<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Invalid FTP Command on smtp connection in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/invalid-ftp-command-on-smtp-connection/m-p/3389811#M922003</link>
    <description>&lt;P&gt;Drill all the way down into the event to look at the packet being sent. It could be an ftp command embedded/obfuscated in the smtp protocol.&lt;/P&gt;</description>
    <pubDate>Sun, 27 May 2018 15:09:43 GMT</pubDate>
    <dc:creator>Marvin Rhoads</dc:creator>
    <dc:date>2018-05-27T15:09:43Z</dc:date>
    <item>
      <title>Invalid FTP Command on smtp connection</title>
      <link>https://community.cisco.com/t5/network-security/invalid-ftp-command-on-smtp-connection/m-p/3389790#M922002</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;we have two SMTP email gateways published on the internet, but we are getting a lot of alerts from Firepower about an invlaid FTP command going to these SMTP servers:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;[125:2:2] ftp_pp: Invalid FTP command [Impact: Potentially Vulnerable] From "p6-ips1" at Sun May 27 13:23:47 2018 UTC [Classification: Potentially Bad Traffic] [Priority: 2] {tcp} 185.55.191.197:63738 (united kingdom)-&amp;gt;10.243.252.84:25 (unknown)&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;As you can see in the alert the destination port is 25 for SMTP, so why is this detecting as an FTP connection and triggering this invalid FTP command alert?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 15:49:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/invalid-ftp-command-on-smtp-connection/m-p/3389790#M922002</guid>
      <dc:creator>matthew.goli1</dc:creator>
      <dc:date>2020-02-21T15:49:08Z</dc:date>
    </item>
    <item>
      <title>Re: Invalid FTP Command on smtp connection</title>
      <link>https://community.cisco.com/t5/network-security/invalid-ftp-command-on-smtp-connection/m-p/3389811#M922003</link>
      <description>&lt;P&gt;Drill all the way down into the event to look at the packet being sent. It could be an ftp command embedded/obfuscated in the smtp protocol.&lt;/P&gt;</description>
      <pubDate>Sun, 27 May 2018 15:09:43 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/invalid-ftp-command-on-smtp-connection/m-p/3389811#M922003</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2018-05-27T15:09:43Z</dc:date>
    </item>
    <item>
      <title>Re: Invalid FTP Command on smtp connection</title>
      <link>https://community.cisco.com/t5/network-security/invalid-ftp-command-on-smtp-connection/m-p/3389816#M922004</link>
      <description>&lt;P&gt;Hi,&amp;nbsp;&lt;/P&gt;
&lt;P&gt;i'm attaching some screen shots.&amp;nbsp; it says the offending command is:&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Capture0.PNG" style="width: 999px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/12358iEBDE80254CE12B01/image-size/large?v=v2&amp;amp;px=999" role="button" title="Capture0.PNG" alt="Capture0.PNG" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Capture1.PNG" style="width: 999px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/12359i812C13EE1FB72C00/image-size/large?v=v2&amp;amp;px=999" role="button" title="Capture1.PNG" alt="Capture1.PNG" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Capture2.PNG" style="width: 999px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/12360i177E52C560C2EF87/image-size/large?v=v2&amp;amp;px=999" role="button" title="Capture2.PNG" alt="Capture2.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Sun, 27 May 2018 15:25:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/invalid-ftp-command-on-smtp-connection/m-p/3389816#M922004</guid>
      <dc:creator>matthew.goli1</dc:creator>
      <dc:date>2018-05-27T15:25:32Z</dc:date>
    </item>
    <item>
      <title>Re: Invalid FTP Command on smtp connection</title>
      <link>https://community.cisco.com/t5/network-security/invalid-ftp-command-on-smtp-connection/m-p/3389828#M922009</link>
      <description>&lt;P&gt;That looks like legitimate smtp traffic. (smtp EHLO request)&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Could it be that your objects have been incorrectly modified? For instance, look under Objects, Object Management, Variable Set and ensure that tcp/25 (smtp) has not been added to the ftp ports listing.&lt;/P&gt;</description>
      <pubDate>Sun, 27 May 2018 17:14:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/invalid-ftp-command-on-smtp-connection/m-p/3389828#M922009</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2018-05-27T17:14:48Z</dc:date>
    </item>
    <item>
      <title>Re: Invalid FTP Command on smtp connection</title>
      <link>https://community.cisco.com/t5/network-security/invalid-ftp-command-on-smtp-connection/m-p/3390158#M922011</link>
      <description>Hello,&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;Our default variable set has FTP_PORTS set to 21, 2100 and 3535&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;[cid:image001.png@01D3F663.5055ECC0]&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;We do not have an variable for SMTP ports.&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;</description>
      <pubDate>Mon, 28 May 2018 14:07:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/invalid-ftp-command-on-smtp-connection/m-p/3390158#M922011</guid>
      <dc:creator>matthew.goli1</dc:creator>
      <dc:date>2018-05-28T14:07:45Z</dc:date>
    </item>
    <item>
      <title>Re: Invalid FTP Command on smtp connection</title>
      <link>https://community.cisco.com/t5/network-security/invalid-ftp-command-on-smtp-connection/m-p/3390159#M922013</link>
      <description>&lt;P&gt;Hmm. that covers the obvious reasons why I could think this might happen.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If you have a support contract I'd recommend opening a TAC case.&lt;/P&gt;</description>
      <pubDate>Mon, 28 May 2018 14:09:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/invalid-ftp-command-on-smtp-connection/m-p/3390159#M922013</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2018-05-28T14:09:54Z</dc:date>
    </item>
  </channel>
</rss>

