Hi,
I get the following email sent a few ramdom times during the day:
....[1:2590:0] A SMTP MAIL FROM overflow attempt [Classification: Attempted Administrator Privilege Gain] [Priority: 1]: {PROTO006} "their addr":40378 -> "our addr":25
Where their addr is the IP of our ISPs mail server! I dont belive for a min that they are doing any hacking of any sort. I have found reference to it, where by its SNORT deciphering a bad SMTP handshake as an intrusion attempt.
Anyone else seen this?
Bryan
This thread was automatically locked due to age.