Firewall-1

Re: [FW-1] TCP: Treason uncloaked - attacks , smartdefense solutions ?

Subject: Re: [FW-1] TCP: Treason uncloaked - attacks , smartdefense solutions ?
From: Hugo van der Kooij <hvdkooij AT VANDERKOOIJ DOT ORG>
To: FW-1-MAILINGLIST AT AMADEUS.US.CHECKPOINT DOT COM
Date: Wed, 25 Oct 2006 22:05:09 +0200
On Wed, 25 Oct 2006, Mark Senior wrote:

> According to this list posting
> (http://lists.freestandards.org/pipermail/printing-user-general/2003/003937.html)
> there are some buggy embedded devices that have this behaviour -
> perhaps home routers...

Based on the port info there is propably a NAT device involved:

> > TCP: Treason uncloaked! Peer 64.201.33.162:61377/80 shrinks window
> > 3086856954:3086856955. Repaired.

Source ports in the 60k range usually happen to be NATted portes.

So I fully agree that it is most likely just a broken client somewhere in 
Ontario. But I would check the full access log to see what patterns 
emerges from there.

Hugo.

-- 
        hvdkooij AT vanderkooij DOT org http://hvdkooij.xs4all.nl/
            This message is using 100% recycled electrons.

=================================================
To set vacation, Out-Of-Office, or away messages,
send an email to LISTSERV AT amadeus.us.checkpoint DOT com
in the BODY of the email add:
set fw-1-mailinglist nomail
=================================================
To unsubscribe from this mailing list,
please see the instructions at
http://www.checkpoint.com/services/mailing.html
=================================================
If you have any questions on how to change your
subscription options, email
fw-1-owner AT ts.checkpoint DOT com
=================================================

<Prev in Thread] Current Thread [Next in Thread>