> I am seeing an increase in TCP FIN attacks on the few firewalls I monitor, > both PIX and SonicWall are reporting them. Is anyone else seeing this > increase? My snort boxes have seen occasional bursts of these for the last three days, all of them were associated with port 113 attempts. That reminds me, I haven't seen a SYN-FIN attempt for over a month now (I usually would see 3 or 4 a week). I have just been assuming that it was just a case of "lower hanging fruit". -- Dr. Everett (Skip) Carter Phone: 831-641-0645 FAX: 831-641-0647 Taygeta Scientific Inc. INTERNET: skipat_private 1340 Munras Ave., Suite 314 UUCP: ...!uunet!taygeta!skip Monterey, CA. 93940 WWW: http://www.taygeta.com/skip.html ---------------------------------------------------------------------------- This list is provided by the SecurityFocus ARIS analyzer service. For more information on this free incident handling, management and tracking system please see: http://aris.securityfocus.com
This archive was generated by hypermail 2b30 : Thu Oct 25 2001 - 15:34:07 PDT