|
|||||||||||
|
Re: Packet from port 80 with spoofed microsoft.com ip
From: Keith Owens <kaos(at)ocs.com.au>
Date: Wed Jan 29 2003 - 22:31:36 EST
I am seeing a lot of sync/ack packets from port 80 to non-existent addresses on my networks. Somebody is spoofing source addresses to attack hosts, we are just innocent victims. When will ISPs learn that they should filter their customer's packets to prevent spoofing? I am even seeing syn/ack packets from 255.255.255.255:80! This list is provided by the SecurityFocus ARIS analyzer service. For more information on this free incident handling, management and tracking system please see: http://aris.securityfocus.com Received on Thu Jan 30 12:32:02 2003 This archive was generated by hypermail 2.1.8 : Wed Aug 23 2006 - 14:01:56 EDT |
||||||||||
|
|||||||||||