Security Incidents mailing list archives
Suspect short first fragment?
From: <jamie () jamie-sue org>
Date: 28 Feb 2002 17:57:09 -0000
I got several of these messages in my syslogd logs -
I'm using Redhat 7.1
any idea? Is this an attack?
Suspect short first fragment.
eth0 PROTO=17 212.15.64.83:0
200.186.111.146:0 L=20 S=0x00 I=40960 F=0x4000
T=116
(#0)
----------------------------------------------------------------------------
This list is provided by the SecurityFocus ARIS analyzer service.
For more information on this free incident handling, management
and tracking system please see: http://aris.securityfocus.com
Current thread:
- Suspect short first fragment? jamie (Feb 28)
- <Possible follow-ups>
- RE: Suspect short first fragment? Ralph Los (Feb 28)
- RE: Suspect short first fragment? Boyan Krosnov (Feb 28)
