Re: SYN Flood attack with sequential destination ports?

From: Joerg Over (overat_private)
Date: Thu Nov 08 2001 - 11:08:50 PST

  • Next message: Keith.Morgan: "RE: Strange "port scans" from a spoofed IP"

    Hi!
    
    At 12:55 08.11.01 -0500 you wrote:
    
    ->The interesting characteristic is the destination port is sequential - each
    ->phase of attack starting at 3039 and ending arouind 34431.
    --8<------------------------------------------------------------------------
    
    Ever thought it could be a syn scan instead of a syn flood?
    :)
    
    Greetings, jo
    +-------------------------------------------------------------------+
    |  __ __ __ __ _ _          It ain't over 'till it's Joerg Over...  |
    | / _ \ V / -_) '_/                                                 |
    | \___/\_/\___|_|                                                   |
    +-------------------------------------------------------------------+
    
    
    ----------------------------------------------------------------------------
    This list is provided by the SecurityFocus ARIS analyzer service.
    For more information on this free incident handling, management 
    and tracking system please see: http://aris.securityfocus.com
    



    This archive was generated by hypermail 2b30 : Fri Nov 09 2001 - 09:00:42 PST