Security Incidents mailing list archives

RE: Possible DoS Attack?


From: "Blake R. Swopes" <bswopes () isecorp com>
Date: Mon, 10 Dec 2001 09:19:13 -0800

My guess would be that your ip got picked as a decoy for someone's port
scan. So you were seeing the target system's replys.

Not sure what would have caused your system to go down, though.

-----Original Message-----
From: Jonathan A. Zdziarski [mailto:jonathan () cafejesus com]
Sent: Monday, December 10, 2001 8:02 AM
To: incidents () securityfocus com
Subject: Possible DoS Attack?


I normally disregard scans, however this particular scan doesn't
look like a
conventional port scan, and it happened around the same time the machine
went down.  It looks like their source port is changing, but the
target port
on our machine is only changed periodically.  Could this have been a DoS
attack?



----------------------------------------------------------------------------
This list is provided by the SecurityFocus ARIS analyzer service.
For more information on this free incident handling, management 
and tracking system please see: http://aris.securityfocus.com


Current thread: