OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
 
[Snort-users] bad traffic in syn packet

From: John Hally (JHallyepnet.com)
Date: Tue Sep 06 2005 - 08:10:45 CDT


Hello All,

 

Need a quick sanity check here. I'm seeing alerts for traffic in syn
packets, and all are destined for TCP/53. Is it possible that data is being
piggy-backed in the syn packet on purpose and the traffic is benign? I
don't see any other anomalies to or from these hosts, but wanted to make
sure that I'm not overlooking something obvious.

 

Thanks in advance!

 

John.

-------------------------------------------------------
SF.Net email is Sponsored by the Better Software Conference & EXPO
September 19-22, 2005 * San Francisco, CA * Development Lifecycle Practices
Agile & Plan-Driven Development * Managing Projects & Teams * Testing & QA
Security * Process Improvement & Measurement * http://www.sqe.com/bsce5sf
_______________________________________________
Snort-users mailing list
Snort-userslists.sourceforge.net
Go to this URL to change user options or unsubscribe:
https://lists.sourceforge.net/lists/listinfo/snort-users
Snort-users list archive:
http://www.geocrawler.com/redir-sf.php3?list=snort-users