[Snort-users] bad traffic in syn packet
JHally at ...5637...
Tue Sep 6 06:12:30 EDT 2005
Need a quick sanity check here. I'm seeing alerts for traffic in syn
packets, and all are destined for TCP/53. Is it possible that data is being
piggy-backed in the syn packet on purpose and the traffic is benign? I
don't see any other anomalies to or from these hosts, but wanted to make
sure that I'm not overlooking something obvious.
Thanks in advance!
-------------- next part --------------
An HTML attachment was scrubbed...
More information about the Snort-users