[lug] outgoing port 220 exploit?

D. Stimits stimits at comcast.net
Tue Jan 20 14:55:53 MST 2004


Jordan Crouse wrote:

> On Tue, 20 Jan 2004 13:38:10 -0700
> Kevin Fenzi  wrote:
>
>
> >tcp syn from randomip:220 -> hismachine:6129 (first part of tcp
> >handshake) tcp rst from hismachine:6129 -> randomip:220 (rst flag set,
> >means"connection refused")
>
>
> Thats right.  Good call.
>
> Stupid UDP, get out of my head!  :)
>
> Jordan
>
FYI, I have it logging and blocking separately the SYN packets and full 
tcp packets.

D. Stimits, stimits AT comcast DOT net





More information about the LUG mailing list