[Snort-users] bad traffic in syn packet

John Hally JHally at ...5637...
Tue Sep 6 06:12:30 EDT 2005


Hello All,

 

Need a quick sanity check here.  I'm seeing alerts for traffic in syn
packets, and all are destined for TCP/53.  Is it possible that data is being
piggy-backed in the syn packet on purpose and the traffic is benign?  I
don't see any other anomalies to or from these hosts, but wanted to make
sure that I'm not overlooking something obvious.

 

Thanks in advance!

 

John.

-------------- next part --------------
An HTML attachment was scrubbed...
URL: <https://lists.snort.org/pipermail/snort-users/attachments/20050906/118f6d68/attachment.html>


More information about the Snort-users mailing list