[<prev] [next>] [<thread-prev] [day] [month] [year] [list]
Message-ID: <ba5e78ea0710142109r1ee316dfl3b838cd513847a32@mail.gmail.com>
Date: Mon, 15 Oct 2007 12:09:38 +0800
From: "Daniel Marsh" <jahilliya@...il.com>
To: "Kelly Robinson" <caliana1989@...il.com>
Cc: full-disclosure@...ts.grok.org.uk
Subject: Re: Is this an attack?
On 10/15/07, Kelly Robinson <caliana1989@...il.com> wrote:
>
> In the Control Field of a TCP segment I noticed the following values:
>
> URG 0
> ACK 0
> PSH 0
> RST 0
> SYN 1
> FIN 1
>
> I assume the checksum is OK, is this an attack packet? If not, why not? If
> so, what is the attacker probably trying to achieve?
>
SYN/FIN portscan.
Someone simply portscanning you or a huge range of hosts looking for a
particular service.
Content of type "text/html" skipped
_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/
Powered by blists - more mailing lists