|
Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com |
Port 0 packets
From: Stuart (secmail
patchsupplier.dyndns.org)
Date: Tue Jul 22 2003 - 19:28:48 CDT
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ]
Hi,
After currently reviewing firewall logs from ISA server I have come
across a period of where the box was hit with an aprox. average of 3 - 4
packets per 5 minute period for 8 hours. After looking up information
from dshield.org
http://isc.incidents.org/port_details.html?port=0
I have found that these packets can cause DoS on certain devices and
OS'. The effect of the packets had no effect on the box itself but the
packets were originating from 2 different hosts so I would assume this
will fall in the category of DDoS?
I first noticed these packets in the logs on the 21st from 11:20 GMT to
22nd 7:20 GMT and they have just started again (22nd 17:40 GMT) and are
continuing.
Has anyone else received such packets? Or know if there is a Trojan/worm
that these packets are sent from?
Thanks for your help
Stu
---------------------------------------------------------------------------
----------------------------------------------------------------------------
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ]