mailing list archives
Re: TCP Syn Flooding
From: "Anders Reed Mohn" <anders_rm () utepils com>
Date: Mon, 17 Feb 2003 23:09:32 +0100
I received this message a few times yesterday after I installed the box:
Fri, 02/14/2003 20:35:01 - TCP connection dropped -
Source:220.127.116.11, 80, WAN - Destination:18.104.22.168, 20306, LAN -
'TCP:Syn Flooding' End of Log ----------
What should I make of this?
Not sure, Tim, but I'll make a guess.
Is there a website at 22.214.171.124 that you've visited?
Now, the firewall will have reacted because this address sent one or more
that weren't expected. The target port for the SYN packet is a typical
and not a service, so it's probably not an attack of any sort.
This is something that all firewalls log tons of after you've visited a
I think the explanation is that when you _left_ the page, the
it were not closed. Thus, the remote server still thinks you are connected,
sends traffic to you. Your firewall, however, has already dropped the
and therefore thinks this is illegitimate traffic.
Re: TCP Syn Flooding Steve Suehring (Feb 18)