[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: firestorm question



Gianni Tedesco wrote:

> On Tue, 2003-03-25 at 17:20, rmkml wrote:
> > How track tcp session and if session is not full open (Syn-SynAck-Ack) and my
> > box send tcp Reset ...
>
> flow:!established; ?

Yes,
but I have many false,
because, my linux send Reset if receive packet after Fin<->Fin ...
do you have "closed" expression ? (or similar)
(flow:!established,!closed; = Event Reset if after tcp session (not established ||
not closed) )

Regard.