----- Original Message -----
From: Zhen Shi <[EMAIL PROTECTED]>
Date: Mon, 8 Apr 2002 07:45:06 -0700 (PDT)
To: [EMAIL PROTECTED]
Subject: DDOS or Spoofed DOS


> Hi,
>    When you see a lot of TCP SYN flooding your network
> with various source IPs, how do you tell if these 
> packets are generated from DDOS or just a plain old
> DOS with spoofed IPs? 
> 
> Thanks.
> Zhenshi
>

this might be a SYN scan with the DECOY option set on nmap
-- 

Get your free email from www.linuxmail.org 


Powered by Outblaze

Reply via email to