Juniper Networks
Solutions
Products & Services
Company
Partners
Support
Education

Signature Detail

Security Intelligence Center
Signatures
Print

Short Name

SCAN:MISC:MSTREAM-REP-15104

Severity

Info

Recommended

No

Category

SCAN

Keywords

Mstream Handler To Client on TCP/15104

Release Date

2003/04/22

Update Number

1213

Supported Platforms

idp-4.0+, isg-3.0+, j-series-9.5+, mx-9.4+, srx-9.2+, srx-branch-9.4+, vsrx-12.1+

DDOS: Mstream Handler To Client on TCP/15104


This signature detects the command string ">" in a TCP packet to port 15104 with the ACK and PUSH flags set. This can indicate that an Mstream handler is attempting to communicate with an Mstream client. Attackers can use Mstream, a denial-of-service (DoS) attack tool, to flood IP addresses with TCP ACK packets from forged source addresses.

Extended Description

None

References

  • CVE: CVE-2000-0138
  • URL: http://staff.washington.edu/dittrich/misc/mstream.analysis.txt

Site Map
RSS Feeds
Careers
Accessibility
Feedback
Privacy Policy
Legal Notices
Copyright © 1999-2010 Juniper Networks, Inc. All rights reserved.
Help
|
My Account
|
Log Out