[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: firestorm question



On Tue, 2003-03-25 at 16:34, rmkml wrote:
> If an attacker send tcp Syn to me,
> 
> If my box respond automaticaly tcp Reset,

alert tcp $HOME_NET any -> $EXTERNAL_NET any (msg:"RST"; flags:R;)

> and other,
> If an attacker send udp to me,
> and my box respond automaticaly icmp port unreachable,

alert icmp $HOME_NET any -> $EXTERNAL_NET any (msg: "ICMP"; itype: X;
icode: Y;)

etc...

or am i missing something? :)

-- 
// Gianni Tedesco (gianni at scaramanga dot co dot uk)
lynx --source www.scaramanga.co.uk/gianni-at-ecsc.asc | gpg --import
8646BE7D: 6D9F 2287 870E A2C9 8F60 3A3C 91B5 7669 8646 BE7D

Attachment: signature.asc
Description: This is a digitally signed message part