----- Original Message ----- From: Zhen Shi <[EMAIL PROTECTED]> Date: Mon, 8 Apr 2002 07:45:06 -0700 (PDT) To: [EMAIL PROTECTED] Subject: DDOS or Spoofed DOS
> Hi, > When you see a lot of TCP SYN flooding your network > with various source IPs, how do you tell if these > packets are generated from DDOS or just a plain old > DOS with spoofed IPs? > > Thanks. > Zhenshi > this might be a SYN scan with the DECOY option set on nmap -- Get your free email from www.linuxmail.org Powered by Outblaze
