bad IP traffic

From: operator (operatorat_private)
Date: Wed Jun 11 2003 - 05:52:16 PDT

  • Next message: Thomas Jensen: "Re: Strange CONNECT entries in apache logs"

    My company NIDS - i.e. snort 2.0 - is triggering since three/four days a lot
    of  "BAD-TRAFFIC bad frag bits" alerts.
    These come out when a TCP packet has both fragment and don't_fragment bit
    on.
    
    Target of these alerts is almost always the IP address of a particular Web
    Server (one of our server farm).
    Other alerts are triggered on this target, some are common ones such as
    Apache worm for Apache old version but this
    is a usual maltraffic, but other ones are of type "bad TCP/IP traffic", such
    as anomalous TTL values for packets.
    
    It seems to me this could be a scan/gathering info technique, is it correct?
    can this be a False Positive ? Can this
    be something more dangerous?
    
    Any help will be very appreciated,
    
    Cheers,
    
    Max
    
    
    ==============================================================
       Lines below are "the price to pay"  for a free service of a commercial
    ISP
    ==============================================================
    
    
    
    --
    Email.it, the professional e-mail, gratis per te: http://www.email.it/f
    
    Sponsor:
    Viaggiare in aereo spendendo poco non è un sogno perchè Sterling fa dei tuoi sogni realtà, clicca subito
    Clicca qui: http://adv.email.it/cgi-bin/foclick.cgi?mid=1227&d=11-6
    
    ----------------------------------------------------------------------------
    ----------------------------------------------------------------------------
    



    This archive was generated by hypermail 2b30 : Wed Jun 11 2003 - 12:46:07 PDT