Security Incidents mailing list archives
RE: Possible DoS Attack?
From: "Blake R. Swopes" <bswopes () isecorp com>
Date: Mon, 10 Dec 2001 09:19:13 -0800
My guess would be that your ip got picked as a decoy for someone's port scan. So you were seeing the target system's replys. Not sure what would have caused your system to go down, though.
-----Original Message----- From: Jonathan A. Zdziarski [mailto:jonathan () cafejesus com] Sent: Monday, December 10, 2001 8:02 AM To: incidents () securityfocus com Subject: Possible DoS Attack? I normally disregard scans, however this particular scan doesn't look like a conventional port scan, and it happened around the same time the machine went down. It looks like their source port is changing, but the target port on our machine is only changed periodically. Could this have been a DoS attack?
---------------------------------------------------------------------------- This list is provided by the SecurityFocus ARIS analyzer service. For more information on this free incident handling, management and tracking system please see: http://aris.securityfocus.com
Current thread:
- Possible DoS Attack? Jonathan A. Zdziarski (Dec 10)
- RE: Possible DoS Attack? Blake R. Swopes (Dec 10)
- Re: Possible DoS Attack? Glenn Forbes Fleming Larratt (Dec 10)
- Re: Possible DoS Attack? Jacques Bourdeau (Dec 10)
- <Possible follow-ups>
- RE: Possible DoS Attack? Jacques Bourdeau (Dec 10)