Using AMP8150 with 5.3.0.3
I see a sig tripping that shouldn't be. 1:655:16.
Sig:
alert tcp $EXTERNAL_NET 113 -> $SMTP_SERVERS 25 (msg:"SERVER-MAIL Sendmail 8.6.9 exploit"; flow:to_server,established; content:"|0A|D/"; metadata:ruleset community, service smtp; reference:bugtraq,2311; reference:cve,1999-0204; classtype:attempted-admin; sid:655; rev:16; )
The device is able to detect the system is a Windows system with network/host discovery- obviously not running Sendmail. Why does this rule keep firing when Sourcefire sees Sendmail is not running?