Security Incidents mailing list archives

Re: TCP FIN Increase


From: Skip Carter <skip () taygeta com>
Date: Thu, 25 Oct 2001 15:17:34 -0700


I am seeing an increase in TCP FIN attacks on the few firewalls I monitor,
both PIX and SonicWall are reporting them.  Is anyone else seeing this
increase?

  My snort boxes have seen occasional bursts of these for the last
  three days, all of them were associated with port 113 attempts.

  That reminds me, I haven't seen a SYN-FIN attempt for over a month
  now (I usually would see 3 or 4 a week).  I have just been assuming
  that it was just a case of "lower hanging fruit".



-- 
 Dr. Everett (Skip) Carter      Phone: 831-641-0645 FAX:  831-641-0647
 Taygeta Scientific Inc.        INTERNET: skip () taygeta com
 1340 Munras Ave., Suite 314    UUCP:     ...!uunet!taygeta!skip
 Monterey, CA. 93940            WWW: http://www.taygeta.com/skip.html












----------------------------------------------------------------------------
This list is provided by the SecurityFocus ARIS analyzer service.
For more information on this free incident handling, management 
and tracking system please see: http://aris.securityfocus.com


Current thread: