SHELLCODE: Prepend Encoder Routine Detection (TCP)

This signature detects payloads being transferred over network that use the PrependEncoder routine. This may be an indication of someone trying to drop malicious file content on targeted systems to achieve remote code execution.

Extended Description

Stack-based buffer overflow in Eureka Email 2.2q allows remote POP3 servers to execute arbitrary code via a long error message.

Affected Products

Eureka-email eureka_email

Short Name
SHELLCODE:PREPENDENCODER-TCP
Severity
Major
Recommended
False
Recommended Action
Drop
Category
SHELLCODE
Keywords
(TCP) Detection Encoder Prepend Routine
Release Date
08/19/2013
Supported Platforms

srx-branch-12.3

srx-19.3

srx-branch-19.3

vsrx3bsd-19.2

srx-branch-19.4

vsrx-19.4

mx-12.3

mx-19.4

vmx-19.4

mx-19.3

vsrx3bsd-19.4

srx-19.4

vsrx-12.3

vmx-19.3

vsrx-19.2

srx-12.3

Sigpack Version
3773
Port
TCP/1-79,81-442,444-3127,3129-7999,8001-8079,8081-65535
False Positive
Unknown
Vendors

Eureka-email

Found a potential security threat?