Home page logo

basics logo Security Basics mailing list archives

RE: TCP Syn Flooding
From: "Tim Laureska" <hometeam () goeaston net>
Date: Mon, 17 Feb 2003 16:58:27 -0500

Craig... is there anything particular in the message that makes you
think its just a 'script kiddie' trying a DoS attack ... or is that just
your thoughts based on experience

-----Original Message-----
From: Craig Searle [mailto:craig.searle () sift com au] 
Sent: Monday, February 17, 2003 4:17 PM
To: 'Tim Laureska'; 'security-basics'
Subject: RE: TCP Syn Flooding

Its just a 'script kiddie' trying a DoS attack- I wouldn't really worry
if I
were you. Your firewall has picked it up and stopped any problems.

If you are still concerned you want to consider setting your firewall to
block that IP altogether.

Craig Searle
SIFT Pty Ltd

P (02) 9236 7276
F (02) 9236 7271
M 0402 914 077
E craig.searle () sift com au

Level 67, MLC Centre,
Martin Place, Sydney NSW 2000

[ABN 42 094 359 743]

This correspondence is for the named person's use only. It may contain
confidential or legally privileged information or both. No
or privilege is waived or lost by any mistransmission. If you receive
correspondence in error, please immediately delete it from your system
notify the sender. You must not disclose, copy or rely on any part of
correspondence if you are not the intended recipient. Any opinions
in this message are those of the individual sender, except where the
expressly, and with authority, states them to be the opinions of SIFT

-----Original Message-----
From: Tim Laureska [mailto:hometeam () goeaston net] 
Sent: Sunday, 16 February 2003 01:21 AM
To: security-basics
Subject: TCP Syn Flooding

OK. I just installed a Netgear firewall box between a cable modem and a
4.0 server on a small network.. and set it up to email me attempts at
security breaches. I am brand new to these devices and a relative
to internet/internal network security.  So the question is this. 

I received this message a few times yesterday after I installed the box:

Fri, 02/14/2003 20:35:01 - TCP connection dropped -
80, WAN - Destination:, 20306, LAN - 'TCP:Syn Flooding' End
Log ----------

What should I make of this?

  By Date           By Thread  

Current thread:
[ Nmap | Sec Tools | Mailing Lists | Site News | About/Contact | Advertising | Privacy ]