[prev in list] [next in list] [prev in thread] [next in thread]
List: incidents
Subject: Re: TCP FIN Increase
From: Skip Carter <skip () taygeta ! com>
Date: 2001-10-25 22:17:34
[Download RAW message or body]
> I am seeing an increase in TCP FIN attacks on the few firewalls I monitor,
> both PIX and SonicWall are reporting them. Is anyone else seeing this
> increase?
My snort boxes have seen occasional bursts of these for the last
three days, all of them were associated with port 113 attempts.
That reminds me, I haven't seen a SYN-FIN attempt for over a month
now (I usually would see 3 or 4 a week). I have just been assuming
that it was just a case of "lower hanging fruit".
--
Dr. Everett (Skip) Carter Phone: 831-641-0645 FAX: 831-641-0647
Taygeta Scientific Inc. INTERNET: skip@taygeta.com
1340 Munras Ave., Suite 314 UUCP: ...!uunet!taygeta!skip
Monterey, CA. 93940 WWW: http://www.taygeta.com/skip.html
----------------------------------------------------------------------------
This list is provided by the SecurityFocus ARIS analyzer service.
For more information on this free incident handling, management
and tracking system please see: http://aris.securityfocus.com
[prev in list] [next in list] [prev in thread] [next in thread]
Configure |
About |
News |
Add a list |
Sponsored by KoreLogic