# policy for IMAP signatures

**URL:** <https://community.zeek.org/t/policy-for-imap-signatures/428>\
**Category:** Zeek\
**Created:** [November 13, 2003, 9:44pm UTC](https://community.zeek.org/t/policy-for-imap-signatures/428 "2003-11-13T21:44:27Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![Nimit\_Sawhney](https://avatars.discourse-cdn.com/v4/letter/n/b9bd4f/32.png) [@Nimit\_Sawhney](https://community.zeek.org/u/Nimit_Sawhney)\
**Post date:** [November 13, 2003, 9:44pm UTC](https://community.zeek.org/t/policy-for-imap-signatures/428/1 "2003-11-13T21:44:27Z")

</div>

Hi,

I am attempting to write a policy script for IMAP signatures  
adapted from Snort using 'snort2bro'. Is this the right way  
to write a policy script for the sample signatures below? I  
am not sure how to treat the 'tcp-state' part? Also, is it  
neccessary to use 'eval' each time?

Suggestions/Pointers??

Thanks,  
-N\*

---

<div class="post-metadata">

**Author:** ![robin](https://yyz1.discourse-cdn.com/flex011/user_avatar/community.zeek.org/robin/32/599_2.png) [@robin](https://community.zeek.org/u/robin)\
**Post date:** [November 13, 2003, 11:05pm UTC](https://community.zeek.org/t/policy-for-imap-signatures/428/2 "2003-11-13T23:05:50Z")

</div>

> I am attempting to write a policy script for IMAP signatures  
> adapted from Snort using 'snort2bro'. Is this the right way  
> to write a policy script for the sample signatures below? I

I'm not exactly sure what you would like to achieve. If you just  
want to get the same functionality that Snort provides for these  
cases, you can just use the converted sid-1930/sid-1902 signatures.  
No additional signatures are needed then.

If you want to enhance the Snort signatures, you can write  
additional Bro signatures which take some more context into account.  
If this is the case, perhaps could describe a little bit more what  
you would like to do?

> signature imap\_auth\_overflow {  
> &nbsp;&nbsp;requires-signature sid-1930  
> &nbsp;&nbsp;eval has\_imapauthoverflow\_been\_attempted  
> &nbsp;&nbsp;event "Host may have been probed for IMAP auth overflow"  
> &nbsp;&nbsp;}

As written this signature will match for a given connection if (1)  
signature sid-1930 matches for the same connection, and if (2) the  
function "has\_imapauthoverflow\_been\_attempted" evaluates to true.  
The latter happens if the same signature sid-1930 has already  
matched for any connection between the originator and the  
responder. I guess this is not what you had intended, is it?

With respect to tcp-state: Actually, this is currently ignored. The  
code is implemented, but it turned out that using it made it even  
more difficult to compare Bro's matches with those from Snort (which  
isn't a problem of Bro as its TCP state decoding is actually quite  
sophisticated). Eventually, we will change this.

Robin

---

<div class="post-metadata">

**Author:** ![Nimit\_Sawhney](https://avatars.discourse-cdn.com/v4/letter/n/b9bd4f/32.png) [@Nimit\_Sawhney](https://community.zeek.org/u/Nimit_Sawhney)\
**Post date:** [November 13, 2003, 11:46pm UTC](https://community.zeek.org/t/policy-for-imap-signatures/428/3 "2003-11-13T23:46:53Z")

</div>

> Robin Sommer wrote:
> 
> As written this signature will match for a given connection if (1)  
> signature sid-1930 matches for the same connection, and if (2) the  
> function "has\_imapauthoverflow\_been\_attempted" evaluates to true.  
> The latter happens if the same signature sid-1930 has already  
> matched for any connection between the originator and the  
> responder. I guess this is not what you had intended, is it?

You are right. Simply speaking, I would like to do this:  
When an IMAP signature-A is detected, I would like to trigger  
an external program/function-B which performs some defensive  
measures (like updating the router to block any more requests  
from the offending client IP). It looks now that the 'eval'  
function is not the right place to do something like this. I  
guess I need to define an event handler instead?

> With respect to tcp-state: Actually, this is currently ignored. The  
> code is implemented, but it turned out that using it made it even  
> more difficult to compare Bro's matches with those from Snort (which  
> isn't a problem of Bro as its TCP state decoding is actually quite  
> sophisticated). Eventually, we will change this.

Thanks for the update on the tcp-state stuff.

best,  
-Nimit

---

<div class="post-metadata">

**Author:** ![robin](https://yyz1.discourse-cdn.com/flex011/user_avatar/community.zeek.org/robin/32/599_2.png) [@robin](https://community.zeek.org/u/robin)\
**Post date:** [November 14, 2003, 12:18am UTC](https://community.zeek.org/t/policy-for-imap-signatures/428/4 "2003-11-14T00:18:24Z")

</div>

Yes, right. Define a signature\_match() handler  
and check if the triggering signature is one of those for which you  
would like the action to be taken.

Actually, for things like this it would be better if you could  
specify some other handler than signature\_match() within signature.  
I will probably add this eventually.

Robin

---

<div class="post-metadata">

**Author:** ![system](https://canada1.discourse-cdn.com/flex011/uploads/zeek/original/1X/f09d732bc2cc7c7cc7e35db67cf4e1d5233ce7a7.png) [@system](https://community.zeek.org/u/system)\
**Post date:** [May 6, 2022, 3:36pm UTC](https://community.zeek.org/t/policy-for-imap-signatures/428/5 "2022-05-06T15:36:52Z")

</div>


