That doesn't sound valid to me. Its only purpose would be a port scan to 
determine if a port is open. With that said, however, there are legitimate 
reasons for doing port scans. Sometimes they are used to test which ports 
are open so that those ports can be explicitly secured.

Priscilla

At 04:25 PM 7/7/01, Mike Mandulak wrote:
>Would there be any valid reason for having both the syn and fin flags set in
>the same packet? My IDS reports are saying that it is usually from a port
>scan.
>
>MikeM
________________________

Priscilla Oppenheimer
http://www.priscilla.com




Message Posted at:
http://www.groupstudy.com/form/read.php?f=7&i=11521&t=11264
--------------------------------------------------
FAQ, list archives, and subscription info: http://www.groupstudy.com/list/cisco.html
Report misconduct and Nondisclosure violations to [EMAIL PROTECTED]

Reply via email to