm getting hundreds of triggers on signature 5748 Non-SMTP Session Start.      When I put a block host on this signature I stop getting e-mail.  Should this be considered normal traffic.  &lt;/P&gt;</description>
      <pubDate>Sun, 10 Mar 2019 10:28:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/non-smtp-session-start-question/m-p/615713#M88355</guid>
      <dc:creator>rrutledge</dc:creator>
      <dc:date>2019-03-10T10:28:42Z</dc:date>
    </item>
    <item>
      <title>Re: Non-SMTP Session Start Question</title>
      <link>https://community.cisco.com/t5/network-security/non-smtp-session-start-question/m-p/615714#M88383</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regarding signature 5748 firing SMTP session initiation with something other than HELO or EHLO.  See below for MySDN link on this&lt;/P&gt;&lt;P&gt;signature&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://tools.cisco.com/MySDN/Intelligence/viewSignature.x?signatureId=5748&amp;amp;signatureSubId=0" target="_blank"&gt;http://tools.cisco.com/MySDN/Intelligence/viewSignature.x?signatureId=5748&amp;amp;signatureSubId=0&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I'm assuming subsig 0.  Is this true?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This is likely a type of reconnaissance attack to see if you are running&lt;/P&gt;&lt;P&gt;an smtp service at this IP address and what type and version number of&lt;/P&gt;&lt;P&gt;smtp software you're running (i.e., Sendmail, Postfix, Microsoft&lt;/P&gt;&lt;P&gt;Exchange, etc.) as they'll get the smtp banner after their initial&lt;/P&gt;&lt;P&gt;connect.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;When you see the signature alert, who's the attacker?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You can turn on 'produce verbose alert' to see more information.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank you.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Edward&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 19 Feb 2007 20:39:31 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/non-smtp-session-start-question/m-p/615714#M88383</guid>
      <dc:creator>edwakim</dc:creator>
      <dc:date>2007-02-19T20:39:31Z</dc:date>
    </item>
    <item>
      <title>Re: Non-SMTP Session Start Question</title>
      <link>https://community.cisco.com/t5/network-security/non-smtp-session-start-question/m-p/615715#M88406</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Today the signature was triggered 2698 times, from 349 hosts (90% public addesses).  I am also seeing this triggered by local addresses, but I suppose the public one's are what I should be concerned with.  As I stated before I did try and block hosts on this signature, but I am considering adding and exception for local address, and only block public.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 19 Feb 2007 22:01:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/non-smtp-session-start-question/m-p/615715#M88406</guid>
      <dc:creator>rrutledge</dc:creator>
      <dc:date>2007-02-19T22:01:12Z</dc:date>
    </item>
    <item>
      <title>Re: Non-SMTP Session Start Question</title>
      <link>https://community.cisco.com/t5/network-security/non-smtp-session-start-question/m-p/615716#M88420</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Can you add "produce verbose alert" as an action  to 5748-0, then from the cli capture "show event alert | in id=5748" and send that to me offline at &lt;A href="mailto:wsulym@cisco.com"&gt;wsulym@cisco.com&lt;/A&gt;. I might have stumbled across something looking at some other traffic and would like to confirm.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 20 Feb 2007 14:19:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/non-smtp-session-start-question/m-p/615716#M88420</guid>
      <dc:creator>wsulym</dc:creator>
      <dc:date>2007-02-20T14:19:45Z</dc:date>
    </item>
    <item>
      <title>Re: Non-SMTP Session Start Question</title>
      <link>https://community.cisco.com/t5/network-security/non-smtp-session-start-question/m-p/615717#M88434</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;PIX smtp fixup causes this.  If you have a pix, disable the sig or disable fixup.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 20 Feb 2007 14:25:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/non-smtp-session-start-question/m-p/615717#M88434</guid>
      <dc:creator>bitterman</dc:creator>
      <dc:date>2007-02-20T14:25:17Z</dc:date>
    </item>
    <item>
      <title>Re: Non-SMTP Session Start Question</title>
      <link>https://community.cisco.com/t5/network-security/non-smtp-session-start-question/m-p/615718#M88442</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;It shouldn't. The signature looks for either HELO EHLO or XXXX at the beginning of the stream - if it's not one of those, the signature will fire. The pix uses XXXX in smtp fixup.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 20 Feb 2007 14:36:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/non-smtp-session-start-question/m-p/615718#M88442</guid>
      <dc:creator>wsulym</dc:creator>
      <dc:date>2007-02-20T14:36:11Z</dc:date>
    </item>
    <item>
      <title>Re: Non-SMTP Session Start Question</title>
      <link>https://community.cisco.com/t5/network-security/non-smtp-session-start-question/m-p/615719#M88447</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I have the fix-up for smtp disabled&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 20 Feb 2007 14:38:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/non-smtp-session-start-question/m-p/615719#M88447</guid>
      <dc:creator>rrutledge</dc:creator>
      <dc:date>2007-02-20T14:38:41Z</dc:date>
    </item>
    <item>
      <title>Re: Non-SMTP Session Start Question</title>
      <link>https://community.cisco.com/t5/network-security/non-smtp-session-start-question/m-p/615720#M88455</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I took this offline with rrutledge. Just so that there's some closure to this thread, in the end, what happened was that 'produce-alert' was set on the subsignatures, and that was what was seen flooding the event store (specifically subsigs -1 &amp;amp; -2). The subsigs will fire on normal traffic and should not have produce alert set.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 21 Feb 2007 15:06:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/non-smtp-session-start-question/m-p/615720#M88455</guid>
      <dc:creator>wsulym</dc:creator>
      <dc:date>2007-02-21T15:06:12Z</dc:date>
    </item>
    <item>
      <title>Re: Non-SMTP Session Start Question</title>
      <link>https://community.cisco.com/t5/network-security/non-smtp-session-start-question/m-p/615721#M88461</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Not in my case. I have the Sig 5748/3  set to "None", but Sig 5748/0 still fires on the "XXXX" command.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 17 Jan 2008 21:12:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/non-smtp-session-start-question/m-p/615721#M88461</guid>
      <dc:creator>hannatest</dc:creator>
      <dc:date>2008-01-17T21:12:32Z</dc:date>
    </item>
    <item>
      <title>Re: Non-SMTP Session Start Question</title>
      <link>https://community.cisco.com/t5/network-security/non-smtp-session-start-question/m-p/615722#M88471</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The IPS version is 6.0(3)E1.The triggered packets were captured.They are the 0x58 0x58 0x58 0x58.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any known bug on this signature?Thanks.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 18 Jan 2008 16:12:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/non-smtp-session-start-question/m-p/615722#M88471</guid>
      <dc:creator>hannatest</dc:creator>
      <dc:date>2008-01-18T16:12:34Z</dc:date>
    </item>
    <item>
      <title>Re: Non-SMTP Session Start Question</title>
      <link>https://community.cisco.com/t5/network-security/non-smtp-session-start-question/m-p/615723#M88479</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Still firing on xxxx in our case. We are running IPS-4260 with the signature S291.0 of 2007-06-18. The smtp payload of the triggering packet starts with xxxx.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 11 Feb 2008 15:50:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/non-smtp-session-start-question/m-p/615723#M88479</guid>
      <dc:creator>mai2mai2m</dc:creator>
      <dc:date>2008-02-11T15:50:32Z</dc:date>
    </item>
    <item>
      <title>Re: Non-SMTP Session Start Question</title>
      <link>https://community.cisco.com/t5/network-security/non-smtp-session-start-question/m-p/615724#M88485</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Are they lower case 'x' or uppercase 'X' ?  The signature only accepts uppercase as a valid start.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;SC&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 11 Feb 2008 18:30:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/non-smtp-session-start-question/m-p/615724#M88485</guid>
      <dc:creator>scothrel</dc:creator>
      <dc:date>2008-02-11T18:30:02Z</dc:date>
    </item>
    <item>
      <title>Re: Non-SMTP Session Start Question</title>
      <link>https://community.cisco.com/t5/network-security/non-smtp-session-start-question/m-p/615725#M88487</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;In my case,they are the uppercase 'X's.The start bytes are:0x58 0x58 0x58 0x58.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 11 Feb 2008 18:38:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/non-smtp-session-start-question/m-p/615725#M88487</guid>
      <dc:creator>hannatest</dc:creator>
      <dc:date>2008-02-11T18:38:21Z</dc:date>
    </item>
    <item>
      <title>Re: Non-SMTP Session Start Question</title>
      <link>https://community.cisco.com/t5/network-security/non-smtp-session-start-question/m-p/615726#M88491</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I have this sig firing very frequently.  This sig constitutes about 80-90% of all of my alerts.  Often the alert is firing on data as "RSET.."&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The source IPs are scattered, some have even had domain names associated with them, like mail.xxxxx.yyyy.com.  &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Over the course of 72 hours I have 2331 Sig 5748/0 events.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am sure that one grouped source attack IP which consists of 27 events (including summaries) in 10 minutes is most likely a malicious activity.  &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;However, about 95% of unique attacker IPs consist of only 1-3 attempts (alerts) with rarely a summary among them.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I was on the latest sig a few weeks ago.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We have so much email activity; it would be difficult to analyze packet captures for RSETs coming in immediately after the TCP handshake.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is this sig really correct? &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 09 Mar 2009 21:06:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/non-smtp-session-start-question/m-p/615726#M88491</guid>
      <dc:creator>bnidacoc</dc:creator>
      <dc:date>2009-03-09T21:06:32Z</dc:date>
    </item>
  </channel>
</rss>

