cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
2060
Views
0
Helpful
5
Replies

Invalid FTP Command on smtp connection

matthew.goli1
Level 1
Level 1

Hello,

 

we have two SMTP email gateways published on the internet, but we are getting a lot of alerts from Firepower about an invlaid FTP command going to these SMTP servers:

 

[125:2:2] ftp_pp: Invalid FTP command [Impact: Potentially Vulnerable] From "p6-ips1" at Sun May 27 13:23:47 2018 UTC [Classification: Potentially Bad Traffic] [Priority: 2] {tcp} 185.55.191.197:63738 (united kingdom)->10.243.252.84:25 (unknown)

 

As you can see in the alert the destination port is 25 for SMTP, so why is this detecting as an FTP connection and triggering this invalid FTP command alert?

 

 

5 Replies 5

Marvin Rhoads
Hall of Fame
Hall of Fame

Drill all the way down into the event to look at the packet being sent. It could be an ftp command embedded/obfuscated in the smtp protocol.

Hi, 

i'm attaching some screen shots.  it says the offending command is:


Capture0.PNGCapture1.PNGCapture2.PNG

That looks like legitimate smtp traffic. (smtp EHLO request)

 

Could it be that your objects have been incorrectly modified? For instance, look under Objects, Object Management, Variable Set and ensure that tcp/25 (smtp) has not been added to the ftp ports listing.

Hello,



Our default variable set has FTP_PORTS set to 21, 2100 and 3535



[cid:image001.png@01D3F663.5055ECC0]





We do not have an variable for SMTP ports.






Hmm. that covers the obvious reasons why I could think this might happen.

 

If you have a support contract I'd recommend opening a TAC case.

Review Cisco Networking for a $25 gift card