this look familar? http://www.whitehats.com/library/worms/lion/index.html > OK, this is beginning to drive me nuts. Since about February > of this year, > our firewall has been periodically hit with what can only be a probe, > attack, whatever to port 53. Every time the scan exhibits > the same behavior > and is from the same set of IP addresses. > > A SYN/ACK packet is sent to TCP port 53. No SYN was sent > from our system. > The SYN & ACK sequence numbers appear to be random, but the > ACK is always 1 > less than the SYN. Our system responds with a RST to the ACK. >
This archive was generated by hypermail 2b30 : Fri May 25 2001 - 10:14:14 PDT