Security Incidents mailing list archives

Re: Odd Increase in Malformed Packets Aimed at Port 0


From: Jose Nazario <jose () monkey org>
Date: Wed, 19 Oct 2005 12:03:31 -0400 (EDT)

could be fragmented traffic. can you secure a tcpdump log of the traffic?
that will reveal more attributes of the traffic than the firewall logs
you shared.

another poster here was discussing a recent spike in fragmented UDP
traffic, too.

________
jose nazario, ph.d.                     jose () monkey org
http://monkey.org/~jose/                http://infosecdaily.net/
                                        http://www.wormblog.com/


Current thread: