[Snort-users] IP spoofing
liste at ...12529...
Fri Oct 8 02:38:18 EDT 2004
-----BEGIN PGP SIGNED MESSAGE-----
On Thursday 07 October 2004 21:01, Aguiar Magalhaes wrote:
> Hi snorters,
> I'm receiving a lot of PING NMAP alerts... The source
> IPs are spoofed
> How can I to know the true source IP of these attacks
Maybe the person that scans you with nmap use decoy options (-D) that allow to
use multiple "spoofed" IP and only one of this is "real" (i.e. IP of people
that doing scan).
Good luck !
Il pensiero e' cosa che con piccolissimo corpo sa compiere divinissime cose.
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.2.4 (GNU/Linux)
-----END PGP SIGNATURE-----
More information about the Snort-users