216acd80d6c751386e7ac1bf6aef1895cfbe8284
[ossec-hids.git] / etc / rules / sendmail_rules.xml
1 <!-- @(#) $Id$
2   -  Official sendmail rules for OSSEC.
3   -  Author: Ahmet Ozturk
4   -  Author: Daniel B. Cid
5   -  License: http://www.ossec.net/en/licensing.html
6   -->
7       
8
9 <group name="syslog,sendmail,">
10   <rule id="3100" level="0">
11     <decoded_as>sendmail-reject</decoded_as>
12     <description>Grouping of the sendmail rules.</description>
13   </rule>
14
15   <rule id="3101" level="0" noalert="1">
16     <if_sid>3100</if_sid>
17     <match>reject=</match>
18     <description>Grouping of the sendmail reject rules.</description>
19   </rule>
20   
21   <rule id="3102" level="5">
22     <if_sid>3101</if_sid>
23     <match>reject=451 4.1.8 </match>
24     <description>Sender domain does not have any valid </description>
25     <description>MX record (Requested action aborted).</description>
26     <group>spam,</group>
27   </rule>
28
29   <rule id="3103" level="6">
30     <if_sid>3101</if_sid>
31     <match>reject=550 5.0.0 |reject=553 5.3.0</match>
32     <description>Rejected by access list </description>
33     <description>(55x: Requested action not taken).</description>
34     <group>spam,</group>
35   </rule>
36
37   <rule id="3104" level="6">
38     <if_sid>3101</if_sid>
39     <match>reject=550 5.7.1 </match>
40     <description>Attepmt to use mail server as relay </description>
41     <description>(550: Requested action not taken).</description>
42     <group>spam,</group>
43   </rule>
44
45   <rule id="3105" level="5">
46     <if_sid>3101</if_sid>
47     <match>reject=553 5.1.8 </match>
48     <description>Sender domain is not found </description>
49     <description> (553: Requested action not taken).</description>
50     <group>spam,</group>
51   </rule>
52
53   <rule id="3106" level="5">
54     <if_sid>3101</if_sid>
55     <match>reject=553 5.5.4 </match>
56     <description>Sender address does not have domain </description>
57     <description>(553: Requested action not taken).</description>
58     <group>spam,</group>
59   </rule>
60
61   <rule id="3107" level="4">
62     <if_sid>3101</if_sid>
63     <description>Sendmail rejected message.</description>
64   </rule>
65   
66   <rule id="3108" level="6">
67     <if_sid>3100</if_sid>
68     <match>rejecting commands from</match>
69     <description>Sendmail rejected due to pre-greeting.</description>
70     <group>spam,</group>
71   </rule>
72   
73   <rule id="3109" level="8">
74     <if_sid>3100</if_sid>
75     <match>savemail panic</match>
76     <description>Sendmail save mail panic.</description>
77     <group>system_error,</group>
78   </rule>
79   
80   <rule id="3151" level="10" frequency="6" timeframe="120">
81     <if_matched_sid>3102</if_matched_sid>
82     <same_source_ip />
83     <description>Sender domain has bogus MX record. </description>
84     <description>It should not be sending e-mail.</description>
85     <group>multiple_spam,</group>
86   </rule>
87
88   <rule id="3152" level="6" frequency="6" timeframe="120">
89     <if_matched_sid>3103</if_matched_sid>
90     <same_source_ip />
91     <description>Multiple attempts to send e-mail from a </description>
92     <description>previously rejected sender (access).</description>
93     <group>multiple_spam,</group>
94   </rule>
95
96   <rule id="3153" level="6" frequency="6" timeframe="120">
97     <if_matched_sid>3104</if_matched_sid>
98     <same_source_ip />
99     <description>Multiple relaying attempts of spam.</description>
100     <group>multiple_spam,</group>
101   </rule>
102
103   <rule id="3154" level="10" frequency="6" timeframe="120">
104     <if_matched_sid>3105</if_matched_sid>
105     <same_source_ip />
106     <description>Multiple attempts to send e-mail </description>
107     <description>from invalid/unknown sender domain.</description>
108     <group>multiple_spam,</group>
109   </rule>
110
111   <rule id="3155" level="10" frequency="6" timeframe="120">
112     <if_matched_sid>3106</if_matched_sid>
113     <same_source_ip />
114     <description>Multiple attempts to send e-mail from </description>
115     <description>invalid/unknown sender.</description>
116     <group>multiple_spam,</group>
117   </rule>
118   
119   <rule id="3156" level="10" frequency="10" timeframe="120">
120     <if_matched_sid>3107</if_matched_sid>
121     <same_source_ip />
122     <description>Multiple rejected e-mails from same source ip.</description>
123     <group>multiple_spam,</group>
124   </rule>
125
126   <rule id="3158" level="10" frequency="6" timeframe="120">
127     <if_matched_sid>3108</if_matched_sid>
128     <same_source_ip />
129     <description>Multiple pre-greetings rejects.</description>
130     <group>multiple_spam,</group>
131   </rule>
132
133
134    <!-- Rules for SMF-SAV -->
135    <rule id="3190" level="0">
136      <decoded_as>smf-sav-reject</decoded_as>
137      <description>Grouping of the smf-sav sendmail milter rules.</description>
138      <group>smf-sav,</group>
139    </rule>
140
141    <rule id="3191" level="6">
142      <if_sid>3190</if_sid>
143      <match>^sender check failed|^sender check tempfailed</match>
144      <description>SMF-SAV sendmail milter unable to verify </description>
145      <description>address (REJECTED).</description>
146      <group>smf-sav,spam,</group>
147    </rule>
148
149 </group> <!-- SYSLOG,SENDMAIL -->