This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

IDS blocking SMTP-Proxy Snort SID 13894 (False Positive?)

ASG 8.102, SMTP-Proxy enabled, ASG (192.168.130.1) is acting as MX and relays mails to an internal SMTP-Server (192.168.130.101).

Tonight, IPS blocked Astaros SMTP-Proxy from relaying one email to the internal SMTP-Server with the following intrusion prevention alert:

##################################
Intrusion Prevention Alert

An intrusion has been detected. The packet has been dropped automatically.
You can toggle this rule between "drop" and "alert only" in WebAdmin.

Details about the intrusion alert:

Message........: SMTP Microsoft Outlook Web Access From field cross-site scripting attempt
Details........: Snort ::
Time...........: 2011:02:23-06:07:00
Packet dropped.: yes
Priority.......: 2medium
Classification.: Misc Attack
IP protocol....: 6 (TCP)

Source IP address: 192.168.130.1 (mx)
Where are my results?
Query the RIPE Database
http://ws.arin.net/cgi-bin/whois.pl?queryinput=192.168.130.1
APNIC - Query the APNIC Whois Database
Source port: 44456
Destination IP address: 192.168.130.101 
Where are my results?
Query the RIPE Database
http://ws.arin.net/cgi-bin/whois.pl?queryinput=192.168.130.101
APNIC - Query the APNIC Whois Database
Destination port: 25 (smtp)
##################################

All other emails seem to get through with no problems.
I tried to look this IDS rule up but the Snort-Website tells me that "This rule does not exist in our database.".
So now I'm unsure whether it is a false positive and whether I should release the mail by temporarily disabling snort.

Any hints are welcome!!

Cheers!


This thread was automatically locked due to age.
  • I've seent that triggered as a false positive before; however, I can't say one way or another whether this is the case for you... I suggest you look at the traffic that triggers the rule and decide.  I will say I have seen this at a few sites, and in all cases thus far, they were false positives.

    CTO, Convergent Information Security Solutions, LLC

    https://www.convergesecurity.com

    Advice given as posted on this forum does not construe a support relationship or other relationship with Convergent Information Security Solutions, LLC or its subsidiaries.  Use the advice given at your own risk.