On 10/15/07, Kelly Robinson <[EMAIL PROTECTED]> wrote:
>
> In the Control Field of a TCP segment I noticed the following values:
>
> URG 0
> ACK 0
> PSH 0
> RST 0
> SYN 1
> FIN 1
>
> I assume the checksum is OK, is this an attack packet? If not, why not? If
> so, what is the attacker probably trying to achieve?
>

SYN/FIN portscan.
Someone simply portscanning you or a huge range of hosts looking for a
particular service.
_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/

Reply via email to