SCAN: Cybercop SMTP ehlo
This signature detects attempts to scan the system using CyberCop Scanner. Attackers can be attempting to use the command "ehlo" to determine if the mailer daemon supports extended SMTP commands (Mail transport agents use "ehlo" to find out which extended SMTP commands a remote mailer accepts).
Extended Description
Scanning tools are often used by hackers to determine which networks they may be able to break into.
References
CVE: CVE-1999-0531
srx-branch-12.3
srx-19.3
srx-branch-19.3
vsrx3bsd-19.2
srx-branch-19.4
vsrx-19.4
mx-12.3
mx-19.4
vmx-19.4
mx-19.3
vsrx3bsd-19.4
srx-19.4
vsrx-12.3
vmx-19.3
vsrx-19.2
srx-12.3