Full Disclosure mailing list archives
Re: Is this an attack?
From: "Daniel Marsh" <jahilliya () gmail com>
Date: Mon, 15 Oct 2007 12:09:38 +0800
On 10/15/07, Kelly Robinson <caliana1989 () gmail com> wrote:
In the Control Field of a TCP segment I noticed the following values: URG 0 ACK 0 PSH 0 RST 0 SYN 1 FIN 1 I assume the checksum is OK, is this an attack packet? If not, why not? If so, what is the attacker probably trying to achieve?
SYN/FIN portscan. Someone simply portscanning you or a huge range of hosts looking for a particular service.
_______________________________________________ Full-Disclosure - We believe in it. Charter: http://lists.grok.org.uk/full-disclosure-charter.html Hosted and sponsored by Secunia - http://secunia.com/
Current thread:
- Is this an attack? Kelly Robinson (Oct 14)
- Re: Is this an attack? Daniel Marsh (Oct 14)