No subject


Thu Nov 23 16:36:19 EST 2017


ping scan option as a single TCP packet with the ACK flag set
_from_ port 80, not directed at it... so how come? I thought it
might be a stray packet from a webserver, but there's none
running under this IP (the network is some server housing firm in
sweden).

Is the first alert caused by the fact that nmap sends out a ICMP
echo request from a random port and the sending host cannot
receive the echo...?

RFE (Request for Education ;o)))

Bye, Jan
-- 
Radio HUNDERT,6 Medien GmbH Berlin
- EDV -
j.muenther at ...206...



More information about the Snort-users mailing list