SV: [Snort-users] BAD TRAFFIC data in TCP SYN packet

Dan Hollis goemon at ...20...
Tue Jan 15 12:29:48 EST 2002

On Tue, 15 Jan 2002, Austad, Jay wrote:
> Here's a description of the probe from the help provided in the
> configuration interface for the 3dns units:
> [...]
> DNS_REV (Reverse IP address lookup)
> [...]

The mysterious malformed packets described in incidents are neither of 

The f5 seems to be sending malformed DNS packets, and the DNS servers are 
responding (correctly) with a format error.

Is this a bug or intentional on behalf of f5?

[-] Omae no subete no kichi wa ore no mono da. [-]

