Forn: That's a darned unreliable form of scanning. The theory is based on an idle host scan where the host really is idle. On a busy network you aren't going to get any viable data by checking the sequence number because anyone or anything could have bumped it in the meantime.