Re: Packet from port 80 with spoofed microsoft.com ip

From: Michael Rowe (mrowe@mojain.com)
Date: 01/30/03

  • Next message: David Hickman: "Re: Firewall logging port 6346"
    Date: Thu, 30 Jan 2003 22:22:05 +1100
    From: Michael Rowe <mrowe@mojain.com>
    To: incidents@securityfocus.com
    
    

    On 03/01/29 14:11 -0600, NESTING, DAVID M (SBCSI) wrote:
    > Are you SURE nothing on your end would have attempted to initiate a
    > connection to this site? When you say your Windows computers weren't
    > "active", did you mean they were physically powered off, or just idle?

    Yeah, turned off.

    On balance, it seems like the mostly likely explaination is my IP
    being used in a spoofed SYN attack. A distant second: the MS web
    server sending a wildly delayed ack to a legitimate connection.

    Thanks for the responses!

    -- 
    Michael Rowe <mrowe@mojain.com>
    IM  - mrowe@jabber.org                Prof - ACM, IEEE, Computer Soc.
    Web - http://www.mojain.com/          Vice - Barley malt, brewed or
    Key - http://mojain.com/keys/mrowe.asc       distilled (hold the ice)
    ----------------------------------------------------------------------------
    This list is provided by the SecurityFocus ARIS analyzer service.
    For more information on this free incident handling, management 
    and tracking system please see: http://aris.securityfocus.com
    


    Relevant Pages

    • Re: Dialup re dials after inactivity
      ... software to initiate a connection. ... is initiating dial-up in this situation. ... before considering the connection "idle" and disconnecting it. ... PC dials out, racks up phone charges, never hangs up. ...
      (microsoft.public.windowsxp.general)
    • Re covery all
      ... > manager is not set to initiate an Internet connection when needed. ... > that an Internet connection is needed, ... With immediate send disabled, MSOE ...
      (microsoft.public.windows.inetexplorer.ie6_outlookexpress)
    • Re: Java Socket Constructor
      ... they take in establishing the connection, why, then, yes, only the "client" can initiate. ... But there are cases where insisting on this terminology, once the connection is made, can lead to madness. ...
      (comp.lang.java.programmer)
    • Re: remote admin question
      ... Or use an email, sms or ... pager message parser to initiate the two way connection from Klosed - can it ...
      (comp.security.unix)
    • Re: Question regarding security programming newsgroups
      ... A will initiate a key exchnage to B and B will initiate a ... key exchnage to A. ... When a connection A->B is in state connecting, ... (hold the packet) ...
      (comp.security.misc)