October 7th, 2005, 02:07 PM
October 7th, 2005, 02:44 PM
A TCP connection is setup using a "three-way handshake". This means a series of packets in order SYN, SYN/ACK and an ACK..
A SYN port attack probably means somebody tried to setup a connection (first SYN packet) to a port on your computer. Your firewall should block all connection attempts, check to make sure. If correctly blocked you can safely ignore these alerts. You'll get a lot of them, thanks to all the viruses running rampant on the Internet..
Experience is something you don't get until just after you need it.
October 7th, 2005, 03:20 PM
Even though i knew tcp sync. process, i wasnt able to figure out what the term means
October 7th, 2005, 06:45 PM
Without actually seeing what your firewall triggered on to give the alert the syn can be used for several things, one of which is a denial of service attacks(SYN Flooding).
The other could be an attempt to fingerprint your OS, I can't think of a time that it wouldn't be sent to a port. It could be your vendors way of generalizing the many malicious uses of a syn packet and just name the alert "SYN Port Attack"
There are two rules for success in life:
Rule 1: Don't tell people everything you know.