Suspect short first fragment?

From: jamie@jamie-sue.org
Date: Thu Feb 28 2002 - 09:57:09 PST

  • Next message: Robert Buckley: "Its not a nimda variant, its the old nimda."

    
     ('binary' encoding is not supported, stored as-is)
    I got several of these messages in my syslogd logs - 
    I'm using Redhat 7.1 
                  
                 any idea?  Is this an attack? 
                  
                 Suspect short first fragment.  
                 eth0 PROTO=17 212.15.64.83:0 
    200.186.111.146:0 L=20 S=0x00 I=40960 F=0x4000 
    T=116 
                 (#0)  
    
    ----------------------------------------------------------------------------
    This list is provided by the SecurityFocus ARIS analyzer service.
    For more information on this free incident handling, management 
    and tracking system please see: http://aris.securityfocus.com
    



    This archive was generated by hypermail 2b30 : Thu Feb 28 2002 - 10:12:31 PST