Security Basics mailing list archives

Ethereal to detect Half Open Syncs


From: "Rivera Alonso, David" <drivera () iberdrola es>
Date: Mon, 10 Apr 2006 13:29:55 +0200

Hi,

my question is very simple: has any of you ever used Ethereal to detect Half
Open Syncs in a LAN.
Maybe it's easily done with a complex filter, but I don't know how to do it.

DeviceA sends a SYN to DeviceB
DeviceB answers with SYN ACK and saves this Half Open Connection in it's
memory table
DeviceA never answers with ACK

I need to detect which DeviceAs are in our LAN, to avoid memory problems in
DeviceB.

thanks a lot,

DAVID



===============================================================
Este mensaje se dirige exclusivamente a su destinatario. La información incluida en el
presente correo es confidencial sometida a secreto profesional, especialmente en lo que
respecta a los datos personales, cuya divulgación está prohibida, en virtud de la
legislación vigente. Si usted no lo es y lo ha recibido por error o tiene conocimiento
del mismo por cualquier motivo, le rogamos que nos lo comunique por este medio y proceda
a destruirlo o borrarlo, y que en todo caso se abstenga de utilizar, reproducir, alterar,
archivar o comunicar a terceros el presente mensaje y ficheros anexos, todo ello bajo
pena de incurrir en responsabilidades legales. Cualquier opinión contenida en este correo
es exclusiva de su autor y no representa necesariamente la opinión de Iberdrola. El
emisor no garantiza la integridad, rapidez o seguridad del presente correo, ni se
responsabiliza de posibles perjuicios derivados de la captura, incorporaciones de virus o
cualesquiera otras manipulaciones efectuadas por terceros.


This message is intended for the exclusive attention of the addressee(s) indicated. Any
information contained herein is strictly confidential and privileged, especially as
regards personal data, which must not be disclosed, in accordance with legislation
currently in force. If you are not the intended recipient and have received it by mistake
or learn about it in any other way, please notify us by return e-mail and delete this
message from your computer system. Any unauthorised use, reproduction, alteration, filing
or sending of this message and/or any attached files to third parties may lead to legal
proceedings being taken. Any opinion expressed herein is solely that of the author(s) and
does not necessarily represent the opinion of Iberdrola. The sender does not guarantee
the integrity, speed or safety of this message, not accept responsibility for any
possible damage arising from the interception, incorporation of virus or any other
manipulation carried out by third parties.
===============================================================


-------------------------------------------------------------------------
This List Sponsored by: Webroot

Don't leave your confidential company and customer records un-protected.
Try Webroot's Spy Sweeper Enterprise(TM) for 30 days for FREE with no
obligation. See why so many companies trust Spy Sweeper Enterprise to
eradicate spyware from their networks.
FREE 30-Day Trial of Spy Sweeper Enterprise

http://www.webroot.com/forms/enterprise_lead.php
--------------------------------------------------------------------------


Current thread: