I keep getting the following message
Intrusion Protection Alert
Details about the intrusion alert:
Message........: SMTP expn cybercop attempt
Details........: http://www.snort.org/pub-bin/sigs.cgi?sid=632
Time...........: 2006:04:30-21:45:03
Packet dropped.: yes
Priority.......: 3 (low)
Classification.: Generic Protocol Command Decode
IP protocol....: 6 (TCP)
The source ip is my firewall while the destination ip is my email server. First it would get delivered to the admin address, now it gets caught in my proxy content manager.
I get 5 every 30 minutes. Can someone tell me why this just started happening and how I can get it to stop?
Thanks
This thread was automatically locked due to age.