Security Incidents mailing list archives

Re: syn+fin = stupid?


From: Derek Becker <DerekB () AMDOCS COM>
Date: Mon, 31 Jul 2000 10:58:51 -0500

It could be a fingerprint attempt. IIRC, responses to illegitimate packets
are one way to figure out what kind of TCP stack is running on a box.

Derek

-----Original Message-----
From: marvin () NSS NU [mailto:marvin () NSS NU]
Sent: Saturday, July 29, 2000 4:57 AM
To: INCIDENTS () SECURITYFOCUS COM
Subject: syn+fin = stupid?


I just noticed that a box in korea (210.223.100.97) checked port 21 and
port 53 one day. He/she checked port 21 twice (approx. 2 hours apart) and
port 53 three times (also approx. 2 hours apart). Both were closed all
day, and have never been open on that IP, ever.

I just have one question:

Why syn+fin? Isn't syn+fin something that will NEVER turn up in legit
traffic? It sticks out like nothing else (well, few other things anyway).


Current thread: