STEALTH ACTIVITY (SYN FIN scan) ???
uh, i'm such a noob.
something was reported on my IDS(snort).
1 instances of (spp_stream4) STEALTH ACTIVITY (SYN FIN scan) detection
it is coming from port 21 and goin to port 21 on my machine
would someone please tell me what the hell it is?
something like ftp bounce attack??
thx in advance
Re: STEALTH ACTIVITY (SYN FIN scan) ???
Quote:
Originally posted here by stanger
something like ftp bounce attack??
No. If it was an FTP bounce attack, it would be coming from port 20 (or perhaps a high port number). But not 21.
Slarty