Home page logo

basics logo Security Basics mailing list archives

Re: Firewall log help
From: fnfspam () yahoo dk
Date: 8 Jun 2005 09:06:16 -0000

These are responses from a web server to a (spoofed?) web client:
!well, the date ;-),
!responding host
!his source is 'your' destination: www
!your IP (you knew that ;-)
!his destination is 'your' source: >1023
TCP (flags:AS),
!correct me if I'm wrong, but I recall it's Syn/Ack. This further shows this packet is a respons from an Ack you 
supposely (sp?)send
!nr of packets
As the firewall is dropping these packets, either the NAT-timers on your firewall are set to low or your address is 
being spoofed (a bit more likely).
Not much you can do about it (appart from blocking Chinese ip-address).

  By Date           By Thread  

Current thread:
[ Nmap | Sec Tools | Mailing Lists | Site News | About/Contact | Advertising | Privacy ]