""GPL IMAP Overflow Attempt""

SID: 2100293

Revision: 8

Class Type: attempted-admin

Metadata: created_at 2010_09_23, updated_at 2012_09_13

Reference:

Protocol: tcp

Source Network: $EXTERNAL_NET

Source Port: any

Destination Network: $HOME_NET

Destination Port: 143

Flow: to_server,established

Contents:

  • Value: "|E8 C0 FF FF FF|/bin/sh"

Within:

PCRE:

Special Options:

source