[Snort-devel] Stream4 qn: ACTION_INC_PORT

Martin Roesch roesch at ...402...
Mon Sep 15 19:06:52 EDT 2008


As I recall (been a while since I wrote it) that was part of Nmap
fingerprint attempt detection back in the old days.  Stream4 is deprecated
in favor of stream5 these days so that code isn't used for much of anything
these days.

Marty

On Mon, Sep 15, 2008 at 6:16 PM, snort user <snort.user at ...2499...> wrote:

> Hello/Greetings
>
> In spp_stream4.c there is a #define --
> #define ACTION_INC_PORT                 0x00000200
>
> UpdateState* functions do not return this action. However, TcpAction
> seems to do the following --
>
>        if(action & ACTION_INC_PORT)
>        {
>            ssn->client.port++;
>        }
>
> I am trying to understand about this..
>
> What is/was the purpose of 'ACTION_INC_PORT'.
> Is it something that was used earlier but not anymore?
>
> Thanks
>
> -------------------------------------------------------------------------
> This SF.Net email is sponsored by the Moblin Your Move Developer's
> challenge
> Build the coolest Linux based applications with Moblin SDK & win great
> prizes
> Grand prize is a trip for two to an Open Source event anywhere in the world
> http://moblin-contest.org/redirect.php?banner_id=100&url=/
> _______________________________________________
> Snort-devel mailing list
> Snort-devel at lists.sourceforge.net
> https://lists.sourceforge.net/lists/listinfo/snort-devel
>



-- 
Martin Roesch - Founder/CTO, Sourcefire Inc. - +1-410-290-1616
Sourcefire - Security for the Real World - http://www.sourcefire.com
Snort: Open Source IDP - http://www.snort.org
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <https://lists.snort.org/pipermail/snort-devel/attachments/20080915/6fa71b55/attachment.html>


More information about the Snort-devel mailing list