SV: [Snort-users] BAD TRAFFIC data in TCP SYN packet

Dan Hollis goemon at ...20...
Tue Jan 15 12:29:48 EST 2002


On Tue, 15 Jan 2002, Austad, Jay wrote:
> Here's a description of the probe from the help provided in the
> configuration interface for the 3dns units:
> DNS_DOT (DNS Dot)
> [...]
> DNS_REV (Reverse IP address lookup)
> [...]

The mysterious malformed packets described in incidents are neither of 
these.

The f5 seems to be sending malformed DNS packets, and the DNS servers are 
responding (correctly) with a format error.

Is this a bug or intentional on behalf of f5?

-Dan
-- 
[-] Omae no subete no kichi wa ore no mono da. [-]






More information about the Snort-users mailing list