|
-
August 18th, 2003, 03:40 AM
#1
From what i can see from your 1st capture and fact that you are receiving many numerous similiar traces, someone is attempting to SYN flood your PC (DoS attack).
Someone is attempting to open "1/2"tcp session numerous times to you.
It is a 1/2 because the perpetrator is not completing the 3 way handshake.
What a TCP/IP stack would usually do is respond to the SYN bit with an ACK and wait for x minutes depenting on TCP/IP stack before it rejects the connection. However if you do not hear back from you acknowledgement, your TCP/IP stack will allocated memory and process cycles for that session for x minutes before it releases the session,,YOUr PC will do this for every TCP session thus and crash because of allocated resources..
The perpertrator can change the source address to a non routable address so the victim never gets a respond back for the x minutes thus hogging up his resources..
I hope I wasnt too vague with my explanations...very exhausted and tired pulling all nighters...
P.S.
If port 6881 is not open on your PC then you have nothing to worry about...
Your PC will drop the 1st SYN packet....
Posting Permissions
- You may not post new threads
- You may not post replies
- You may not post attachments
- You may not edit your posts
-
Forum Rules
|
|