05-27-2018 06:28 AM - edited 02-21-2020 07:49 AM
Hello,
we have two SMTP email gateways published on the internet, but we are getting a lot of alerts from Firepower about an invlaid FTP command going to these SMTP servers:
[125:2:2] ftp_pp: Invalid FTP command [Impact: Potentially Vulnerable] From "p6-ips1" at Sun May 27 13:23:47 2018 UTC [Classification: Potentially Bad Traffic] [Priority: 2] {tcp} 185.55.191.197:63738 (united kingdom)->10.243.252.84:25 (unknown)
As you can see in the alert the destination port is 25 for SMTP, so why is this detecting as an FTP connection and triggering this invalid FTP command alert?
05-27-2018 08:09 AM
Drill all the way down into the event to look at the packet being sent. It could be an ftp command embedded/obfuscated in the smtp protocol.
05-27-2018 08:25 AM
Hi,
i'm attaching some screen shots. it says the offending command is:
05-27-2018 10:14 AM - edited 05-27-2018 10:14 AM
That looks like legitimate smtp traffic. (smtp EHLO request)
Could it be that your objects have been incorrectly modified? For instance, look under Objects, Object Management, Variable Set and ensure that tcp/25 (smtp) has not been added to the ftp ports listing.
05-28-2018 07:07 AM
05-28-2018 07:09 AM
Hmm. that covers the obvious reasons why I could think this might happen.
If you have a support contract I'd recommend opening a TAC case.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide