SMTP: Duplicate "HELO"

This protocol anomaly triggers when it detects two HELO commands on the same SMTP connection. SMTP clients and servers issue HELO only once. This can indicate an attacker or an exploit script manually trying to send commands to an SMTP server.

Extended Description

This protocol anomaly could enable a remote attacker to deny service to an SMTP server user.

Short Name
SMTP:REQERR:REQ-DUPLICATE-HELLO
Severity
Warning
Recommended
False
Recommended Action
None
Category
SMTP
Release Date
08/27/2003
Supported Platforms

srx-branch-12.3

srx-19.3

srx-branch-19.3

vsrx3bsd-19.2

srx-branch-19.4

vsrx-19.4

mx-12.3

mx-19.4

vmx-19.4

mx-19.3

vsrx3bsd-19.4

srx-19.4

vsrx-12.3

vmx-19.3

vsrx-19.2

srx-12.3

Sigpack Version
3324
False Positive
Unknown

Found a potential security threat?