Veritas777 opened this issue on Jan 26, 2005 ยท 91 posts
JeniferC posted Wed, 26 January 2005 at 6:47 PM
Attached Link: http://www.whitehats.com/info/ids144
This is what I read about the error from Norton's site: *"Tcp_Xmas_Scan Severity: Low This attack poses a minor threat. Corrective action may not be possible or is not required. Attack Category: Suspicious Activity Anomalous network conditions or traffic patterns. A suspicious activity signature, for example, might detect two systems with identical IP addresses, a condition that indicates an attempted IP spoofing attack. Description This signature detects a TCP packet that contains a sequence number of zero, and with the FIN, URG, and PUSH bits set. Sending invalid combinations can result in DoS, Enumerations, and Reconnaissance. Additional Information There are reported incidents where legitimate traffic may cause an intrusion detection system to raise "false positive" alerts for this event."* More info at link