Snort mailing list archives
Re: null scan without port number
From: Matt Kettler <mkettler () evi-inc com>
Date: Mon, 27 Sep 2004 11:47:04 -0400
At 06:23 PM 9/25/2004, Annie Green wrote:
What it means when there's "null scan" alert without any port number? Source port and destination port are 'none'.
That sounds like a bug, since null scans can only happen in TCP. However, it might mean that the src and dest port are both 0 in the packet.
What snort version are you using?Are you using some kind of report interpreter (ie: ACID) or is this present in the logs snort directly generates?
Can you give an example alert (censor IPs if you wish)?
------------------------------------------------------- This SF.Net email is sponsored by: YOU BE THE JUDGE. Be one of 170 Project Admins to receive an Apple iPod Mini FREE for your judgement on who ports your project to Linux PPC the best. Sponsored by IBM. Deadline: Sept. 24. Go here: http://sf.net/ppc_contest.php _______________________________________________ Snort-users mailing list Snort-users () lists sourceforge net Go to this URL to change user options or unsubscribe: https://lists.sourceforge.net/lists/listinfo/snort-users Snort-users list archive: http://www.geocrawler.com/redir-sf.php3?list=snort-users
Current thread:
- null scan without port number Annie Green (Sep 25)
- Re: null scan without port number Matt Kettler (Sep 27)