Security Incidents mailing list archives

Re: Unusual scan pattern


From: kjh () CERT ORG (Kevin Houle)
Date: Thu, 20 Jan 2000 20:35:44 +0000


-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

Russell Fulton wrote:

HI folks,
        I have not seen this type of scan before so I am forwarding the
argus logs for others to examine.
...
What interests me is the initial tcp data packets which look as if
they have been crafted to go through firewalls (at least simple packet
filter types) and the artifical source port numbers.

You might take a look at the following document:

  http://www.cert.org/incident_notes/IN-99-01.html

The footprint made in your argus logs is quite like the footprint
made by 'sscan'.

Kevin

-----BEGIN PGP SIGNATURE-----
Version: PGP for Personal Privacy 5.0
Charset: noconv

iQA/AwUBOIdxWVr9kb5qlZHQEQL49gCeK6NJES2grreFMJ98R6+WLmmqH0YAn2J8
FiucEqim1R2k+QET+acHNkwK
=Rufw
-----END PGP SIGNATURE-----


Current thread: