Pantek Library
Hosting Provided By
CybrHost
High Speed Hosting

bad IP traffic

From: operator <operator(at)email.it>
Date: Wed Jun 11 2003 - 08:52:16 EDT


My company NIDS - i.e. snort 2.0 - is triggering since three/four days a lot of "BAD-TRAFFIC bad frag bits" alerts.
These come out when a TCP packet has both fragment and don't_fragment bit on.

Target of these alerts is almost always the IP address of a particular Web Server (one of our server farm).
Other alerts are triggered on this target, some are common ones such as Apache worm for Apache old version but this is a usual maltraffic, but other ones are of type "bad TCP/IP traffic", such as anomalous TTL values for packets.

It seems to me this could be a scan/gathering info technique, is it correct? can this be a False Positive ? Can this
be something more dangerous?

Any help will be very appreciated,

Cheers,

Max


   Lines below are "the price to pay" for a free service of a commercial ISP


--
Email.it, the professional e-mail, gratis per te: 
http://www.email.it/f

Sponsor:
Viaggiare in aereo spendendo poco non è un sogno perchè Sterling fa dei tuoi sogni realtà, clicca subito
Clicca qui: 
http://adv.email.it/cgi-bin/foclick.cgi?mid=1227&d=11-6

----------------------------------------------------------------------------
----------------------------------------------------------------------------
Received on Wed Jun 11 16:01:55 2003

This archive was generated by hypermail 2.1.8 : Wed Aug 23 2006 - 14:02:08 EDT

Do you need help?X

Contact Us  Legal Notices  Order Services Online 
Pantek Home  Privacy Policy  IT news  Site Map  Pantek Library