Project

General

Profile

Actions

Bug #5491

open

SMTP response 221 appears to generate an SMTP invalid response alert

Added by Orion Poplawski over 1 year ago. Updated 6 months ago.

Status:
New
Priority:
Normal
Assignee:
Target version:
Affected Versions:
Effort:
Difficulty:
Label:

Description

We have a public facing mail server and we see a lot of SMTP invalid reply alerts when it issues a response like:

530 5.7.0 Must issue a STARTTLS command first
221 2.0.0 Bye

Now, I suppose this is indication of a failed attempt to send mail through it, but it’s not really an “invalid reply” and it’s not unexpected.

Actions #1

Updated by Philippe Antoine 6 months ago

Could you provide a pcap or a suricata-verify test for this ?

Actions

Also available in: Atom PDF