Short Name |
TCP:S2C:FLAGSERROR:DIR-SYNACK |
---|---|
Severity |
High |
Recommended |
No |
Recommended Action |
Drop Packet |
Category |
TCP |
Release Date |
2003/04/22 |
Update Number |
1213 |
Supported Platforms |
idp-4.0+, isg-3.0+, j-series-9.5+, mx-9.4+, srx-9.2+, srx-branch-9.4+, vsrx-12.1+ |
This protocol anomaly triggers when it detects a SYN-ACK packet with unexpected flags set. This can be a SYN-ACK-FIN packet attempting to hang the server.
An attacker could maliciously craft a packet containing an invalid combination of SYN, FIN, ACK, PSH, and URG bits, sent from a server to a client. Such a packet is abnormal. Detection of this packet could indicate a network misconfiguration or that an attacker is attempting to insert malformed TCP packets into the network.