On 10/15/07, Kelly Robinson <[EMAIL PROTECTED]> wrote: > > In the Control Field of a TCP segment I noticed the following values: > > URG 0 > ACK 0 > PSH 0 > RST 0 > SYN 1 > FIN 1 > > I assume the checksum is OK, is this an attack packet? If not, why not? If > so, what is the attacker probably trying to achieve? >
SYN/FIN portscan. Someone simply portscanning you or a huge range of hosts looking for a particular service.
_______________________________________________ Full-Disclosure - We believe in it. Charter: http://lists.grok.org.uk/full-disclosure-charter.html Hosted and sponsored by Secunia - http://secunia.com/