We are MSSP and one of our clients is generating lots Buffer Overflow Exploit from source 196.35.77.17.This source is IS SMTP relay server that relays mail to client network.
Now we are picking up this Buffer Overflow Exploit from this source.
Can this mean that this signature is a false positve from misconfigured IS server?
Any sugestion please