Security Incidents mailing list archives

Re: Small tcp fragments.


From: Marc Matteo <mmatteo () SACBEE COM>
Date: Wed, 6 Sep 2000 21:05:16 -0700

cider () SPEAKEASY ORG wrote:

        from time to time I see very small tcp fragments with source and
destination port == 0, no payload, no options, and both DF and MF bits
set.

A `nmap -f` scan (or something similar) perhaps?

Marc
--
Marc Matteo
Online Technology Leader
sacbee.com  http://www.sacbee.com


Current thread: