Re: Logging unserved ports

Alan Cox (alan@lxorguk.ukuu.org.uk)
Fri, 11 Dec 1998 15:43:01 +0000 (GMT)


> > confuses, and/or defeats a number of stealth scanning or stack-
> > identification tools such as nmap, queso, etc. I make no claims that it's
> > perfect, or cleanly done (or that it works at all, for that matter ;).
>
> FIN+SYN is valid under some circumstances, is it not?

SYN|FIN is legal TCP. If you ever see it be suspicious however. The only
legitimate cause of it is T/TCP which is an experimental protocol nobody
is supposed to use

Alan

-
To unsubscribe from this list: send the line "unsubscribe linux-kernel" in
the body of a message to majordomo@vger.rutgers.edu
Please read the FAQ at http://www.tux.org/lkml/