0
   

"Invalid TCP Flag Attack" from advertiser here?? (doubt it!)

 
 
dlowan
 
Reply Thu 5 Feb, 2004 07:32 pm
My Norton Internet Security just said my computer had been accessed in a manner characteristic of an "Invalid TCP Flag attack"

The tracker gave this info about the source:

IP no. (I think!) 64.70.54.44
adclst03.value click com
Cable and Wireless
ExCW
Cary NC
27511

It said this re such an "attack"
Invalid TCP Flags
Severity: Medium

This attack could pose a moderate security threat. It does not require immediate action.

Attack Category: Pre-Attack Probe

Pre-Attack probes gather information about a system necessary to launch an attack. A pre-attack probe signature might detect a UDP scan, for example, which an attacker could use to identify all live systems on a network.

Description

This attack signature detects TCP packets that have invalid combinations of flags in the TCP header. e.g. TCP packets that have both the FIN and RST bits set. This intrusion also detects packets that have the TCP reserved bits set.

False Positive

Certain Internet devices, typically routers, sometimes violate the specifications for TCP flags and set the reserved bits to 1.

___________________________________________________________

I assume this was the Norton being a nervous Nellie???? It has reason to be - my system just crashed! And Microsoft doesn't know why. lol

Just thought it was worth letting you know Craven - in case it actually WAS something odd from here.
  • Topic Stats
  • Top Replies
  • Link to this Topic
Type: Discussion • Score: 0 • Views: 1,953 • Replies: 3
No top replies

 
dlowan
 
  1  
Reply Thu 5 Feb, 2004 07:33 pm
Oh - A2k was just loading itself in my browser at the time - the only site that was on...
0 Replies
 
Craven de Kere
 
  1  
Reply Thu 5 Feb, 2004 08:46 pm
Not a nervous Nellie but a dog bringing a stuffed animal and dropping it at your feet. Laughing

Yeah, it's hard to imagine it as anything but a false positive. But I'm going to look into it.
0 Replies
 
dlowan
 
  1  
Reply Thu 5 Feb, 2004 08:56 pm
Thanks Craven....just didn't want to let it go if it WAS a problem...
0 Replies
 
 

Related Topics

How to use the new able2know - Discussion by Craven de Kere
New A2K feature requests. - Discussion by DrewDad
I'm the developer - Discussion by Nick Ashley
JIM NABORS WAS GOY? - Question by farmerman
A2K censors tags? - Discussion by hingehead
New A2K Bugs - Discussion by sozobe
New A2K annoyances - Discussion by sozobe
The a2k world is changing 3: about voting - Discussion by Craven de Kere
LOST & MISPLACED A2K people. - Discussion by msolga
Welcome to the 'New' My Posts - Discussion by Nick Ashley
The "I get folksonomy" club - Discussion by Robert Gentel
 
  1. Forums
  2. » "Invalid TCP Flag Attack" from advertiser here?? (doubt it!)
Copyright © 2024 MadLab, LLC :: Terms of Service :: Privacy Policy :: Page generated in 0.05 seconds on 12/26/2024 at 07:07:41