RE: Ip spoof from 0.0.0.0
On Thu, 2002-11-07 at 13:29, Omar Herrera wrote:
>
> -----BEGIN PGP SIGNED MESSAGE-----
but this is not a SYN flood, or even a SYN trickle. It is one or two
packets per hour targeted at individual addresses in the low half of a
/24.
Yes, I saw one of these yesterday in a /24 that I monitor. Have not
seen anything in our main address block yet.
--
Russell Fulton, Computer and Network Security Officer
The University of Auckland, New Zealand
"It aint necessarily so" - Gershwin
----------------------------------------------------------------------------
This list is provided by the SecurityFocus ARIS analyzer service.
For more information on this free incident handling, management
and tracking system please see:
http://aris.securityfocus.com
Received on Thu Nov 7 21:33:43 2002
This archive was generated by hypermail 2.1.8
: Wed Aug 23 2006 - 14:01:50 EDT
|