Juniper Networks
Solutions
Products & Services
Company
Partners
Support
Education

Signature Detail

Security Intelligence Center
Signatures
Print

Short Name

SCAN:MISC:MSTREAM-CLIENT-REQ

Severity

Info

Recommended

No

Category

SCAN

Keywords

Mstream Client to Handler on TCP/12754

Release Date

2003/04/22

Update Number

1213

Supported Platforms

idp-4.0+, isg-3.0+, j-series-9.5+, mx-9.4+, srx-9.2+, srx-branch-9.4+, vsrx-12.1+

DDOS: Mstream Client to Handler on TCP/12754


This signature detects the command string ">" in a TCP packet to port 12754 with the ACK and PUSH flags set. This can indicate that a Mstream client is attempting to communicate with a Mstream handler. Attackers can use Mstream, a denial-of-service (DoS) attack tool, to flood IP addresses with TCP ACK packets from forged source addresses.

Extended Description

None

References

  • CVE: CVE-2000-0138
  • URL: http://staff.washington.edu/dittrich/misc/mstream.analysis.txt

Site Map
RSS Feeds
Careers
Accessibility
Feedback
Privacy Policy
Legal Notices
Copyright © 1999-2010 Juniper Networks, Inc. All rights reserved.
Help
|
My Account
|
Log Out