Snort mailing list archives

Re: null scan without port number


From: Matt Kettler <mkettler () evi-inc com>
Date: Mon, 27 Sep 2004 11:47:04 -0400

At 06:23 PM 9/25/2004, Annie Green wrote:
What it means when there's "null scan" alert without any port number? Source port and destination port are 'none'.

That sounds like a bug, since null scans can only happen in TCP. However, it might mean that the src and dest port are both 0 in the packet.

What snort version are you using?

Are you using some kind of report interpreter (ie: ACID) or is this present in the logs snort directly generates?

Can you give an example alert (censor IPs if you wish)?


-------------------------------------------------------
This SF.Net email is sponsored by: YOU BE THE JUDGE. Be one of 170
Project Admins to receive an Apple iPod Mini FREE for your judgement on
who ports your project to Linux PPC the best. Sponsored by IBM.
Deadline: Sept. 24. Go here: http://sf.net/ppc_contest.php
_______________________________________________
Snort-users mailing list
Snort-users () lists sourceforge net
Go to this URL to change user options or unsubscribe:
https://lists.sourceforge.net/lists/listinfo/snort-users
Snort-users list archive:
http://www.geocrawler.com/redir-sf.php3?list=snort-users


Current thread: