This is Interesting: Free IT Magazines  
Home > Archive > Snort > September 2004 > [Snort-users] null scan without port number





You are viewing an archived Text-only version of the thread. To view this thread in it's original format and/or if you want to reply to this thread please [click here]

Author [Snort-users] null scan without port number
Annie Green

2004-09-25, 5:50 pm

Dear Gurus

What it means when there's "null scan" alert without any port number? Source
port and destination port are 'none'.

Regards,
A.

________________________________________
_________________________
Keep track of Singapore & Malaysia stock prices.
http://www.msn.com.sg/money/



-------------------------------------------------------
This SF.Net email is sponsored by: YOU BE THE JUDGE. Be one of 170
Project Admins to receive an Apple iPod Mini FREE for your judgement on
who ports your project to Linux PPC the best. Sponsored by IBM.
Deadline: Sept. 24. Go here: http://sf.net/ppc_contest.php
________________________________________
_______
Snort-users mailing list
Snort-users@lists.sourceforge.net
Go to this URL to change user options or unsubscribe:
https://lists.sourceforge.net/lists...nfo/snort-users
Snort-users list archive:
http://www.geocrawler.com/redir-sf....ist=snort-users
Matt Kettler

2004-09-27, 5:47 pm

At 06:23 PM 9/25/2004, Annie Green wrote:
>What it means when there's "null scan" alert without any port number?
>Source port and destination port are 'none'.


That sounds like a bug, since null scans can only happen in TCP. However,
it might mean that the src and dest port are both 0 in the packet.

What snort version are you using?

Are you using some kind of report interpreter (ie: ACID) or is this present
in the logs snort directly generates?

Can you give an example alert (censor IPs if you wish)?



-------------------------------------------------------
This SF.Net email is sponsored by: YOU BE THE JUDGE. Be one of 170
Project Admins to receive an Apple iPod Mini FREE for your judgement on
who ports your project to Linux PPC the best. Sponsored by IBM.
Deadline: Sept. 24. Go here: http://sf.net/ppc_contest.php
________________________________________
_______
Snort-users mailing list
Snort-users@lists.sourceforge.net
Go to this URL to change user options or unsubscribe:
https://lists.sourceforge.net/lists...nfo/snort-users
Snort-users list archive:
http://www.geocrawler.com/redir-sf....ist=snort-users
Sponsored Links






Free braindumps | Software forum | Database administration forum

Copyright 2003 - 2010 webservertalk.com