Re: Packet from port 80 with spoofed microsoft.com ip
On Thursday 30 January 2003 03:31, Keith Owens wrote:
>I am seeing a lot of sync/ack packets from port 80 to non-existent
Ditto, started getting these earlier on today (and also others from there
going to 1080 and 3128). They definitely _aren't_ backscatter but I'm equally
amazed that they get through. Interestingly snort fingered some of the port
80 probes as possible Backdoor Q accesses.
cheers
john
This list is provided by the SecurityFocus ARIS analyzer service.
For more information on this free incident handling, management
and tracking system please see: http://aris.securityfocus.com
Received on Thu Jan 30 13:35:19 2003
This archive was generated by hypermail 2.1.8
: Wed Aug 23 2006 - 14:01:56 EDT
|