Snort mailing list archives

Re: Evasive RST?


From: Robert van der Meulen <rvdm () cistron nl>
Date: Mon, 6 Aug 2001 17:14:08 +0200


Quoting George D. Nincehelser (george () ccitriad net):
[**] [111:2:1] spp_stream4: EVASIVE RST detection [**]

Can anyone give me a nutshell description of what the above line means?  I
did a search on "EVASIVE RST" but came up with nothing.
From the source, i gather it's a check on RST packets coming in, on a closed
connection (a connection that's being closed while it's not present in the
connection state table anymore)

Greets,
        Robert
-- 
                              Linux Generation
   encrypted mail preferred. finger rvdm () debian org for my GnuPG/PGP key.
        Microsoft is number one. And you, the millions of consumers 
             who use our products, are the zeroes. -- the onion

_______________________________________________
Snort-users mailing list
Snort-users () lists sourceforge net
Go to this URL to change user options or unsubscribe:
http://lists.sourceforge.net/lists/listinfo/snort-users
Snort-users list archive:
http://www.geocrawler.com/redir-sf.php3?list=snort-users


Current thread: