Nmap Security Scanner
*Intro
*Ref Guide
*Install Guide
*Download
*Changelog
*Book
*Docs
Security Lists
*Nmap Hackers
*Nmap Dev
*Bugtraq
*Full Disclosure
*Pen Test
*Basics
*More
Security Tools
*Pass crackers
*Sniffers
*Vuln Scanners
*Web scanners
*Wireless
*Exploitation
*Packet crafters
*More
Site News
Site Search:
Exploit World
Advertising
About/Contact
Credits
Sponsors:
edgeos



Security Incidents: SYN Flood attack with sequential destination ports?

SYN Flood attack with sequential destination ports?

From: Joshua Wright <Joshua.Wright_at_jwu.edu>
Date: Thu, 8 Nov 2001 12:55:04 -0500

I am working with some folks at a partner network who are seeing a SYN flood
attack to a single destination address.

The interesting characteristic is the destination port is sequential - each
phase of attack starting at 3039 and ending arouind 34431.

I checked the source for synful.c, syn4k.c and a few others - all seem to
use a random or fixed destination port. Any ideas on what tool this could
be?

Thanks.

-Joshua Wright, GCIH
Joshua.Wright_at_jwu.edu

----------------------------------------------------------------------------
This list is provided by the SecurityFocus ARIS analyzer service.
For more information on this free incident handling, management
and tracking system please see: http://aris.securityfocus.com
Received on Nov 08 2001

[ Nmap | Sec Tools | Mailing Lists | Site News | About/Contact | Advertising | Privacy ]
edgeos