Juniper Networks
Solutions
Products & Services
Company
Partners
Support
Education

Signature Detail

Security Intelligence Center
Signatures
Print

Short Name

TCP:S2C:FLAGSERROR:DIR-SYNACK

Severity

High

Recommended

No

Recommended Action

Drop Packet

Category

TCP

Release Date

2003/04/22

Update Number

1213

Supported Platforms

idp-4.0+, isg-3.0+, j-series-9.5+, mx-9.4+, srx-9.2+, srx-branch-9.4+, vsrx-12.1+

TCP: S2C Flags Error Additional Flags in SYNACK Packet


This protocol anomaly triggers when it detects a SYN-ACK packet with unexpected flags set. This can be a SYN-ACK-FIN packet attempting to hang the server.

Extended Description

An attacker could maliciously craft a packet containing an invalid combination of SYN, FIN, ACK, PSH, and URG bits, sent from a server to a client. Such a packet is abnormal. Detection of this packet could indicate a network misconfiguration or that an attacker is attempting to insert malformed TCP packets into the network.

References

  • URL: http://www.faqs.org/rfcs/rfc1180.html

Site Map
RSS Feeds
Careers
Accessibility
Feedback
Privacy Policy
Legal Notices
Copyright © 1999-2010 Juniper Networks, Inc. All rights reserved.
Help
|
My Account
|
Log Out