|
Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com |
Subject: Re: Port 65535
From: Pavel Kankovsky (peak
ARGO.TROJA.MFF.CUNI.CZ)Date: Sat Mar 04 2000 - 11:14:17 CST
- Next message: Russell Fulton: "scans with spoofed address (was
home: Is *anyone*...)"
- Previous message: Ryan Russell: "Re: getting to the point with DDoS"
- In reply to: Murray, Mike: "Port 65535"
- Next in thread: Murray, Mike: "Re: Port 65535"
- Reply: Pavel Kankovsky: "Re: Port 65535"
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ]
On Thu, 2 Mar 2000, Murray, Mike wrote:
> Feb 29 07:12:25 firepower kernel: Packet log: private1 DENY eth0 PROTO=6
> 192.115.221.125:65535 207.245.232.127:65535 L=28 S=0x00 I=15817 F=0x00B8 T=47
> (#7)
This is a fragment (F stands for fragment offset). ipchains leave port
numbers equal to (u_short)(-1) if the fragment does not include a
(complete) TCP/UDP header.
--Pavel Kankovsky aka Peak [ Boycott Microsoft--http://www.vcnet.com/bms ]
"Resistance is futile. Open your source code and prepare for assimilation."
- Next message: Russell Fulton: "scans with spoofed address (was
home: Is *anyone*...)"
- Previous message: Ryan Russell: "Re: getting to the point with DDoS"
- In reply to: Murray, Mike: "Port 65535"
- Next in thread: Murray, Mike: "Re: Port 65535"
- Reply: Pavel Kankovsky: "Re: Port 65535"
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ]