Re: [Snort-users] not your typical : BAD-TRAFFIC tcp port 0 traffic

This is a discussion on Re: [Snort-users] not your typical : BAD-TRAFFIC tcp port 0 traffic within the Snort forums, part of the System Security and Security Related category; Michael Scheidell wrote: > Any idea what they are doing? Trying to portscan? Looking for some > vulnerability with 'dest ...


Go Back   Usenet Forums > System Security and Security Related > Snort

FAQ Members List Calendar Search Today's Posts Mark Forums Read
  #1 (permalink)  
Old 05-26-2007
Richard Bejtlich
 
Posts: n/a
Default Re: [Snort-users] not your typical : BAD-TRAFFIC tcp port 0 traffic

Michael Scheidell wrote:

> Any idea what they are doing? Trying to portscan? Looking for some
> vulnerability with 'dest port' 0?


> 05/25-09:22:49 TCP 121.35.241.129:8000 --> xxx.xxx.xxx.xxx :0
> [1:524:8] BAD-TRAFFIC tcp port 0 traffic
> [Classification: Misc activity] [Priority: 3]
>
>
> #(2 - 738314) [2007-05-25 07:43:37] [snort/524] BAD-TRAFFIC tcp port 0
> traffic IPv4: 121.35.241.129 -> xxx.xxx.xxx.xxx
> hlen=5 TOS=0 dlen=40 ID=51608 flags=0 offset=0 TTL=238 chksum=35950
> TCP: port=80 -> dport: 0 flags=***A*R** seq=0
> ack=759384068 off=5 res=0 win=0 urp=0 chksum=50032 Payload: none


Michael,

It's "backscatter." An unknown third party is spoofing
xxx.xxx.xxx.xxx and SYN flooding port 80 TCP on 121.35.241.129.
121.35.241.129 is the real victim.

2000 paper:

http://www.taosecurity.com/nid_3pe_v101.pdf

1999 paper:

http://www.taosecurity.com/intv2-8.html

There's nothing to worry about.

Sincerely,

Richard

-------------------------------------------------------------------------
This SF.net email is sponsored by DB2 Express
Download DB2 Express C - the FREE version of DB2 express and take
control of your XML. No limits. Just data. Click to get it now.
http://sourceforge.net/powerbar/db2/
_______________________________________________
Snort-users mailing list
Snort-users@lists.sourceforge.net
Go to this URL to change user options or unsubscribe:
https://lists.sourceforge.net/lists/...fo/snort-users
Snort-users list archive:
http://www.geocrawler.com/redir-sf.p...st=snort-users
Reply With Quote
Reply
Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is Off
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT +1. The time now is 08:46 AM.


Powered by vBulletin® Version 3.7.3
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.0.0