subject: (Fwd) Re: odd scans?
posted: Fri, 7 Jun 2002 18:04:51 +0100


on backscatter, synfloods and firewalls

------- Forwarded message follows -------
Date sent: Wed, 29 May 2002 14:47:56 -0600
To: "Kyle R. Hofmann" <[email protected]>,
"Scott, Michael R." <[email protected]>
From: Brett Glass <[email protected]>
Subject: Re: odd scans?
Copies to: "'[email protected]'" <[email protected]>,
"'[email protected]'" <[email protected]>

[ Double-click this line for list subscription options ]

At 12:21 PM 5/24/2002, Kyle R. Hofmann wrote:

>I've seen similar behavior from a misbehaving Linux 2.2.19 system. I don't
>know what triggered it, but it began trying to reset connections that weren't
>there:
>
>05:41:44.057978 xxx.62174 > yyy.zz: R 1060312:1060312(0) win 0
>05:42:38.212257 xxx.62175 > yyy.zz: R 1060356:1060356(0) win 0
>05:53:50.091303 xxx.62176 > yyy.zz: R 1060312:1060312(0) win 0

[Snip]

Resetting connections which are not there is frequently a symptom
of SYN flooding by someone who's spoofing your source address. We
see this sort of "backscatter" frequently. A stateful firewall can
help by blocking SYN-ACKs and ACKs when an outbound SYN was never
sent.

--Brett Glass


----------------------------------------------------------------------------
This list is provided by the SecurityFocus ARIS analyzer service.
For more information on this free incident handling, management
and tracking system please see: http://aris.securityfocus.com
------- End of forwarded message -------

---
* Origin: [adminz] tech, security, support (192.168.0.2)

generated by msg2page 0.06 on Jul 21, 2006 at 19:04:39

 search: